#305 - Identity Week America with Ryan Galluzzo of NIST

#305 - Identity Week America with Ryan Galluzzo of NIST

In this episode of the Identity at the Center podcast, Jeff and Jim are live at the Identity Week America conference in Washington, DC. Welcoming Ryan Galluzzo, Identity Management Program Lead at NIST, they dive into recent NIST updates, including a mobile driver's license project, changes in public comment and revision processes, and the significance of user-controlled wallets. They also touch on self-sovereign identity, risk management, evolution in identity assurance levels, and the vital role of continuous evaluation and improvement. The episode concludes with a light-hearted discussion on the inquisitive nature of children and the spontaneous, enriching conversations that happen at industry conferences.

00:00 Welcome to Identity at the Center Podcast

01:26 Conference Highlights and Networking

02:47 Panel Discussions and Key Takeaways

05:07 Mobile Driver's License Project

07:09 Public Comment Draft and Feedback

11:40 Self-Sovereign Identity and Trust Issues

16:41 NIST Guidance and Risk Management

28:47 Introduction to RMF and Assurance Levels

29:05 Contextualizing Assurance Levels for Different Users

30:25 Continuous Evaluation and Improvement

34:28 User-Controlled Wallets and Federation

35:59 Account Recovery and Assurance Levels

37:18 Overview of NIST 800-63 Documents

51:25 Existential Questions and Personal Anecdotes

55:25 Conclusion and Final Thoughts

Connect with Ryan: ⁠https://www.linkedin.com/in/ryan-galluzzo-a100563b/⁠

Authenticate Conference - Use code IDAC15 for 15% off: ⁠https://authenticatecon.com/event/authenticate-2024-conference/⁠

Connect with us on LinkedIn:

Jim McDonald: ⁠https://www.linkedin.com/in/jimmcdonaldpmp/⁠

Jeff Steadman: ⁠https://www.linkedin.com/in/jeffsteadman/⁠

Visit the show on the web at ⁠http://idacpodcast.com⁠ and watch at ⁠https://www.youtube.com/@idacpodcast

Jaksot(395)

Identity at the Center #59 - Optimizing Security & Convenience with Frank Villavicencio

Identity at the Center #59 - Optimizing Security & Convenience with Frank Villavicencio

Jim and Jeff talk with Frank Villavicencio, Head of Product for Shared Services at ADP, about the IAM user experience and how to optimize security and convenience. Connect with Frank on LinkedIn here: https://www.linkedin.com/in/fvillavicencio/ IDSA Webinar - Hacking Identity: The Good, Bad and Ugly of Identity-Centric Security Controls with Jerod Brennen of SailPoint: https://www.idsalliance.org/webinar-hacking-identity-the-good-bad-and-ugly-of-identity-centric-security-controls/ Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show at www.IdentityAtTheCenter.comand follow @IDACPodcast on Twitter.

31 Elo 202059min

Identity at the Center #58 - Browser Tracking and the Identity Effects with Vittorio Bertocci

Identity at the Center #58 - Browser Tracking and the Identity Effects with Vittorio Bertocci

Jim and Jeff talk with Vittorio Bertocci, Principal Architect with Auth0, about the effects of browser tracking and how it is affecting the identity space. Connect with Vittorio on LinkedIn here: https://www.linkedin.com/in/vittoriobertocci/ Follow Vittorio on Twitter @vibronet Learn more about Auth0 here: www.auth0.com Listen to the Identity Unlocked Podcast: www.identityunlocked.com Check out the Identiverse On-Demand Session "Browser Features vs Identity Protocols: An Arms Race?" from June 17th, 2020 and "Modern Identity for Developers 101" from July 27th, 2020 here: https://portal.inxpo.com/ID/PingIdentity/IdentiverseVirtual/ Books mentioned on the show: The Age of Surveillance Capitalism: https://www.amazon.com/Age-Surveillance-Capitalism-Future-Frontier/dp/1610395697 21 Lessons for the 21st Century: https://www.amazon.com/Lessons-21st-Century-Yuval-Harari/dp/0525512179 Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcaston Twitter.

24 Elo 202059min

Identity at the Center #57 - Learning about the Identity Defined Security Alliance with Julie Smith

Identity at the Center #57 - Learning about the Identity Defined Security Alliance with Julie Smith

Jim and Jeff talk with Julie Smith, Executive Director of the Identity Defined Security Alliance (IDSA), about their mission, IAM frameworks they have developed, and future focus. Episode Links: Connect with Julie on LinkedIn here: https://www.linkedin.com/in/juliaesmith/ Follow them on Twitter: @IDSAlliance IDSA Security Outcomes: https://securityoutcomes.idsalliance.org/ Learn more about the Identity Defined Security Alliance: https://www.idsalliance.org Best practices: https://www.idsalliance.org/identity-defined-security-framework/best-practices/ Zero Trust: https://www.idsalliance.org/identity-defined-security-framework/use-cases/ Webinar - Hacking Identity: The Good, Bad and Ugly of Identity-Centric Security Controls: https://www.brighttalk.com/webcast/18458/430843 Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show at www.IdentityAtTheCenter.comand follow @IDACPodcast on Twitter.

