Title: Comments on Identity Management IdM at CSU
1Comments on Identity Management (IdM) at CSU
- Pat Burns, AVPIIT
- For June 13 IAC Meeting
- 2-4 PM
- Weber 202
2Outline
- Central IT Resources in ACNS trends
- Because resources are an essential requirement
- ACNS comments on IdM
- After detailed consideration over several years
3Resources in ACNS Before and After Last Self
Assessment
4ACNS Systems Services 1999/2000
8 Servers
5ACNS Systems Services Today
30 Unix Servers
43 Windows Servers
6ACNS Networking - 1999/2000
7ACNS Networking - Today
8ACNS Staffing Before and After1999/2000
Today
29 FTE, 22 Funded Centrally
34 FTE, 33 Funded Centrally
9Trends
Staffing
Number, volume, criticality, complexity, and
scope of services
Service Quality Issues
Time
Today
1999/2000
10Informal Survey of Peers- Central IT Staff
Avg/CSU 4.301
11Informal Survey of Peers- Central IT
Avg/CSU 4.411
12ACNS Comments on IdM
13Why We in ACNS are Hesitant to Embark upon
Additional IdM Activities
- Over the past three years, ACNS has thoroughly
investigated and scoped IdM - Last Fall, ACNS sent 3 of its best people (Scott
Baily, Eric Galyon and Rusty Scott) to an
extensive Middleware conference on iDM - Staff in ACNS have, in addition, attended
numerous presentations on IdM from EDUCAUSE and
Internet2 - Conclusion was that IdM is a vast area, requires
substantial resources to address, is campuswide
in scope, and can not be done piecemeal
14Why We in ACNS are Hesitant to Embark upon
(contd)
- ACNS is already overwhelmed with addressing
existing IdM issues - Banner now writing 10,000 lines of IdM code to
accommodate Applicants in Banner, and are out of
time to complete and test this code - WebCT automated feeds from Banner involve IdM
issues - Keyless access deployment will involve IdM issues
- New FRS/RMS would involve IdM issues
- Additional IdM would complicate our operational
and support environments perpetually
15Why We in ACNS are Hesitant to Embark upon
(contd)
- Current areas for additional effort are
- IT security, and
- Fixing operational problems with email
- We are reluctant to embark upon additional new
projects, especially large ones, until these
problems are addressed
16Why We in ACNS are Hesitant to Embark upon
(contd)
- IdM is a University issue, and is not just
limited to IT - An effort to change our IdM should engage the
larger problem, and involve how individuals get
into and out of our systems, and is not just an
IT issue - Requires the Registrar, Admissions, HR, the ID
Card Office, etc. to be at the table - Requires a wholesale change in the way we operate
permeating all departments
17Why We in ACNS are Hesitant to Embark upon
(contd)
- An IT Best Practice is not to let project
scopes be expanded to the point where they will
not be successful - We are in danger of doing this here