<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ZapThink &#187; Waveset</title>
	<atom:link href="http://www.zapthink.com/tag/waveset/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.zapthink.com</link>
	<description>Sharpening Your Vision of the Future of IT</description>
	<lastBuildDate>Fri, 10 Feb 2012 18:12:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>OASIS Stamps Approval on Provisioning Standard</title>
		<link>http://www.zapthink.com/2003/11/20/oasis-stamps-approval-on-provisioning-standard/</link>
		<comments>http://www.zapthink.com/2003/11/20/oasis-stamps-approval-on-provisioning-standard/#comments</comments>
		<pubDate>Thu, 20 Nov 2003 00:11:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[In the News]]></category>
		<category><![CDATA[BEA Systems]]></category>
		<category><![CDATA[BMC Software]]></category>
		<category><![CDATA[Business Layers]]></category>
		<category><![CDATA[Computer Associates]]></category>
		<category><![CDATA[Entrust]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Netegrity]]></category>
		<category><![CDATA[OpenNetwork]]></category>
		<category><![CDATA[Security & Identity Management]]></category>
		<category><![CDATA[Service-Oriented Architecture (SOA)]]></category>
		<category><![CDATA[Sun Microsystems]]></category>
		<category><![CDATA[Waveset]]></category>
		<category><![CDATA[Web Services]]></category>
		<category><![CDATA[Web Services Management]]></category>

		<guid isPermaLink="false">http://test.zapthink.com/?p=860</guid>
		<description><![CDATA[Previously, there was no one way to do this in a uniform manner. With SPML, companies don't have to waste what could be millions of dollars on development work in order to get people provisioned or deprovisioned, said ZapThink Senior Analyst Ronald Schmelzer.
<p>
"What this means for companies is that as they purchase applications that require some sort of user access, they should make sure that they have a standard way of provisioning users on, and deprovisioning users from that application," Schmelzer told internetnews.com.
<p>
"SPML will most likely work within a broader framework for enterprise-wide security infrastructure such as those provided by other standardization initiatives, such as WS-Security and WS-Policy," he said. "WS-Security and WS-Policy are more concerned with specific user access to business logic, but there are clearly going to be cases when the two specifications will need to overlap. At the very least, any comprehensive security platform for Web Services will need to handle both of these sets of specifications -- provisioning of physical and virtual assets and the access to these applications." <p/>Read more at: <a href='http://www.internetnews.com/dev-news/article.php/3111561' target='_new'>Internetnews.com</a>]]></description>
			<content:encoded><![CDATA[<p>Previously, there was no one way to do this in a uniform manner. With SPML, companies don&#8217;t have to waste what could be millions of dollars on development work in order to get people provisioned or deprovisioned, said ZapThink Senior Analyst Ronald Schmelzer.</p>
<p>
&#8220;What this means for companies is that as they purchase applications that require some sort of user access, they should make sure that they have a standard way of provisioning users on, and deprovisioning users from that application,&#8221; Schmelzer told internetnews.com.</p>
<p>
&#8220;SPML will most likely work within a broader framework for enterprise-wide security infrastructure such as those provided by other standardization initiatives, such as WS-Security and WS-Policy,&#8221; he said. &#8220;WS-Security and WS-Policy are more concerned with specific user access to business logic, but there are clearly going to be cases when the two specifications will need to overlap. At the very least, any comprehensive security platform for Web Services will need to handle both of these sets of specifications &#8212; provisioning of physical and virtual assets and the access to these applications.&#8221;
<p/>Read more at: <a href='http://www.internetnews.com/dev-news/article.php/3111561' target='_new'>Internetnews.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zapthink.com/2003/11/20/oasis-stamps-approval-on-provisioning-standard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web services ID management touted</title>
		<link>http://www.zapthink.com/2003/06/26/web-services-id-management-touted/</link>
		<comments>http://www.zapthink.com/2003/06/26/web-services-id-management-touted/#comments</comments>
		<pubDate>Thu, 26 Jun 2003 00:06:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[In the News]]></category>
		<category><![CDATA[BMC Software]]></category>
		<category><![CDATA[Business Layers]]></category>
		<category><![CDATA[Entrust]]></category>
		<category><![CDATA[OASIS]]></category>
		<category><![CDATA[OpenNetwork]]></category>
		<category><![CDATA[PeopleSoft]]></category>
		<category><![CDATA[Sun Microsystems]]></category>
		<category><![CDATA[Thor Technologies]]></category>
		<category><![CDATA[TruLogica]]></category>
		<category><![CDATA[Waveset]]></category>
		<category><![CDATA[Web Services Management]]></category>

		<guid isPermaLink="false">http://test.zapthink.com/?p=621</guid>
		<description><![CDATA["SPML adds to the identity management capabilities by providing a standard way in which access to these critical infrastructure resources can be granted or denied," said analyst Ronald Schmelzer of ZapThink in Waltham, Mass. "This means that companies can build applications that have strict identity and security policies without having to do so in a proprietary and noninteroperable manner."

