<?xml version="1.0" encoding="windows-1252" ?>

<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Anakam - Anakam Two-Factor Authentication|Identity|Secure Access Management|Assurance</title> 
		<link>http://www.anakam.com/RSS/</link> 
		<language>en-us</language>
		<copyright>Copyright 2009 Anakam.com</copyright>
		<image>
			<title>Anakam - Anakam Two-Factor Authentication|Identity|Secure Access Management|Assurance</title>
			<url>http://www.anakam.com/images/rss_logo.gif</url>
			<link>http://www.anakam.com/RSS/</link>
		</image>
		<description>Two-Factor Authentication|Identity|Secure Access Management|Assurance</description>
		<atom:link href="http://www.anakam.com/RSS/" rel="self" type="application/rss+xml" />
		<item>
			<title><![CDATA[Vulnerability Assessment — Do You Know Who Is Accessing Your Data?]]></title>
			<description><![CDATA[Organizations remain accountable for data protection whether their data resides behind corporate firewalls or in the cloud, and regardless of the method by which the data is accessed.  Analyzing potential attack vectors related to remote access, identifying vulnerabilities, and implementing solutions to minimize risk of compromise is an essential part of securing systems and networks.  The threats and potential vulnerabilities involving credentials used to access corporate networks and view or transact business with corporate data need to be addressed along with more traditional defense assessments. - <a href="http://www.anakam.com/News/Blog/Policy/25/Vulnerability-Assessment/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Wed, 23 Jun 2010 00:00:00 -0700</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Policy/25/Vulnerability-Assessment/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Policy/25/Vulnerability-Assessment/]]></guid>
		</item>
		<item>
			<title><![CDATA[Context-based Identity Proofing]]></title>
			<description><![CDATA[Context-based identity proofing acknowledges how an identity will be used and is tailored to meet the levels of risk associated with the identity and the transaction.  It builds from existing levels of trust already established within an industry vertical or a group within a circle of trust. - <a href="http://www.anakam.com/News/Blog/Technical/24//" target="_blank">View Full Article</a>]]></description>
			<pubDate>Tue, 08 Jun 2010 00:00:00 -0700</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Technical/24//]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Technical/24//]]></guid>
		</item>
		<item>
			<title><![CDATA[Federation vs. Single Sign On]]></title>
			<description><![CDATA[As mobile banking webs, cloud-based databases, and electronic transaction applications continue to proliferate, the knowledge of who has access to the system and who verified the user’s identity will be essential.  The trust fabric between organizations needs to leverage identity proofing, professional credentialing, and authentication as part of a comprehensive approach to risk management. - <a href="http://www.anakam.com/News/Blog/Technical/23/Federation-vs-SSO/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Wed, 26 May 2010 00:00:00 -0700</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Technical/23/Federation-vs-SSO/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Technical/23/Federation-vs-SSO/]]></guid>
		</item>
		<item>
			<title><![CDATA[Protecting Against Willful Compromise]]></title>
			<description><![CDATA[A lock is easily opened when the owner gives the key to somebody else. This is true for gaining access to online accounts with passwords as well as second factor authentication tokens and smart cards. The act of token fraud may increase the likelihood of identity fraud, but it is fundamentally different from identity fraud, and different means of risk mitigation are needed to counter the fraud if it is a concern for the enterprise.
