Meeting minutes (final) subject: generic processes for the Identity- & Access Management 9th Meeting date: Friday, 2008-02-08 time: 09:30 16:00 location: NIFIS e.v., Hanauer Landstraße 300, Frankfurt am Main, Germany Attendees Oliver Belikan doubleslash Net-Business GmbH oliver.belikan@doubleslash.de OB Marc Dierichsweiler Impuls IT Beratungsgesellschaft mbh m.dierichsweiler@impulsit.de MD Thomas Felder SECUDE Global Consulting GmbH Thomas.Felder@secudeconsulting.com Holger Görz Institut für System-Management GmbH Holger.Goerz@secu-sys.de HG Henning Guder Services for Business IT Ruhr GmbH Henning.Guder@sbi-ruhr.de HGu Martina Hendricks Dekra AG Martine.hendricks@dekra.com MH Vanessa Henning Impuls IT Beratungsgesellschaft mbh v.hennig@impulsit.de VH Bernd Hohgräfe Siemens Enterprise Communications GmbH & Co. KG bernd.hohgraefe@siemens.com Jürgen Kühn Trivadis GmbH Juergen.Kuehn@trivadis.com JK Volker Ludwig Nationale Initiative für Internet-Sicherheit e.v. VolkerL@InterXion.com VL Volker Schaberow Services for Business IT Ruhr GmbH Volker.Schwaberow@sbi-ruhr.de VS Roland Stahl Henkel KGaA roland.stahl@henkel.com RS Marko Vogel KPMG Advisory mvogel@kpmg.com MV Stephan Vogtland KPMG Advisory svogtland@kpmg.com SV Horst Walther Kuppinger, Cole + Partner horst.walther@nifis.org HW Holger Weß RWE AG Holger.wess@rwe-ag.de HWe Additional distribution Roland Awischus Beta Systems Software AG roland.awischus@betasystems.com RA Giovanni Baruzzi Syntlogo GmbH Giovanni.baruzzi@syntlogo.de GB Roland Blomer UMIT, Institut für Informationssysteme des Gesundheitswesens roland@blomer.de Norbert Boß Sun Microsystems GmbH norbert.boss@sun.com NB Arslan Brömme ConSecur GmbH broemme@consecur.de AB Isabell Conrad SSW Schneider Schiffer Weihermüller Rechtsanwälte Steuerberater Wirtschaftsprüfer Isabell.Conrad@SSW-muc.de Manfred Hübner WestLB AG Manfred_Huebner@WestLB.de MHü Nicole Kleff Nicole Kleff IS-Consulting info@nkleff.de NK Peter Knapp Nationale Initiative für Internet-Sicherheit e.v. PeterK@InterXion.com PK 2008-02-08_GenericIAM-Meeting-Minutes(1.0).doc Horst.Walther@nifis.org Seite 1/7 TF BH RB IC
Erich Krahmer ROHDE & SCHWARZ GmbH & Co. KG Erich.Krahmer@rohde-schwarz.com EK Martin Kuppinger Kuppinger, Cole + Partner mk@kuppingercole.de MK Michael Lang Novell GmbH milang@novell.com ML Holger Nahrgang Berliner Volksbank eg Holger.Nahrgang@Berliner- Volksbank Mathias Neher doubleslash Net-Business GmbH mathias.neher@doubleslash.de MN Andreas Netzer ic Compas GmbH & Co KG netzer@ic-compas.de AN Dörte Neundorf Bayerische Motoren Werke Aktiengesellschaft Doerte.Neundorf@bmw.de DN Franz- Josef Nölke Siemens Enterprise Communications GmbH & Co. KG franz-josef.noelke@siemens.com Jens Petersen FirstAttribute AG Jens.Petersen@firstattribute.com JP Jörg Resch Kuppinger, Cole + Partner jr@kuppingercole.de JR Gerd Rossa Institut für System-Management GmbH Gerd.Rossa@secu-sys.de GR Denis Royer Institute of Business Informatics, Johann Wolfgang Goethe - University Frankfurt a. M. denis.royer@m-lehrstuhl.de Matthias Schabl Novell Österreich GmbH mschabl@novell.com MS Jan Schallaböck Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein ld103@datenschutzzentrum.de Jürgen Skirde Deutsche Steinkohle AG Juergen.Skirde@dsk.de JSk Angelika Steinacker CSC, IT Management & Security asteinac@csc.com AS Peter Weierich Völcker Informatik AG PeterW@Voelcker.com PW HN FN DR JS Agenda 09:30 Start welcome - housekeeping new members introduction participants (confirmend, no participation, no answer) meeting minutes from Friday, 2007-10-12 assignments from last meeting activities report WG Organisation (Horst Walther) activities report WG Modelling (Andreas Netzer) activities report WG Validation (Angelika Steinacker) activities report WG Presentation (Peter Weierich) NIFIS-GenericIAM on the EIC 2008 Members of the working groups Additional topics NIFIS-GenericIAM-infrastructure NIFIS-members Links to NIFIS-GenericIAM Next steps, Workgroup meetings, next regular meeting, assignments 16:00 End
