November 3, 2009 by Scott Bils
While billions of dollars will be spent on SaaS and cloud applications by the end of 2009, executives continue to question data security inside the cloud. A recent article in CIO Magazine notes a growing majority of execs are worried about cloud security. These executives recognize that each SaaS application, like Salesforce.com, represents a potential highway of highly sensitive corporate data outside the firewall and outside IT’s security protocol. While no means exhaustive, here is a list of mistakes we’re seeing companies make when deploying SaaS applications, creating unnecessary risk and cost for their organizations:
- Creating the ‘three-headed admin’ – granting multiple people administrator-level roles inside a single SaaS application, or having multiple admins share the same credentials. Aside from the obvious security issues, resulting SaaS app management data typically ends up reflecting multiple perspectives of users and permissions.
- Hoping that everyone ‘locks the door’ – relying on manual workflows, phone calls and emails to de-provision SaaS users’ access in an accurate and timely fashion across SaaS apps. If there’s not an automated way to guarantee deprovisioning across all apps, then it’s unlikely that it’s happening.
- Applying a short term ‘band-aid’ for management – using trouble ticketing and help desk systems to coordinate administration between central IT and departmental SaaS admins. This is typically a short term fix that just kicks critical provisioning and identity management issues down the road, and does it in a way that creates more pain later.
- Attempting the IT ‘end-run’ – not engaging IT on management and support until SaaS app(s) become “mission critical” within the organization. As SaaS and cloud are now becoming more mainstream technologies, IT is regaining their seat at the table to help extend existing policies and controls – ignore this dynamic at your own peril.
- Delegating policy enforcement – relying on individual SaaS administrators to enforce corporate policies for roles and permissions. Most organizations have access control policies and controls exist for on-premise apps and data, but few think about how to extend them to SaaS and cloud applications prior to deployment, particularly in environments with distributed administration.
- Believing in a management ‘silver bullet’ – assuming that existing on-premise directories (such as Microsoft Active Directory) or identity management tools (including SSO) extend to support all SaaS-related identity challenges. They don’t.
- Creating ‘two sets of rules’ – treating SaaS governance differently than on-premise applications with regard to user identity and compliance. Governance frameworks and best practices should consistently apply to applications no matter how they’re delivered.
- Failing to create a ‘rearview mirror’ for audit and compliance – failure to identify and approach for capturing an audit trail of access, usage, user change and permissions history. Though delivered by a 3rd party, companies are still responsible for implementing and enforcing access control policies, and for demonstrating it at audit time.
- Forgetting about compliance reporting – wasting 20-30 executive hours each quarter to manually compile reports for internal or external compliance audits. Forgetting to consider compliance reporting needs up front when evaluating SaaS vendors and overall SaaS/cloud strategy can be painful.
- When in doubt, spending more – buying unnecessary subscription seats because of a lack of visibility to actual subscriptions and current usage.
We’d be interested in hearing what others are seeing and hearing in these areas as well…
Tags: Active Directory, cio, Cloud, Cloud Computing, GRC, SaaS, SSO
Posted in Access Managment, Active Directory, Cloud Computing, Cloud Management, Compliance, Conformity, Federated Provisioning, IaaS, Identity Management, Microsoft, Provisioning, SAML, SPML, SSO, SaaS, SaaS Adoption, SaaS Governance, SaaS Integration, SaaS Management | Leave a Comment »
October 17, 2009 by Scott Bils
One of the use cases we’re almost universally supporting across our midsize enterprise customer base here at Conformity is integration with Microsoft Active Directory (AD), and providing the ability to extend and link employee, role and organizational data with identity stores contained in leading SaaS applications such as Salesforce.com, NetSuite, Google Apps and others. With our AD connector, customers of the Conformity platform are extending capabilities today in two major areas:
- User provisioning / deprovisioning – by normalizing and synchronizing role and permissions models across AD and Conformity and through deploying our event monitoring capabilities customers can automate user provisioning, deprovisioning and change management activities. When a new employee is onboarded and set up within AD, access and permissions to cloud services appropriate for the employee’s role are automatically provisioned via Conformity. For example, when a new outside sales rep joins the organization, when added in AD they then can also be provisioned against Salesforce.com, Xactly and Google Apps with appropriate access and permissions. When the sales rep changes title or role, or leaves the organization, changes in AD also then trigger appropriate changes in cloud application access and permissions. In effect, we’re providing users a cloud provisioning extension for AD that enables IT to extend access policies and controls to the cloud.