"While SPML has more to do with provisioning physical access to specific resources, there is definitely potential for overlap or at least complementary offering to the WS-Security and WS-Policy specifications," Schmelzer said.<p/>Read more at: <a href='http://www.infoworld.com/article/03/06/26/HNspml_1.html' target='_new'>InfoWorld</a>]]></description>
			<content:encoded><![CDATA[<p>&#8220;SPML adds to the identity management capabilities by providing a standard way in which access to these critical infrastructure resources can be granted or denied,&#8221; said analyst Ronald Schmelzer of ZapThink in Waltham, Mass. &#8220;This means that companies can build applications that have strict identity and security policies without having to do so in a proprietary and noninteroperable manner.&#8221;</p>
<p>&#8220;While SPML has more to do with provisioning physical access to specific resources, there is definitely potential for overlap or at least complementary offering to the WS-Security and WS-Policy specifications,&#8221; Schmelzer said.
<p/>Read more at: <a href='http://www.infoworld.com/article/03/06/26/HNspml_1.html' target='_new'>InfoWorld</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zapthink.com/2003/06/26/web-services-id-management-touted/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OASIS Forms Committee to Promote BPEL</title>
		<link>http://www.zapthink.com/2003/04/29/oasis-forms-committee-to-promote-bpel/</link>
		<comments>http://www.zapthink.com/2003/04/29/oasis-forms-committee-to-promote-bpel/#comments</comments>
		<pubDate>Tue, 29 Apr 2003 00:04:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[In the News]]></category>
		<category><![CDATA[BEA Systems]]></category>
		<category><![CDATA[Commerce One]]></category>
		<category><![CDATA[E2open]]></category>
		<category><![CDATA[EDS]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Intalio]]></category>
		<category><![CDATA[IONA]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[NEC]]></category>
		<category><![CDATA[Novell]]></category>
		<category><![CDATA[OASIS]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[SAP]]></category>
		<category><![CDATA[SeeBeyond]]></category>
		<category><![CDATA[Service-Oriented Process]]></category>
		<category><![CDATA[Siebel Systems]]></category>
		<category><![CDATA[Sun Microsystems]]></category>
		<category><![CDATA[Sybase]]></category>
		<category><![CDATA[TIBCO]]></category>
		<category><![CDATA[Vignette]]></category>
		<category><![CDATA[Waveset]]></category>

		<guid isPermaLink="false">http://test.zapthink.com/?p=511</guid>
		<description><![CDATA[Ronald Schmelzer, an analyst with ZapThink LLC, a Cambridge, Mass., market research firm, said: "The submission of BPEL to OASIS is a great step for BPEL as well as Web Services in general. BPEL is a key specification aimed at providing a mechanism by which Web Services can be orchestrated into business processes, which can then be exchanged and choreographed with external processes. Business process is a critical aspect of adoption of Web Services and especially Service-Oriented Architectures since business processes are how companies define their business requirements that must then be implemented with Web Services. Without process, all you have is a jumble of Web Services. Specifications like BPEL bring order to the chaos by specifying a logical flow by which Web Services can be orchestrated to meet defined business requirements." <p/>Read more at: <a href='http://www.eweek.com/article2/0,3959,1047671,00.asp' target='_new'>eWeek</a>]]></description>