Risks Description Potential damage probability Too slow modelling progress High Medium No. Type Who Check minutes from last meeting L1 D All The minutes of the last meeting from the 8 th meeting at 2007-10-12 in München were accepted unchanged. (attached document 2007-10-12-GenericIAM-Meeting-Minutes(1.0).pdf ) No. Type Who Assignments tracking (old) L2 A All Set a link to the GenericIAM-Website (www.genericiam.org) on their companies website at a prominent location. 2007-10-12 open Still an open issue for the new and many of the members. Links set by GenericIAM-Members set so far are doubleslash Net-Business GmbH ic Compas GmbH & Co KG Nicole Kleff IS-Consulting Peak Solution GmbH Gesellschaft für Prozessmanagement SiG Software Integration GmbH No. Type Who Assignments tracking (from last meeting) L3 A AN Taking of an inventory of all received models + some quantitative metrics. 2007-07-13 open L4 A AN Decide how to use ARIS in our modelling process with special respect to interchange possibilities via a standardized interchange format and / or alternative free open source products. L5 A AB Include, supported by AN + HW: Control, the Audit-process: Adding preventive controls for auditing Adding detective controls for auditing (reconciliation) Demonstrate the generic projection capabilities by "generating" an example process. 2007-07-13 open 2007-07-13 Provide a twofold proof: 1. proof of design and 2. proof of effectiveness.(by random sampling) L6 A JS Provide the data protection requirements (Datenschutzanforderungen) L7 A JS Inform about the next ISO meeting No. Type Who Members affairs L8 S All 3 of the 16 attendees were first timers at a GenericIAM quarterly meeting: Volker Schaberow Stephan Vogtland Holger Weß Therefore all attendees introduced themselves: Who I am? Where I come from?
What exposure I have to IAM? Why I came here? What I may contribute? L9 S HW Friedel Vogel left the group due to change of job and professional focus. L10 S MV SV will take over MV s role in the team and in the Validation group No. Type Who Report from the Working Groups L11 D All Each working group determines a speaker (S). The speaker appoints a deputy (D). At present the working groups are populated as follows: Modelling Oliver Belikan Norbert Boss Marc Dierichsweiler (S) Thomas Felder Holger Görz (D) Henning Guder Matthias Neher Andreas Netzer Vanessa Henning Peter Weierich Roland Stahl Validation Jürgen Kühn Martin Kuppinger (D) Gerd Rossa Angelika Steinacker (S) Marko Vogel Presentation Martin Kuppinger Denis Royer (D) Peter Weierich (S) Horst Walther Organisation Horst Walther (S) N.N. (D) L12 A HGu Provide a link to http://www.genericiam.org/ on the company web-site 2008-02-22 L13 A TF Provide a link to http://www.genericiam.org/ on the company web-site 2008-02-22 L14 A MD Provide a link to http://www.genericiam.org/ on the company web-site 2008-02-22 L15 A TF Submit an application for NIFIS-membership to the VL / NIFIS 2008-02-22 L16 A RS Submit an application for NIFIS-membership to the VL / NIFIS 2008-02-22 No. Type Who Report of the Working Group Organisation L17 S HW 1. phone call and mail-invitation to Dr. Martin Kuhlmann / Omada 2. Martin Kuhlmann, Omada joined 3. reworking 1st paper on top down approach (Arslan Brömme, Andreas Netzer) 4. Updating GenericIAM-Webpage 5. Further contacts to international standardisation bodies had been put on hold due to lack of substantial results. 6. guideline on membership
