Spring 2011 Internet2 Member Meeting

Use Internet2 SiteID

Already have an Internet2 SiteID?
Sign in here.

Internet2 SiteID

Balancing Risk and Opportunity for an Institutional Groups Service

Time 04/19/11 08:45AM-10:00AM

Session Abstract

Provisioning employee and student groups into an institutional groups service raises hard questions about data classification and appropriate access controls. At the UW, the IAM team collaborated with institutional data custodians and used a risk-based approach to classify groups provisioned from HR and student systems and evaluate their access controls. The access controls for most groups were found to provide an appropriate balance between minimizing risks and capturing opportunities, but controls on some groups were updated. The working meetings between IAM staff and data custodians provided a valuable opportunity to exchange perspectives from different domains of expertise and helped data custodians take ownership of access control decisions.


Speaker Michael Brogan University of Washington

Presentation Media

Secondary tracks Security Middleware Governance

gold Sponsors

supporter Sponsors