			<content:encoded><![CDATA[<p>Ronald Schmelzer, an analyst with ZapThink LLC, a Cambridge, Mass., market research firm, said: &#8220;The submission of BPEL to OASIS is a great step for BPEL as well as Web Services in general. BPEL is a key specification aimed at providing a mechanism by which Web Services can be orchestrated into business processes, which can then be exchanged and choreographed with external processes. Business process is a critical aspect of adoption of Web Services and especially Service-Oriented Architectures since business processes are how companies define their business requirements that must then be implemented with Web Services. Without process, all you have is a jumble of Web Services. Specifications like BPEL bring order to the chaos by specifying a logical flow by which Web Services can be orchestrated to meet defined business requirements.&#8221;
<p/>Read more at: <a href='http://www.eweek.com/article2/0,3959,1047671,00.asp' target='_new'>eWeek</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zapthink.com/2003/04/29/oasis-forms-committee-to-promote-bpel/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Overview of Web Services Security</title>
		<link>http://www.zapthink.com/2003/04/17/overview-of-web-services-security/</link>
		<comments>http://www.zapthink.com/2003/04/17/overview-of-web-services-security/#comments</comments>
		<pubDate>Thu, 17 Apr 2003 00:04:00 +0000</pubDate>
		<dc:creator>Jason Bloomberg</dc:creator>
				<category><![CDATA[Presentation]]></category>
		<category><![CDATA[Actional]]></category>
		<category><![CDATA[AmberPoint]]></category>
		<category><![CDATA[Baltimore Technologies]]></category>
		<category><![CDATA[Bang Networks]]></category>
		<category><![CDATA[BEA Systems]]></category>
		<category><![CDATA[Bowstreet]]></category>
		<category><![CDATA[Cape Clear]]></category>
		<category><![CDATA[Computer Associates]]></category>
		<category><![CDATA[EDS]]></category>
		<category><![CDATA[Entegrity]]></category>
		<category><![CDATA[Entrust]]></category>
		<category><![CDATA[Flamenco Networks]]></category>
		<category><![CDATA[Grand Central Communications]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Internet Security Systems]]></category>
		<category><![CDATA[IONA]]></category>
		<category><![CDATA[Liberty Alliance]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[nCipher]]></category>
		<category><![CDATA[Netegrity]]></category>
		<category><![CDATA[Novell]]></category>
		<category><![CDATA[Oblix]]></category>
		<category><![CDATA[OneName]]></category>
		<category><![CDATA[OpenNetwork]]></category>
		<category><![CDATA[Phaos Technology Corp.]]></category>
		<category><![CDATA[PricewaterhouseCoopers]]></category>
		<category><![CDATA[Primordial]]></category>
		<category><![CDATA[Quadrasis]]></category>
		<category><![CDATA[Reactivity]]></category>
		<category><![CDATA[RSA Security]]></category>
		<category><![CDATA[Security & Identity Management]]></category>
		<category><![CDATA[SeeBeyond]]></category>
		<category><![CDATA[Slam Dunk Networks]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Systinet]]></category>
		<category><![CDATA[TIBCO]]></category>
		<category><![CDATA[TruSecure]]></category>
		<category><![CDATA[VeriSign]]></category>
		<category><![CDATA[Vitria]]></category>
		<category><![CDATA[Vordel]]></category>
		<category><![CDATA[Waveset]]></category>
		<category><![CDATA[webMethods]]></category>
		<category><![CDATA[Westbridge Technology]]></category>

		<guid isPermaLink="false">http://test.zapthink.com/?p=ZTP-0122</guid>
		<description><![CDATA[Download File]]></description>
			<content:encoded><![CDATA[<p><a href='?file_id=OverviewWSSecurity-Samsung-042003-ZTP-0122-1.pdf' class='download'>Download File</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zapthink.com/2003/04/17/overview-of-web-services-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Services Security Technologies &amp; Markets</title>
		<link>http://www.zapthink.com/2002/10/25/web-services-security-technologies-markets/</link>
		<comments>http://www.zapthink.com/2002/10/25/web-services-security-technologies-markets/#comments</comments>
		<pubDate>Fri, 25 Oct 2002 00:10:00 +0000</pubDate>
		<dc:creator>Jason Bloomberg</dc:creator>
				<category><![CDATA[Presentation]]></category>
		<category><![CDATA[Actional]]></category>
		<category><![CDATA[AmberPoint]]></category>
