Andras Cser serves Security & Risk Professionals. See the full Analyst bio.
Visit Forrester.com to learn how we make Security & Risk Professionals successful every day.
Cisco Acquires Securent - moving policy decisions to the network layer
Posted by Andras Cser on November 1, 2007
- 230 Recommendations
- 0 comments
The consolidation of the IAM market is not a new phenomenon and has been following the following pattern: a large software company with a follower IAM product set acquires a smaller IAM vendor with a proven track record to update the IAM product and services portfolio and to secure increased market presence. The acquisition of Securent by Cisco is fairly different and highlights the following trends: 1) Entitlement Management is needed so much by the market that Cisco – even though it has not traditionally been a player in the IAM space – enters the market first with an Entitlement Management product. It is surprising, as only CA has an EM product today – all other IAM vendors are still trying to build their own as the other serious competitors on the EM market, BEA ALES is not for sale as a startup. 2) Entitlement Management may be moving (along with to IAM) to operations and to the network protocol level. In fact, Cisco intends to incorporate the Secucent EMS product into the policy engine of their SONA architecture. Policy Enforcement Points (PEP) are currently implemented at the application endpoint. With this acquisition, in the future customers can implement hybrid PEPs distributed between the network and the application, thus starting to move non-business policy logic into the infrastructure layer. The omnipresence of the network is obvious, but moving policy decisions securely (without compromising network payload privacy) to the network is not immediately convincing – network operations and GRC groups are still siloed at most organizations. Given the fact that enterprises are increasingly looking for integrated IAM stacks, the entry of Cisco into the entitlement management market will require a clear strategy of becoming a provider of IAM solutions either through organic growth or by acquisition.
search forrester's blogs
Secure the digital business future.
Attend Forrester’s Forum for Security & Risk Professionals EMEA, June 10-11, London UK
Analyst Blogs
- Andras Cser (30)
- Andrew Rose (17)
- Chris McClean (54)
- Christopher Sherman (1)
- Edward Ferrara (19)
- Eve Maler (19)
- Heidi Shey (9)
- John Kindervag (28)
- Khalid Kark (13)
- Laura Koetzle (2)
- Nick Hayes (5)
- Rick Holland (20)
- Stephanie Balaouras (50)
Top Categories
- Identity and access management (7)
- Security & Risk (2)
- Acquisition (1)
- application security (1)
- cloud (1)
- Enterprise Role Management (1)
- IT Risk Management (1)
- IT security (1)
- provisioning (1)
- RSA (1)
- See all
Archives
- May 2013 (2)
- April 2013 (3)
- February 2013 (2)
- May 2012 (2)
- April 2012 (1)
- March 2012 (1)
- December 2011 (1)
- June 2011 (1)
- March 2011 (1)
- February 2011 (3)
- October 2010 (1)
- September 2010 (1)
- June 2010 (1)
- See all