- Chargeback models – integration of department and other organizational identifiers between AD and Conformity’s role model also streamlines our customers ability to automate extension of internal chargeback and financial management models to cloud applications. By linking SaaS administrative siloes to AD via Conformity, enterprises can track and manage departmental usage not just at the application level, but also within specific modules within the cloud services themselves.
In addition to dramatically reducing administrative headaches, synchronizing and normalizing identity data across AD and major cloud applications is also enabling them to streamline audit prep activities, reduce operational costs and strengthen access control and security. More to come on this…
Tags: Active Directory, Cloud, Cloud Computing, SaaS
Posted in Access Managment, Active Directory, Cloud, Cloud Computing, Cloud Management, Conformity, Federated Provisioning, Google, IT Management, LDAP, Microsoft, NetSuite, Provisioning, SPML, SaaS, SaaS Governance, SaaS Integration, SaaS Management, Salesforce.com | 1 Comment »
October 15, 2009 by Scott Bils
We find very few people today that would dispute the notion that SaaS and cloud applications have become mainstream technologies in SMB and the midmarket. The challenges for the SaaS industry are also changing as a result. With the battle over the viability of the on-demand model largely won, the questions are now turning to the operational and IT management implications of a SaaS-centric environment.
Our customers and prospects here at Conformity are forward-thinking organizations that are aggressively leveraging the cloud delivery model for multiple, if not a majority of their business applications. Given our strong belief in the SaaS and cloud model, we believe that they are a good indicator of trends we’ll shortly be seeing more broadly in the market. All of these organizations are struggling with what their management processes and approaches look like in a purely ‘on-demand’ model. Among these multi-SaaS organizations we’re consistently seeing three general problem domains:
- User provisioning and administration – as they’re optimized for different problem sets, all major SaaS applications have fundamentally different ways of thinking about users, roles, profiles and permissions. Organizations have tended to have separate business administrators for say Salesforce.com, NetSuite and SuccessFactors. Each of these admins as a result has had to develop a separate model of their organization, deparments and role structures, with the result being that various siloed identity stores have been created across the organization. These stores are are all independent from each other and from on-premise directory services (Microsoft AD) and identity management solutions. Normalizing these identity stores in support of centralized, streamlined administration and reporting is a common theme we’re hearing, and what what our solution here at Conformity is addressing.
- Single sign-on (SSO) / authentication – another common challenge we’re hearing is the desire to provide end-users the ability to access multiple SaaS applications (and often on-prem apps as well) using a single set of credentials, both for end-user convenience and security purposes. This is the problem set being addressed by vendors such as Ping Identity, Tricipher and Symplified.
- Data integration – the final theme we’re hearing is around cross-application data integration, and the desire to integrate multiple ‘best of breed’ applications across a common business processes or workflow. This issue set consists of integration of cloud apps to both cloud and on-premise applications. This is the domain being addressed by vendors such as Cast Iron Systems, Pervasive and Boomi.
While the data integation challenge is fairly distinct from the first two challenges, significant market confusion exists around provisioning and SSO, and whether a solution in one addresses both areas. The short answer is no – the very simple analogy we use is that SSO tells you if you should let the visitor knocking on the front door into the house – provisioning and permissions management provides guardrails around what they can and cannot do once they’re in the front door. Both are needed, but complementary capabilities – more to come on this….
Tags: cio, Cloud, Cloud Computing, SaaS
Posted in Access Managment, Active Directory, Cloud, Cloud Computing, Cloud Management, Conformity, Federated Provisioning, IT Management, Identity Management, MSE, NetSuite, Provisioning, SAML, SMB, SPML, SSO, SaaS, SaaS Adoption, SaaS Governance, SaaS Integration, SaaS Management, Salesforce.com | Leave a Comment »
October 1, 2009 by Scott Bils
It’s been an exciting few days here at Conformity after our recent GA announcement and the kickoff of the Enterprise SaaS Working Group yesterday. We had a very lively, engaging debate on the key issues the group believes need to be addressed for SaaS and cloud applications to become ‘mainstream’ technologies in the enterprises. The group featured a diverse set of executive perspectives from cloud vendors, thought leaders and practitioners, and included:
- Peter Coffee, Director of Platform Research, Salesforce.com
- Tom Fisher, VP of Cloud Computing, SuccessFactors
- Ryan Nichols, VP Cloudsourcing and Cloud Strategies, Appirio
- Steve Coplan, Senior Analyst, Enterprise Security Practice, The 451 Group
- Doug Harr, CIO, Ingres Corporation
- Scott Carruth, VP Information Systems, Initiate Systems
- Michael Amend, Director of Enterprise Architecture, Dell Inc.
