Showing posts with label IBM Pulse. Show all posts
Showing posts with label IBM Pulse. Show all posts

Tuesday, February 26, 2013

Focus on IBM Security: IBM Security Policy Manager and IBM Security Access Manager for e-Business

Many customers have asked me "Why do I need an additional Authorization product when I have IBM Security Access Manager for e-Business?"

I recently attended a discussion focused on IBM Security Policy Manager (SPM) and IBM Security Access Manager for e-Business (SAMeb). IBM Security Policy Manager can be used in the following ways:
  1. Fine-Grained Authorization Control as opposed to coarse grained SAMeB group to J2EE Role Mapping (Sample: Policy to restrict a money transfer that exceeds $500 in a single transaction)
  2. Authorize and Audit Communications between application modules. (When Modules are independent and belong to different organizations/Access External Interfaces)
  3. Can have Multiple Policies on a service, each with multiple roles
  4. Centralized Policy management for Web Services
  5. Data Power could be used as a Web Service proxy and TSPM as the Policy Decision Point
  6. By Default all web services are denied
  7. Policies can be attached to Web Service/Port/Operation/Message
Here is a side by side comparison:

Next week, Prolifics will be at IBM Pulse in Las Vegas, a leading security intelligence conference. If you would like to learn more about Prolifics' Security solutions, visit booth #E525 and visit our IBM Pulse Page.

For more information about Prolifics, please visit www.prolifics.com or email solutions@prolifics.com.

Rama Yenumula is a Senior Consultant in the Security practice at Prolifics.

Wednesday, February 20, 2013

IBM Pulse Session Preview: Simplifying Administration and Maximizing Time-to-Value with SmartCloud Application Performance Management

In less than 2 weeks, I will be representing Prolifics at IBM Pulse 2013. I am looking forward to attending keynotes and sessions, speaking with industry experts and meeting attendees at Prolifics' booth, but I am most looking forward to presenting in two sessions focused on Application Performance Management.

I am hosting my first session at the start of the conference on Sunday, March 3. During this session, we will explore how our clients have achieved a quick time-to-value, and vastly simplified administration, when deploying IBM SmartCloud APM to monitor their middleware infrastructure by taking a unique approach. Attendees will learn how we simplified the often complex management aspects, and reduced implementation time, by leveraging the APM UI; eliminating the need for Managed System Lists (MSLs) by leveraging the little-known Situation Groups; and how they addressed the unique challenges of monitoring a pooled WebSphere Application Server infrastructure.

To learn more about my speaking session and to see what else Prolifics has lined up for IBM Pulse, click here.

If you are interested in learning more about IBM SmartCloud, I have included a video by Prolifics' APM Practice Director and IBM Champion for Tivoli, Dan Kern. In this video, Dan discusses increasing the availability, visibility and virtualization of business-critical applications with IBM SmartCloud solutions.


For more information about Prolifics, please visit: www.prolifics.com.


Brian Fisher is a Solution Architect at Prolifics focusing on monitoring and application performance management. He is a Technical Sales Specialist equipped with six years of innovative portfolio experience serving a broad base of IBM Tivoli clients, as well as sales specialists.

The Congruence Model for Security

From management literature (Tushman & O'Reilly), the congruence-based problem solving is a method to quickly and accurately identify the root cause of performance or opportunity gaps. In the context of security architecture, the congruence model can be applied to creating comprehensive security assessments for an organization. The model emphasizes analysis of the relationships among four core components of an organization (shown in the graphic below) also called the building blocks whose alignment relationships are the focus of congruent security architecture techniques. The goal is to leverage the relationships and interactions between those core components to reveal the underlying security posture of an organization.


Each congruence relation is important in forming organizational diagnoses that help us understand the current state of security in the enterprise, and the causes of the vulnerabilities. Analyzing these relations tends to define the political map and how the players tend to navigate it. It helps identify organizational behaviors that are helpful, neutral or detrimental to the security architecture initiative.

Analyzing the following three alignments using an appropriate "congruence questionnaire" is crucial to determining the security posture of the enterprise.