who is to be counted as an (active) group member Everybody who shows up at our quarterly meetings and / or actively contributes to our mission will be considered as a GenericIAM-member. If he does not meet these criteria for one year we don't consider him / her as a GenericIAM-member any longer. Not-Members may stay registered in the GenericIAM Google group in order to receive relevant information further on. They should also maintain their NIFIS-membership. We consider them as "friends of GenericIAM". Whenever anyone out of the group "friends of GenericIAM" resumes his volunteering activities or starts them for the first time, we will count him / her as a member again. Members will be listed on our NIFIS-Generic-IAM-Webpage with their company and full name and logo. to take into account the volatile environment of our members and friends, so that they can flexibly invest more or less effort into our joint initiative. No. date Name vote 1 03.12.2007 Jens Petersen yes 2 03.12.2007 Marcus Schmid yes 3 03.12.2007 Nicole Kleff yes 4 04.12.2007 Andreas Netzer yes 5 04.12.2007 Angelika Steinacker yes 6 04.12.2007 Bernd Hohgräfe yes 7 04.12.2007 Holger Nahrgang yes 8 04.12.2007 Marc Dierichsweiler yes 9 04.12.2007 Peter Weierich yes 10 04.12.2007 Roland Awischus yes 11 04.12.2007 Thomas Felder yes 12 05.12.2007 Jürgen Kühn yes 13 05.12.2007 Oliver Belikan yes 14 05.12.2007 Thomas Felder yes 15 05.12.2007 Yash Vartak yahbut (issue solved) 16 06.12.2007 Denis Royer yes 17 06.12.2007 Marko Vogel yes 18 07.12.2007 Vanessa Henning yes 19 10.12.2007 Holger Görz yes 20 11.12.2007 Norbert Boss yes 21 12.12.2007 Martina Hendricks yes 7. votes in total 20 yes 1 yahbut 0 no 8. Policy is accepted No. Type Who Report of the Working Group Presentation L18 S HW No presentation group activities have been undertaken during last quarter. No. Type Who Report of the Working Group Validation L19 P AS See attached PowerPoint file 2008-02-08_GenericIAM_9th_Quarterly_Meeting (0.3).ppt No. Type Who Report of the Working Group Modelling L20 A AN Organise a meeting of the GenericIAM-WG Modelling mid of November 2007 at the following location: Impuls IT Beratungsgesellschaft mbh, Wilhelm-Theodor-Römheld-Str. 14, 55130 Mainz. See attached PowerPoint file 2008-02- 08_GenericIAM_9th_Quarterly_Meeting (0.3).ppt L21 S HW Due to heavy workloads AN resigned from his position as a speaker of the WG Modelling. L22 D All We appoint MD as a speaker of the WG Modelling. L23 S MD The modelling group doubts, that the top-down approach using Petri-nets will be well received by
the majority of members of our target group. L24 A HW Collect all available input-documents for the modelling group and pass them over to MD L25 A HW Apply for admin-access to the NIFIS-Generic-Intranet for 2 more NIFIS- GenericIAM-members: Horst Walther Thomas Felder L26 D All If the access to the NIFIS-GenericIAM-intranet can not be handled as flexible as necessary for the work of the active members of NIFIS-GenericIAM, we will switch to MD (Impuls IT) as a hoster. L27 D All We will grant access to the GenericIAM-Intranet to all active NIFIS-Generic IAM-members according to our active membership policy. L28 A HW Provide for a single entry (through: http://www.genericiam.org/) to all of the web-representations and work-spaces of our initiative. L29 A HW Place all our meeting minutes on our Web-Site: http://www.genericiam.org/. L30 S OB Our modelling-progress suffers from lack of financial sponsoring. E.g. a bachelor thesis would cost ~ 800 per month for ½ a year resulting in 4,800. But it would bring us a huge step further. L31 D All We will try to acquire sponsors, willing to support a bachelor-thesis on modelling generic IAMprocesses. L32 S HG Presentation of two candidates for Generic processes re-certification : See attached document GPM_Re-Zertifizierung_V7.pdf assign role : See attached document GPM_Rolle-zuteilen_V7.pdf L33 A HG Contribute the remaining ~ 13 ready modelled processes as candidates for generic IAM-processes to