A quick highlight of some of the discussion yesterday:
- PaaS/SaaS – which model ‘wins’ in the enterprise? While opinions differed, a common sentiment shared by the panel was that there’s not going to be ‘right answer’ for all organizations. Depending on the industry vertical, business process or IT management model PaaS or SaaS could be the ‘right answer’, and in many situations organizations could have PaaS and SaaS offerings sitting side by side.
- Private clouds – part of the answer or indicative of SaaS market immaturity? As with the PaaS/SaaS discussion a common theme was ‘it depends’. The core advantage to SaaS and cloud delivery models is the ability to share resources – what part of the stack organizations decide they’d like to share will likely be driven primarily by security concerns and issues. A likely scenario, as with PaaS/SaaS, is that different models will likely be adopted by different types of organizations depending on security and operational requirements.
- Enterprise SaaS adoption – when does it overtake on-premise? Two different perspectives were discussed around when SaaS will overtake on-premise apps in the enterprise. A common belief of the group was that SaaS is winning in a majority of new deals in the enterprise today, with the perspective shared that 50-75% of enterprises would ‘flip the switch’ on cloud in some manner by approximately 2012. Peter Coffee of Salesforce also shared his belief that total installed base for SaaS would outnumber on-premise apps by 2020, though there would also likely be 1-2% of the market that would be ‘holdouts’.
- Any applications that SaaS/cloud won’t be able to penetrate? If architected and deployed correctly, there are no perceived areas in which SaaS and cloud application models could not be leveraged with Peter Coffee of Salesforce , Tom Fisher of SuccessFactors and Ryan Nichols of Appirio all providing compelling examples of large scale, transaction intensive customer deployments.
The full recording of the webinar is available and can be access by clicking here. Also, Ryan Nichols at Appirio had a great post on their perspective on our discussion topics here.
Please drop us an email as eswg@conformity-inc.com to be added to our mailing list, and to be notified of future Enterprise SaaS Working Group news and events.
Posted in Cloud, Cloud Computing, Cloud Management, Conformity, Enterprise, Federated Provisioning, Google, IT Management, IaaS, Identity Management, Infosec, MSE, PAAS, SaaS, SaaS Adoption, SaaS Governance, SaaS Integration, SaaS Management, Salesforce.com, SuccessFactors | Leave a Comment »
September 30, 2009 by Scott Bils
We’re excited to announce today the general availability of the Conformity solution, which provides customers the first enterprise-class management platform for cloud applications and users. The Conformity solution is designed to arm enterprises with the same level of visibility and control over on-demand applications as they’ve come to expect with traditional packaged apps. With our solution, enterprises can now be confident bringing new cloud applications into their business environments, knowing there will no longer be compromises made in the areas of management processes, insight and control. With today’s GA, enterprises can:
- Increase data security and reduce compliance risks
- Optimize license allocation and expenses
- Automate and streamline administration
- Expand and extend enterprise usage of SaaS and cloud applications
Specific capabilities of the Conformity solution include:
- User provisioning – provides centralized point of provisioning and deprovisioning of users accounts within cloud applications, and ongoing management of user permissions and authorizations.
- Role and profile management – enables organizations to centrally manage cloud application roles, profiles and permissions through normalized permission models, and maps policies to users and roles.
- Approval workflows – provides auditable cross-functional approval processes for users requiring new or amended access permissions, or role and profile changes.
- Directory integration – enables organizations to seamlessly synchronize Conformity’s user repository with on-premise directory services.
- Compliance reporting – provides reports required for effective preparation for audits for SOX, HIPAA, PCI and other regulatory mandates and standards.
- Usage analytics – provides visibility, analytics and reporting on cloud application and license utilization.
- Change management – enables archiving, management and recovery of application configurations and role models.
The Conformity platform provides templates, tools and workflow needed to manage all cloud applications in a customer’s environment. Conformity also provides additional analytics, reporting and provisioning automation through integrations with the following leading cloud applications:
The Conformity platform also supports directory integration for Microsoft Active Directory, and is compatible with industry standards such as SPML, SAML and WS-Federation.