The Task and People Congruence Relation:
  1. Do people have the required competencies to perform the critical tasks that ensure safety of data and process?
  2. To what extent do the skills, abilities and motives of today’s human resources fit with security planning, architecture formulation and implementation requirements?
Identification goals: task-human resource inconsistencies that inhibit the ability to execute on security strategy.

The Task and Formal Organization Relation:
  1. Do the formal linking mechanisms between units facilitate security task integration, security team building and agility from a product delivery perspective?
  2. Is there a company wide vision for security and a strategy for addressing regulations, audit and security breaches?
Identification goals: task-structure inconsistencies that inhibit necessary integration among SBUs, needed to deliver a comprehensive security solution.

The Task and Culture Relation:
  1. Does the existing culture energize the accomplishment of critical tasks?
  2. Does the informal communication network and informal distribution of power help get the work done?
  3. Is there a reluctance to take action? Is there reliance on being told what to do? Identification goals: culture-task inconsistencies that drag performance down and inhibit consensus on security goals.
This due-diligence analysis can help identify the need for managers and their teams to realign the formal structures, people processes and cultural aspects of their organization with the critical tasks necessary to achieve the overall security vision. Managers and their teams should learn from this process, and even re-initiate the process iteratively within their own SBUs if necessary.

Next month, I will be attending IBM Pulse 2013 in Las Vegas, the industry-leading conference on Security Intelligence. Prolifics will exhibit in the solution showcase and host a number of sessions throughout the conference. To learn more about Prolifics' presence at IBM Pulse, visit: www.prolifics.com/pulse-2013.htm. If you would like to connect with me before the conference, please click here.


Javed Shah is a Practice Director for Security at Prolifics with more than 12 years experience in identity and access management architectures. He has broad exposure developing identity and access management solutions, and system software components that deliver reliable data security, web enablement and user lifecycle management services to customers. Before joining Prolifics, Javed founded and ran a professional services company in India for 6 years. Spanning over a decade, Javed has led identity management projects to successful exits at Nestle, University of California San Francisco, Kaiser Permanente, ABM Industries, BRE Properties, UPS, Tampa General Hospital and E*TRADE Bank. He was also the leader of the ITIM Level 3 defect resolution and analysis team in India where he was responsible for handling all customer defects for North America and Asia. Javed holds a Bachelor’s degree in Computer Science, a Certificate in Implementing and Managing an Enterprise Architecture using the Zachman Framework and the CISSP certification. He is also currently pursuing an MBA from the Haas School of Business, University of California Berkeley.

Wednesday, February 13, 2013

Prolifics Thought Leaders Named IBM Champions in 2013!

The IBM Champion program recognizes innovative thought leaders in the technical community. An IBM Champion is an IT professional, business leader, developer, or educator who influences and mentors others to help them make best use of IBM software, solutions, and services.

Meet Prolifics' 2013 IBM Champions!
Prolifics is proud to announce that 15 of our thought leaders have been recognized as IBM Champions for 2013. Prolifics has long demonstrated technology leadership through deep skills, a proven methodology, and high customer marks. Our technical staff has consistently developed innovative and creative solutions for Prolifics' clients and has dedicated themselves to rigorous and ongoing training - raising the bar and bringing thought leadership to the entire industry. Many of Prolifics' Champions selected by IBM have been published in several trade journals and often speak at conferences. Additionally, their custom-solutions implemented for customers worldwide have been honored with several awards.



Congratulations to all of our IBM Champions!

Handly Cameron - ICS
Laks Sundararajan - ICS
Alex Ivkin - Security
Dan Kern - Tivoli
Greg Hodgkinson - Rational
AJ Aronoff - WebSphere
Steve Fraser - WebSphere
Leland Irwin - WebSphere
Eric Markowitz - WebSphere
Vladimir Serebryany - WebSphere
Ashraf Souleiman - WebSphere
Prithvi Srinivasan - WebSphere
Neha Dhawale - WebSphere
Arup Datta - WebSphere
Rajiv Ramachandran - WebSphere

To learn more about our IBM Champions, visit: http://www.ibm.com/developerworks/champion/
For more information about Prolifics, visit: www.prolifics.com