September 03, 2004

The global challenge

Agreeing on standards for sharing identity is hard enough without having to reconcile privacy laws around the world

As complicated as identity federation can be for U.S. companies, globalization adds still further complexity. Privacy laws, in particular -- although easy enough to manage when doing business locally -- can become a thorny issue when exchanging user identity information across international borders.

“If you’re a manager who has an employee in Germany and you’re based in the United States, it raises some interesting questions about what information you’re allowed to look at and what information you’re not allowed to look at,” says Simon Nicholson, chair of the business and marketing expert group of the Liberty Alliance.

Even for U.S. companies with no overseas operations, it’s shortsighted to plan for identity federation without considering the international implications. Some of the companies pursuing identity-based systems most aggressively can be found in Europe and Asia, and many of them are attractive partners for American businesses.

“Thirty percent of our members are headquartered outside North America,” Nicholson says. “If you want to do business with anybody outside of North America, you need to understand what their terms and conditions are going to look like and what their operating environment is like.”

According to Dan Blum, senior vice president and research director at Burton Group, those environments and conditions vary widely.

“Imagine taking a trip around the world where you start in the United States, then fly to New Zealand, then Singapore, then Japan, then over to Germany -- the European Union -- and then back again,” Blum says. “And think of all the differences in attitudes toward privacy that you’d encounter on that trip.”

A government such as Singapore’s, Blum explains, assumes broad powers to monitor, collect, and correlate data on individuals. On the other hand, the German government regulates and upholds personal privacy to a degree Blum  describes as “paranoid.”

Federation didn’t create these problems. It merely brings them to the fore. In fact, the need to address the differing needs of world governments and industries may prove to be the new driver for federated identity solutions, after security and cost control. Given such a diverse number of players, there may simply be no viable alternative.

Neil McAllister is a freelance writer based in San Francisco. He also writes InfoWorld's Fatal Exception blog.

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

The one-stop resource center for IT professionals.

White Paper

CA Security Management Solutions

A comprehensive security management solution can help you streamline, as well as grow, your current or evolving business. In this way, a strategic security approach can help you increase your competitiveness in these challenging market conditions.

Download now! »

White paper

Beyond Compliance: The Significant Benefits of Log Management

Find out how you can effectively collect, normalize and archive enterprise-wide, security-related data that is invaluable for security investigation and compliance reporting.

Download now! »

Webcast

Integrated Identity Compliance: Enabling Cost-Effective Role-Based Compliance

This session focuses on the intersection of role management and identity compliance, and addresses the importance of identity compliance in enterprise governance and the challenges that organizations may face in achieving it.

View now! »
©1994-2009 Infoworld, Inc.