Please click here to read the full announcement, and stay tuned for more upcoming news!!!
Posted in Active Directory, Cloud, Cloud Computing, Cloud Management, Compliance, Enterprise, Federated Provisioning, GRC, Google, IT Management, Identity Management, Infosec, MSE, NetSuite, Provisioning, SAML, SPML, SaaS, SaaS Governance, SaaS Integration, SaaS Management, Salesforce.com, SuccessFactors, Systems Management, Web access management, Web applications, Web services | Leave a Comment »
September 10, 2009 by Scott Bils
We’re very excited to announce our participation in the SuccessFactor’s new SuccessCloud™ program, which was introduced earlier today. Conformity’s AppConnect integration with SuccessFactors’ Business Execution Software Suite will enable customers to synchronize critical employee information across 3rd party applications and on-premise directory services. Customers will be able to ensure Cloud application access and permissions are consistent with organizational roles, and to automate service provisioning and change management across the employee lifecycle. With Conformity, SuccessFactors’ customers will be able to reduce data security and compliance risks as well as streamline costly, time-intensive activities associated with management of cloud applications and associated users. Click here to read the full announcement and to learn more about the partnership…
Tags: Cloud, Cloud Computing, GRC, SaaS
Posted in Enterprise, Identity Management, Provisioning, SPML, SaaS, SaaS Governance, SaaS Integration, SaaS Management, SuccessFactors | Leave a Comment »
August 28, 2009 by Scott Bils
We’re excited to announce that on September 30th at 11:00am PDT / 2:00pm EDT we’ll be holding the first event in our Best Practices webinar series, featuring a roundtable discussion with the Enterprise SaaS Working Group. Comprised of recognized thought leaders and visionaries in SaaS and cloud computing, the group will discuss the challenges and issues that need to be overcome for SaaS and cloud applications to become truly ‘enterprise-ready’. Participants in the session will include:
The discussion will focus on critical issues and corresponding best practices in the areas of management, governance, security and compliance, and will include a Q&A session open to all attendees. Click here for more information and to register for this exciting event!
Tags: Cloud, Cloud Computing, GRC, SaaS
Posted in Cloud, Cloud Computing, Cloud Management, Compliance, Enterprise, GRC, IT Management, SaaS, SaaS Adoption, SaaS Governance, SaaS Integration, SaaS Management, Salesforce.com, SuccessFactors, Web access management, Web applications, Web services | 1 Comment »
August 20, 2009 by Scott Bils
As frequently discussed in this blog, here at Conformity we believe that there are a fundamental set of issues that the SaaS industry as a whole needs to address for SaaS and cloud applications to become truly ‘enterprise-ready’. These issues range from management access and APIs to SLAs and performance monitoring. To provide a forum to further surface, discuss and propose solutions to these issues, in September we will be introducing the first Enterprise SaaS Working Group. The group will discuss challenges that need to be overcome to accelerate adoption of on-demand solutions in the enterprise, and will include a broad range of perspectives from thought leaders and practitioners alike. Participants will include:
- Enterprise CIOs and IT executives
- SaaS vendor executives
- SaaS consultants and service providers
- Industry analysts
We will be formally introducing the group at an exciting event we’re going to be hosting in late September. Please stay tuned for more details…
Tags: Cloud, Cloud Computing, SaaS
Posted in API, Access Managment, Cloud, Cloud Computing, Cloud Management, Conformity, Enterprise, IT Management, Identity Management, Infosec, MSE, SLA, SaaS, SaaS Adoption, SaaS Governance, SaaS Integration, SaaS Management, Web access management, Web applications, Web services | Leave a Comment »
August 3, 2009 by Scott Bils
As we heard once again last week at Catalyst from end-users, partners and vendors alike, many large enterprises are now finally taking a serious look at how to effectively leverage SaaS and cloud applications in their environments. As we’ve observed in this blog before, enterprise CIOs are also finding that there are no easy answers to how to address the fundamentally disruptive impact that SaaS and cloud-based applications have on current IT management approaches.