		<category><![CDATA[Baltimore Technologies]]></category>
		<category><![CDATA[Bang Networks]]></category>
		<category><![CDATA[BEA Systems]]></category>
		<category><![CDATA[Bowstreet]]></category>
		<category><![CDATA[Cape Clear]]></category>
		<category><![CDATA[Computer Associates]]></category>
		<category><![CDATA[EDS]]></category>
		<category><![CDATA[Entegrity]]></category>
		<category><![CDATA[Entrust]]></category>
		<category><![CDATA[Flamenco Networks]]></category>
		<category><![CDATA[Grand Central Communications]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Internet Security Systems]]></category>
		<category><![CDATA[IONA]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[nCipher]]></category>
		<category><![CDATA[Netegrity]]></category>
		<category><![CDATA[Novell]]></category>
		<category><![CDATA[Oblix]]></category>
		<category><![CDATA[OneName]]></category>
		<category><![CDATA[OpenNetwork]]></category>
		<category><![CDATA[Phaos Technology Corp.]]></category>
		<category><![CDATA[PricewaterhouseCoopers]]></category>
		<category><![CDATA[Primordial]]></category>
		<category><![CDATA[Quadrasis]]></category>
		<category><![CDATA[Reactivity]]></category>
		<category><![CDATA[RSA Security]]></category>
		<category><![CDATA[Security & Identity Management]]></category>
		<category><![CDATA[SeeBeyond]]></category>
		<category><![CDATA[Slam Dunk Networks]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Systinet]]></category>
		<category><![CDATA[TIBCO]]></category>
		<category><![CDATA[TruSecure]]></category>
		<category><![CDATA[VeriSign]]></category>
		<category><![CDATA[Vitria]]></category>
		<category><![CDATA[Vordel]]></category>
		<category><![CDATA[Waveset]]></category>
		<category><![CDATA[webMethods]]></category>
		<category><![CDATA[Westbridge Technology]]></category>

		<guid isPermaLink="false">http://test.zapthink.com/?p=ZTP-0103</guid>
		<description><![CDATA[Download File]]></description>
			<content:encoded><![CDATA[<p><a href='?file_id=WSSecurity-DCI-102002-ZTP-0103-1.pdf' class='download'>Download File</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zapthink.com/2002/10/25/web-services-security-technologies-markets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Services Security</title>
		<link>http://www.zapthink.com/2002/10/15/web-services-security/</link>
		<comments>http://www.zapthink.com/2002/10/15/web-services-security/#comments</comments>
		<pubDate>Tue, 15 Oct 2002 00:10:00 +0000</pubDate>
		<dc:creator>Jason Bloomberg</dc:creator>
				<category><![CDATA[Presentation]]></category>
		<category><![CDATA[Actional]]></category>
		<category><![CDATA[AmberPoint]]></category>
		<category><![CDATA[Baltimore Technologies]]></category>
		<category><![CDATA[Bang Networks]]></category>
		<category><![CDATA[BEA Systems]]></category>
		<category><![CDATA[Bowstreet]]></category>
		<category><![CDATA[Cape Clear]]></category>
		<category><![CDATA[Computer Associates]]></category>
		<category><![CDATA[EDS]]></category>
		<category><![CDATA[Entegrity]]></category>
		<category><![CDATA[Entrust]]></category>
		<category><![CDATA[Flamenco Networks]]></category>
		<category><![CDATA[Grand Central Communications]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Internet Security Systems]]></category>
		<category><![CDATA[IONA]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[nCipher]]></category>
		<category><![CDATA[Netegrity]]></category>
		<category><![CDATA[Novell]]></category>
		<category><![CDATA[Oblix]]></category>
		<category><![CDATA[OneName]]></category>
		<category><![CDATA[OpenNetwork]]></category>
		<category><![CDATA[Phaos Technology Corp.]]></category>
		<category><![CDATA[PricewaterhouseCoopers]]></category>
		<category><![CDATA[Primordial]]></category>
		<category><![CDATA[Quadrasis]]></category>
		<category><![CDATA[Reactivity]]></category>
		<category><![CDATA[RSA Security]]></category>
		<category><![CDATA[Security & Identity Management]]></category>
