On "Consent Management"
Mon, 2008-01-07 15:54

I just found Marco's blog the other day, and I'm glad I did.

Marco writes about something he believes will grow in importance in 2008 in the world of identity management - "consent management." Consent Management is, "the active management and enforcement of users' consent when collecting, storing, accessing, processing and disclosing personal data."

Now, in the circles of the identirati, ownership and control of personal identity data has been the subject of debate since the beginning of identity technology. But in a larger realm, that has not been the case, with individuals often willing to give up their sensitive information for a free coffee or candy bar.

The recent kerfluffle with Robert Scoble and Facebook has got the alpha geek-sphere buzzing with the "who owns my data?" question. Despite the fact that their asking the wrong question (its not about ownership, its about control), their collective attention will, over time, translate into a workforce that is concerned about issues of -- you guessed it -- consent.

One of the big ideas that I was kicking around a couple of years ago when Kim Cameron first wrote his "laws of identity" was how "user-centric identity" would someday alter the architecture of identity management within the enterprise. Its now beginning to look like social networking may be the vehicle that drives us toward that alteration. Notice too, that as "social networking" drives us toward consent management, we find ourselves with *another* critical piece in identity that is suddenly very related to collaboration (the other, I argue, is federation). Could it be a larger wave occurring? Is identity ultimately to be driven more by "collaboration" than "security?"

Hmmmm....

No matter, in the meantime, its time for architects and CIOs everywhere to start thinking about how their going to deal with the issue of consent when their workforce rises up and demands it.

--Eric Norlin

Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
* Denotes a required field
WEBCAST
Gartner Video: Best Practices for Web Application Security and Compliance

Cenzic Faced with the growing threat of hacker attacks, how do you protect your data and your corporate reputation while increasing revenue?

» View this Webcast

WHITE PAPER
Email Continuity: Don't Know What You've Got Till it's Gone

MessageLabs Today, more email is being sent and attachment sizes are becoming larger. This means that security, archiving, and continuity systems must be able to scale easily. Learn to manage your email better…

» View this White Paper