 - <a href="http://www.anakam.com/News/Blog/Technical/22/Willful_Compromise/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Wed, 21 Apr 2010 00:00:00 -0700</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Technical/22/Willful_Compromise/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Technical/22/Willful_Compromise/]]></guid>
		</item>
		<item>
			<title><![CDATA[Privacy and Consent in Patient Health Information]]></title>
			<description><![CDATA[The growing scale of electronic health information exchange has brought us face-to-face with the question about the extent to which patient should be able to control access to their health information. With paper records patients could decide to not tell one doctor about other doctors they were seeing, or not to tell one doctor what medications were prescribed for them by other doctors. This is being fundamentally changed by the ability to search for electronic health information and then collect and collate it.  - <a href="http://www.anakam.com/News/Blog/Policy/21/Privacy-and-Consent/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Fri, 02 Apr 2010 00:00:00 -0700</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Policy/21/Privacy-and-Consent/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Policy/21/Privacy-and-Consent/]]></guid>
		</item>
		<item>
			<title><![CDATA[Don’t Put the Key Under the Mat – Authentication AND Encryption Working Together]]></title>
			<description><![CDATA[In order to prevent different types of attacks against usernames and passwords, organizations have made the login process more difficult--passwords have become more complex, additional “security questions” have become part of the process, and some organizations have moved toward two-factor authentication either because they are required to do so by regulation or because they find the risk of unauthorized access to be too high for the type of data they house. - <a href="http://www.anakam.com/News/Blog/Policy/20/Authentication-and-Encryption/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Wed, 10 Mar 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Policy/20/Authentication-and-Encryption/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Policy/20/Authentication-and-Encryption/]]></guid>
		</item>
		<item>
			<title><![CDATA[Understanding the Identity Lifecycle—Part 3]]></title>
			<description><![CDATA[The identity lifecycle involves a series of different processes, each with its own essential role. These processes can be classified into identity creation and validation (sometimes also called “registration”), authentication, and identity change management. In this final installment in the series we will discuss how identities change and how the changes are managed over time. - <a href="http://www.anakam.com/News/Blog/Technical/19/Identity-Lifecycle-part-3/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Tue, 02 Mar 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Technical/19/Identity-Lifecycle-part-3/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Technical/19/Identity-Lifecycle-part-3/]]></guid>
		</item>
		<item>
			<title><![CDATA[Understanding the Identity Lifecycle—Part 2]]></title>
			<description><![CDATA[The identity lifecycle involves a series of different processes, each with its own essential role. These processes can be classified into identity creation and validation, authentication, and identity change management. In Part 1 of this blog series we discussed how an identity is created and validated within the enterprise. In this post we will discuss how registered identities are used to gain access to systems, applications and data. - <a href="http://www.anakam.com/News/Blog/Technical/18/Identity-Lifecycle-part-2/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Mon, 22 Feb 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Technical/18/Identity-Lifecycle-part-2/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Technical/18/Identity-Lifecycle-part-2/]]></guid>
		</item>
		<item>
			<title><![CDATA[Patient Identity and Health IT]]></title>
			<description><![CDATA[Having a way to represent the identity of a patient in electronic transactions when the patient is not present is critical. According to the HIPAA Privacy Rule, there 
are at least 17 data elements that can be used to identify a patient that must be removed before a medical record can be considered ‘de-identified’. It is 
essential that the data that represents the patient be accurately matched to the person who is the subject of this data across all records about that person. - <a href="http://www.anakam.com/News/Blog/Policy/17/Patient_Identity_Health_IT/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Tue, 16 Feb 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Policy/17/Patient_Identity_Health_IT/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Policy/17/Patient_Identity_Health_IT/]]></guid>
		</item>
		<item>
			<title><![CDATA[Telework and Corporate Security]]></title>
			<description><![CDATA[In February 2010, Federal Government offices in Washington, D.C. closed for four days because of an historic snowfall in the Washington-Baltimore region.  Last fall, President Obama declared the H1N1 flu pandemic a national emergency. These extreme examples and many other more ordinary ones highlight the importance of teleworking in today’s connected environment. - <a href="http://www.anakam.com/News/Blog/Policy/7/Corporate_Security/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Fri, 12 Feb 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Policy/7/Corporate_Security/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Policy/7/Corporate_Security/]]></guid>
		</item>
		<item>
			<title><![CDATA[Secrets and Authentication]]></title>
			<description><![CDATA[Five to ten years ago, little known facts about our lives were widely used for authentication before we were permitted access to sensitive information. Quite often 
the question was, “What was your mother’s maiden name?” This was a “shared secret” model of authentication. Over time, as more organizations use the same 
facts in various contexts, “shared secrets” become much less secret.  - <a href="http://www.anakam.com/News/Blog/Policy/16/Secrets-and-Authentication/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Wed, 10 Feb 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Policy/16/Secrets-and-Authentication/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Policy/16/Secrets-and-Authentication/]]></guid>
		</item>
		<item>
			<title><![CDATA[Understanding the Identity Lifecycle—Part 1]]></title>
			<description><![CDATA[Terminology used in the marketplace for identity management solutions is can be confusing. In some cases, the same word is used to refer to more than one element of the identity lifecycle; in other cases, a certain concept or process may be referred to by varying terms depending on the person speaking or the situation. - <a href="http://www.anakam.com/News/Blog/Technical/15/Identity-Lifecycle-part-1/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Tue, 09 Feb 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Technical/15/Identity-Lifecycle-part-1/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Technical/15/Identity-Lifecycle-part-1/]]></guid>