The issue comes down to this: if a third party controls the software, data and access, and the CIO no longer has the capabilities to directly monitor and manage software operations, how can the CIO fulfill his or her responsibility for governance and compliance? It’s a question that SaaS vendors must address if they expect to effectively compete and succeed in the enterprise marketplace
Our new white paper titled Success in the Enterprise: Making SaaS Manageable examines the CIOs need to manage SaaS applications as part of the larger responsibility for systems management in the enterprise. It also looks at steps SaaS vendors can being to take to meet this need, and outlines best practices in the following areas:
- APIs
- Activity access
- Performance monitoring
- Back office visibility
- Standards
The enterprise continues to present an enormous opportunity for SaaS vendors, but to capture this opportunity vendors need to take the next steps to ensure their services provide the management visibility needed to be truly enterprise-ready, and that they address the unique identity and systems management challenges created by the SaaS model.
This is the first in a series of best practice white papers that Conformity will be publishing for SaaS vendor executives to help the industry meet the needs of enterprise CIOs and their teams. Please visit our website to download a copy of Success in the Enterprise and to subscribe for future white papers, and to learn more about how we can help SaaS vendors address IT enterprise challenges.
Posted in Cloud, Cloud Computing, Cloud Management, Conformity, Enterprise, Federated Provisioning, GRC, IT Management, Identity Management, Provisioning, SaaS, SaaS Adoption, SaaS Governance, SaaS Integration, SaaS Management, Systems Management | Leave a Comment »
July 8, 2009 by Scott Bils
One of the big challenges the SaaS industry continues to face (which we talked about at our presentation at SaaS University last week in Chicago) is the gap that exists between the APIs/management access that SaaS applications provide today and the expectations of CIOs and IT teams, particularly in the enterprise. The end-customer CIOs we’re working with are typically surprised at how difficult it is to integrate most SaaS applications into their existing management processes and solutions – a CIO we recently spoke with just assumed that all major SaaS applications supported direct integrations into Active Directory and LDAP. On the flip side, most SaaS vendors are being faced with IT requirements and expectations they haven’t yet considered, let alone support in their services (though there are exceptions) particularly in identity-related areas such as user authentication and access control.
Why is this important?
IT is regaining its seat at the table when it comes to SaaS. In mid-size enterprises, as SaaS adoption has accelerated cross-functionally organizations are beginning to look to IT to centralize management and governance of SaaS applications and users to minimize compliance risks and administrative costs. In a recent survey we found that IT was involved in management and administration of SaaS applications in 72% of multi-SaaS organizations. In larger enterprises that are now taking a serious look at SaaS, IT is involved from the start to determine how the applications will be integrated into broader business processes and other on-premise applications, as well as management processes and solutions. We’re starting to hear from both types of organizations, as well as the SaaS vendors that serve them, that application ‘manageability’ is becoming a consideration in sales cycles – in fact we’re aware of several situations where an incumbent SaaS provider was displaced by an offering with improved API and management access.
Why the disconnect between SaaS vendors and IT? Based on our experiences and interactions with both sides of the issue, the gap that exists between SaaS applications and IT is driven by two factors:
- SMB legacy – the majority of leading SaaS vendors (including Salesforce.com) grew from an initial focus on SMB customers. Applications were architected and optimized to solve a specific functional business problem for this initial class/size of customer, with (understandably) limited focus on how the application would have to integrate into multi-SaaS or enterprise environments.
- IT as ‘the enemy’ – the ease of deployment and flexibility of SaaS eliminated the need for business users to involve their IT organizations in the selection, configuration and management of SaaS applications. As IT historically has neither been a decision-maker or influencer in the sales process, most SaaS vendors haven’t been exposed to IT organizations, particularly in the enterprise. In fact, IT was and is often times (and often unfairly) characterized as the enemy of SaaS adoption, needlessly entangling business users in red tape and bureaucracy. IT teams have also been part of the problem, often taking little interest in administering or managing SaaS applications. In either case, most SaaS vendors have had relatively limited interactions with enterprise IT organizations, particularly when compared to on-premise ISVs.
We fundamentally believe that for SaaS adoption to continue to accelerate in both midmarket and large enterprises that the gap between IT requirements and SaaS application capabilities will need to be closed. SaaS vendors need to improve APIs, management access and visibility in areas such as user and identity management, activity logging and monitoring, service management and back-office/financial management. More on this to come….
Posted in Access Managment, Active Directory, Enterprise, Federated Provisioning, Identity Management, LDAP, Provisioning, SaaS, SaaS Adoption, SaaS Governance, SaaS Integration, SaaS Management, Salesforce.com, Web access management, Web applications, Web services | Leave a Comment »