our knowledge base. L34 D All There will we 2 working meetings of the Work group Modelling from now until April 22nd. Participants will be RS, HG, TFe, MD & VH): 1. Meeting: ~ beginning of march 2. meeting: 2008-04-21 in Munich We aim at the presentation of our first 3 to 5 truly generic IAM-processes which will become the core of our yearly issue NIFIS-GenericIAM model 2008. L35 A MD Organise and arrange the two working meetings of the WG Modelling. L36 A OB Translate the texts in the graphical elements in the GenericIAM-website from Germen to English. (HW) L37 S OB By now we receive ~ 100 accesses per day to the website www.genericiam.org that near to nothing. This situation needs to be improved. No. Type Who NIFIS-GenericIAM on the EIC 2008 L38 D All We will have a NIFIS-GenericIAM booth on the European Identity Conference (EIC) 2008 L39 D All Who will attend? Oliver Belikan: Für den Donnerstag den 24.04.2008 bin ich sehr gerne ganztätig auf dem Stand und vermarkte GenericIAM so gut es geht. Auch helfe ich gerne bei Abbau und Aufräumen. Angelika Steinacker: ich bin gerne bereit, ein paar Stunden "Dienst" zu schieben. planen sie mich ruhig ein. Thomas Felder: ich würde an einem Tag ein paar Stunden übernehmen. Michael Lang: Ja, gerne, planen Sie mich ein. Roland Stahl Bernd Hohgräfe Marc Dierichsweiler Volker Ludwig
L40 S HW Our time slot will be: 09:00-11:00 coffee break - 11:30-13:00 L41 D All We will start our meeting at 10:00 L42 S HW Booking Code for NIFIS-Members (not booth attendance): 20% reduction using the Booking code nifis208 L43 A HW Prepare a speaker text for NIFIS-GenericIAM attendees. 2008-02-22 L44 A VL Arrange marketing material for the booth (signage, flyers, work samples, ) HW and HG assist. 2008-02-22 No. Type Who Miscellaneous topics L45 D All We will go on using the widely spread basic tools which are commonly available and easy to use without training. We will therefore not be using the ARIS-Licences, which we were granted by IDS- Scheer but use basis tools like MS-Visio instead. L46 S HW There is an IAM survey of the KPMG (in German) available. For the invitation and a link to the questionnaire please follow: http://link.nifis.de/archive.php?p=111907095_86504 L47 S HW Enrich your profile at http://groups.google.com/group/genericiam/ We will put more emphasis on the virtual interaction in our work for GenericIAM. We need more personal and professional member information about in the profile. Please fill in your full name and professional picture, Location, Title, Industry, Email address, Website and / or Blog, Quote and About me in your profile properly. This additional information will help us to work more confidently in the virtual space. It makes clear, that there are real humans acting and contributing behind the electronic representations. Registered Members who prefer to stay anonymous will be removed until next meeting. Next Meeting L48 D All Besides the additional emphasis of virtual collaboration we will continue to meet on a quarterly basis. The next Meeting will be in Munich. We plan to meet at Tuesday, 2008-04-22, 10:00 13:00, a reminder will be sent 1 week in advance. The meeting was hosted and facilitated by the 2nd European Identity Conference 2008 (EIC 2008: http://www.id-conf.com/). Guests, who are interested in participation in the group activities, are welcome. L49 R HW Please also visit the Web-references... and GenricIAM-Blog (http://blog.genericiam.org/) GenericIAM-Calendar (http://www.google.com/calendar/render?cid=8e49efvhc4thl3ngbs19cgjetk%40group.calen dar.google.com) GenericIAM-Discussions (http://groups.google.de/group/genericiam/) GenericIAM-Homepage (http://www.genericiam.org/) GenericIAM @ NIFIS (http://www.nifis.org/joomla/index.php?option=com_content&task=view&id=1492&itemid=2 08) IAM-Wiki (http://www.iam-wiki.org/)