		</item>
		<item>
			<title><![CDATA[Multiple First Factor Questions Do Not Equal Multi-factor Authentication]]></title>
			<description><![CDATA[The FBI recently reported that the surge of Automated Clearing House (ACH) fraud committed by criminals stealing the online banking credentials of small and midsize businesses has resulted in approximately $100 million in attempted losses. As these losses have been discovered and the online security practices at the banks or credit unions in question are examined, it has become apparent that there is cause for concern in the way multi-factor authentication schemes are implemented. - <a href="http://www.anakam.com/News/Blog/Technical/14/True-Multi-Factor-Aunthentication/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Fri, 29 Jan 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Technical/14/True-Multi-Factor-Aunthentication/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Technical/14/True-Multi-Factor-Aunthentication/]]></guid>
		</item>
		<item>
			<title><![CDATA[Authentication and Electronic Signatures]]></title>
			<description><![CDATA[An interesting court case was recently sent for trial in New York federal court. The case revolves around an appropriate level of authentication for an individual who electronically signed an insurance application. - <a href="http://www.anakam.com/News/Blog/Policy/13/Electronic-Signatures/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Mon, 25 Jan 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Policy/13/Electronic-Signatures/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Policy/13/Electronic-Signatures/]]></guid>
		</item>
		<item>
			<title><![CDATA[Authentication and "Defense-in-Depth"]]></title>
			<description><![CDATA[In all successful data security systems, the goal of the organization should be to combine multiple authentication strategies with the right combination of enterprise security solutions to better assure the organization that the user on the opposite end of the online transaction is the person the company expects to be executing that specific transaction. - <a href="http://www.anakam.com/News/Blog/Technical/12/Authentication_Deep_Defense/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Tue, 19 Jan 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Technical/12/Authentication_Deep_Defense/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Technical/12/Authentication_Deep_Defense/]]></guid>
		</item>
		<item>
			<title><![CDATA[Authenticating Password Re-sets]]></title>
			<description><![CDATA[In the past few days Google has announced that its Gmail system suffered an attack in which the Chinese authorities apparently tried to gain information about activities of human rights activists. In its corporate blog, Google posted information about the attack and about how it is responding. Interestingly, some of the accounts were accessed not through a security breach at Google but through a misuse of Gmail credentials. - <a href="http://www.anakam.com/News/Blog/Policy/11/Password_Google/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Thu, 14 Jan 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Policy/11/Password_Google/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Policy/11/Password_Google/]]></guid>
		</item>
		<item>
			<title><![CDATA[PKI Is Not User Authentication]]></title>
			<description><![CDATA[We need to take a fresh look at user identity and how electronic systems establish, validate, exchange, and trust identities as more and more transactions move to the Web, and the sensitivity of those transactions grows significantly. There are choices that need to be made about how a user is authenticated in a transaction that are separate from how the transaction itself is authenticated. - <a href="http://www.anakam.com/News/Blog/Technical/10/PKI_authentication/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Wed, 13 Jan 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Technical/10/PKI_authentication/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Technical/10/PKI_authentication/]]></guid>
		</item>
		<item>
			<title><![CDATA[Proposed Rule on the Electronic Health Record Incentive Program]]></title>
			<description><![CDATA[On December 30, 2009, the Centers for Medicare & Medicaid Services issued the Proposed Rule on the Electronic Health Record Incentive Program. Together with the Interim Final Rule on Health Information Technology, they provide an initial view into the approach that the Department of Health and Human Services is taking toward ensuring that health information technology will provide privacy and security protections to individuals’ sensitive health information. - <a href="http://www.anakam.com/News/Blog/Policy/9/Electronic_Health_Records/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Wed, 06 Jan 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Policy/9/Electronic_Health_Records/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Policy/9/Electronic_Health_Records/]]></guid>
		</item>
		<item>
			<title><![CDATA[Federated: Identity or Search?]]></title>
			<description><![CDATA[The differences and best application of Federated Identity verses Federated Search can sometimes be difficult to understand and apply. An enterprise truly needs to know what they are asking for and what they will get with each of the Federated solutions.

 - <a href="http://www.anakam.com/News/Blog/Technical/8/Federated/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Tue, 05 Jan 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/Technical/8/Federated/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/Technical/8/Federated/]]></guid>
		</item>
		<item>
			<title><![CDATA[Welcome to the Anakam Blog]]></title>
			<description><![CDATA[Truly transformational eGovernment is happening, health information sharing standards are solidifying and true sharing of sensitive information is gaining 
momentum, and major new security and privacy regulations have been announced to better enable trusted information access through the Web. Anakam launched 
this blog to discuss all of these issues and many others in an interactive dialog with our partners, clients, and the broader privacy, security, and identity 
management communities. - <a href="http://www.anakam.com/News/Blog/All/6/Welcome/" target="_blank">View Full Article</a>]]></description>
			<pubDate>Mon, 04 Jan 2010 00:00:00 -0800</pubDate>
			<link><![CDATA[http://www.anakam.com/News/Blog/All/6/Welcome/]]></link>
			<guid><![CDATA[http://www.anakam.com/News/Blog/All/6/Welcome/]]></guid>
		</item>
	</channel> 
</rss>				