17 Elo 202045min

Identity at the Center #56 - What is FIDO with Andrew Shikiar

Identity at the Center #56 - What is FIDO with Andrew Shikiar

Jim and Jeff talk with Andrew Shikiar, Executive Director and Chief Marketing Officer of the FIDO Alliance, about what FIDO is and the challenges it seeks to solve. FIDO Alliance website: https://fidoalliance.org FIDO paper: https://fidoalliance.org/white-paper-cxo-explanation-why-use-fido-for-passwordless-employee-logins/ Authenticate 2020 conference (free!): https://authenticatecon.com/ Krisp.AI is the microphone noise reduction software mentioned on the show. They are not a sponsor of the show, but a software we like. You can learn more at https://krisp.ai/ or you can use Jeff's referral link to get a free extra month of pro by clicking here: https://ref.krisp.ai/u/u5dc480464 Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcast on Twitter.

10 Elo 202046min

Identity at the Center #55 - Solving Identity Challenges with MFA

Identity at the Center #55 - Solving Identity Challenges with MFA

Jim and Jeff talk about the challenges of multifactor authentication and solving some of the unique challenges that come with it. A Security Update From Instacart: https://news.instacart.com/a-security-update-from-instacart-89beb7bf5121 NIST 800-63-3 and Levels of Assurance: https://pages.nist.gov/800-63-3/sp800-63-3.html Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcaston Twitter.

3 Elo 202049min

Identity at the Center #54 - Mark Perry on Open Banking

Identity at the Center #54 - Mark Perry on Open Banking

Jim and Jeff talk with Mark Perry, CTO for Ping Identity APAC region, about his Identiverse talks around the user experience with IAM and the Open Banking Standard. Connect with Mark on LinkedIn here: https://www.linkedin.com/in/markperryau/ Mark's Identiverse Talks: https://portal.inxpo.com/ID/PingIdentity/IdentiverseVirtual/ June 15th - Stop Blaming the End User! Using Empathy and Understanding to Deliver Better Identity Experiences. July 28th - Will User Experience Kill Open Banking? Learn more about the Open Banking Standard here: https://standards.openbanking.org.uk/ Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcast on Twitter.

27 Heinä 202042min

Identity at the Center #53 - Twitter, MGM, and ITSM IGA with Darran Rolls

Identity at the Center #53 - Twitter, MGM, and ITSM IGA with Darran Rolls

Jim and Jeff talk with Darran Rolls, former CTO and CISO at SailPoint and current "Identity Dude" about the recent Twitter breach, the new revelations as to the scope of the MGM data leak, and how ITSM is positioned as a platform to build IGA services on. Visit Darran on the web here: https://darranrolls.com/ Connect with Darran on LinkedIn here: https://www.linkedin.com/in/darran-rolls-068b84 Get Darran’s book here: https://darranrolls.com/general/identity-attack-vectors/ Twitter Breach: https://www.chicagotribune.com/business/ct-biz-twitter-bitcoin-hack-cybersecurity-20200716-frecqlxiczf7nipn7yiwrv6uz4-story.html MGM incident update: https://www.zdnet.com/article/a-hacker-is-selling-details-of-142-million-mgm-hotel-guests-on-the-dark-web/ Connect with Jim and Jeff on LinkedIn here: Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/ Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/ Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcast on Twitter.

20 Heinä 202056min

Identity at the Center #52 - Jackson Shaw, IAM Jedi

Identity at the Center #52 - Jackson Shaw, IAM Jedi

Jim and Jeff talk with an IAM Knight of the Old Republic, Jackson Shaw, about his 36 years in the IAM space, some of his observations over the years, and the intersection of IT Service Management (ITSM) platforms and Identity Governance & Administration (IGA) technologies. Connect with Jackson on LinkedIn here: https://www.linkedin.com/in/jshaw Follow Jackson on Twitter @JacksonShaw "Jackson’s List of Things About IAM"™ (Working Title): Conferences & Organizations: Martin Kuppinger & KuppingerCole – Their conferences (identity, CIAM, security) and YouTube channel – www.kuppingercole.com Gary Rowe & Techvision Research - https://techvisionresearch.com/ Gartner – www.gartner.com Forrester – www.forrester.com Identiverse conference – www.identiverse.com IDPro – www.idpro.com Books: Powerful, Patty McCord Death by Meeting, Patrick Lencioni Steve Jobs, Walter Isaacson Surrounded by Idiots, Thomas Erikson Power Presentations, Jerry Weissman & his website www.besuasive.com Visit the show at www.IdentityAtTheCenter.com and follow @IDACPodcast on Twitter.

13 Heinä 202054min