Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - A Revolution will Happen: IAM Proprietary vs Cloud
Articles

A Revolution will Happen: IAM Proprietary vs Cloud

ISBuzz TeamBy ISBuzz TeamNovember 17, 2015Updated:December 10, 20154 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
IAM Prioprietary vs Cloud
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Surprisingly perhaps, use of the cloud to store and provision user credentials are still low within business; but it is beginning to grow. The reason for this slow growth probably has less to do with trust or the lack of it as it does with a growing experience in handling cloud vendor contracts.

Wisegate, a peer-driven IT research company that generates resources through collaboration of its senior-level IT professional membership base, recently surveyed more than 100 CISOs to get their thoughts and insights on the current state of IAM maturity within business. Today, I’ll share parts of those insights by focusing on the attitudes toward IAM and the cloud, and providing insights into the revolution of businesses adopting cloud credentialing.

In the Beginning

When the cloud first started, there were minimal options when it came to selecting service providers. The providers that existed held ascendancy and embraced ‘take it or leave it’ contracts. There was no negotiating, risk was pushed toward the customer, and contract terms were rigid.

As we all know, user credentials are business-critical, and with a rigid contract most companies chose to ‘leave it’ and I don’t blame them.

Times are Changing

The balance of power is changing, thankfully. With more cloud providers, businesses get just that: more. The competition is greater so business has the ability to negotiate and gain more over contract terms within providers. Business is gaining more experience in learning how to handle cloud contracts, which is a necessity since larger companies can easily use more than 1,000 different cloud services.

Business and cloud vendors are finding new ways to strike a balance. For example, cloud vendors are learning to deliver critical tasks like audits, and business is learning to balance paper audits with third party confirmations and on-site physical inspections.

Growth is Occurring

Although cloud-based IAM provisioning is low, it shows signs of growth and adoption over the next few years. In the survey of CISO Wisegate members, we found the following to show strong signs of growth :

  • 2014: 2 percent of companies used the cloud for identity management ‘moderately’
  • 2014: Zero companies used the cloud for identity management ‘always’
  • 2015: 13 percent were using the cloud ‘moderately’
  • 2015: 2 percent were using the cloud ‘always’

Social Media is Lagging

Though the opportunity for fast growth is visible, there is still one area that shows little potential – and that’s the use of social media credentials. Small online service providers are allowing users to access Internet services through social media usernames and passwords. Why would a company do this? Well, it effectively pushes effort and responsibility (if not risk) to big companies like Twitter, Facebook, and LinkedIn, while simultaneously making access much simpler for the user.

The social media credentialing approach seems to have spawned the future of identity and access management with the use of third party companies to attest a user’s identity. It’s a compromise between the old government desire to effectively maintain a strict centralized national identity database and the more modern wild west of social media.

There are currently three initiatives in progress, all using social media as a valid resource:

  • NSTIC: Promoted by the U.S. government
  • Verify: Being developed by the U.K. government
  • Identity 3.0: An open source being developed by the NFP Global Identity Foundation

Will the business world accept this new approach to IAM when it is currently rejecting the social media version, and if so, will it adopt a government or independent version?

In five years, things will certainly have evolved. CISOs will have the choice between maintaining their own expensive proprietary identity ecospheres, or tapping into an inexpensive wider one, and the U.S. and U.K. governments will press for their own systems to be used.

The Revolution of Choosing

When CISOs compare the cost of running their internal password management and maintenance efforts with piggybacking of a system effectively underwritten by government, I suspect things will change.

Overall it there is a slow improvement in business IAM maturity, and very little adoption of cloud credentialing. Business is still concentrating on maintaining its own proprietary identity ecospheres, and slowly improving them. We know, however, that a revolution is coming.[su_box title=”About Wisegate” style=”noise” box_color=”#336588″]Wisegate logoWisegate is a member-based IT research company that serves the industry’s most senior-level IT practitioners. Wisegate’s editorial team keeps a pulse on what matters to IT via its members, and publishes member-based advice, best practices and collaborative insights for the IT industry’s most pressing and important issues. [/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}