		<category><![CDATA[SeeBeyond]]></category>
		<category><![CDATA[Slam Dunk Networks]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Systinet]]></category>
		<category><![CDATA[TIBCO]]></category>
		<category><![CDATA[TruSecure]]></category>
		<category><![CDATA[VeriSign]]></category>
		<category><![CDATA[Vitria]]></category>
		<category><![CDATA[Vordel]]></category>
		<category><![CDATA[Waveset]]></category>
		<category><![CDATA[webMethods]]></category>
		<category><![CDATA[Westbridge Technology]]></category>

		<guid isPermaLink="false">http://test.zapthink.com/?p=ZTP-0102</guid>
		<description><![CDATA[Download File]]></description>
			<content:encoded><![CDATA[<p><a href='?file_id=WSSecurity-Beacon-102002-ZTP-0102-1.pdf' class='download'>Download File</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zapthink.com/2002/10/15/web-services-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What You Need to Know About Web Services Security</title>
		<link>http://www.zapthink.com/2002/10/06/what-you-need-to-know-about-web-services-security/</link>
		<comments>http://www.zapthink.com/2002/10/06/what-you-need-to-know-about-web-services-security/#comments</comments>
		<pubDate>Sun, 06 Oct 2002 00:10:00 +0000</pubDate>
		<dc:creator>Jason Bloomberg</dc:creator>
				<category><![CDATA[Presentation]]></category>
		<category><![CDATA[Actional]]></category>
		<category><![CDATA[AmberPoint]]></category>
		<category><![CDATA[Baltimore Technologies]]></category>
		<category><![CDATA[Bang Networks]]></category>
		<category><![CDATA[BEA Systems]]></category>
		<category><![CDATA[Bowstreet]]></category>
		<category><![CDATA[Cape Clear]]></category>
		<category><![CDATA[Computer Associates]]></category>
		<category><![CDATA[EDS]]></category>
		<category><![CDATA[Entegrity]]></category>
		<category><![CDATA[Entrust]]></category>
		<category><![CDATA[Flamenco Networks]]></category>
		<category><![CDATA[Grand Central Communications]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Internet Security Systems]]></category>
		<category><![CDATA[IONA]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[nCipher]]></category>
		<category><![CDATA[Netegrity]]></category>
		<category><![CDATA[Novell]]></category>
		<category><![CDATA[Oblix]]></category>
		<category><![CDATA[OneName]]></category>
		<category><![CDATA[OpenNetwork]]></category>
		<category><![CDATA[Phaos Technology Corp.]]></category>
		<category><![CDATA[PricewaterhouseCoopers]]></category>
		<category><![CDATA[Primordial]]></category>
		<category><![CDATA[Quadrasis]]></category>
		<category><![CDATA[Reactivity]]></category>
		<category><![CDATA[RSA Security]]></category>
		<category><![CDATA[Security & Identity Management]]></category>
		<category><![CDATA[SeeBeyond]]></category>
		<category><![CDATA[Slam Dunk Networks]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Systinet]]></category>
		<category><![CDATA[TIBCO]]></category>
		<category><![CDATA[TruSecure]]></category>
		<category><![CDATA[VeriSign]]></category>
		<category><![CDATA[Vitria]]></category>
		<category><![CDATA[Vordel]]></category>
		<category><![CDATA[Waveset]]></category>
		<category><![CDATA[webMethods]]></category>
		<category><![CDATA[Westbridge Technology]]></category>

		<guid isPermaLink="false">http://test.zapthink.com/?p=ZTP-0101</guid>
		<description><![CDATA[Download File]]></description>
			<content:encoded><![CDATA[<p><a href='?file_id=WSSecurity-TechTarget-102002-ZTP-0101-1.pdf' class='download'>Download File</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zapthink.com/2002/10/06/what-you-need-to-know-about-web-services-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;Five Things You Should Know About Internet Identity&#8221;</title>
		<link>http://www.zapthink.com/2002/07/18/five-things-you-should-know-about-internet-identity/</link>
		<comments>http://www.zapthink.com/2002/07/18/five-things-you-should-know-about-internet-identity/#comments</comments>
		<pubDate>Thu, 18 Jul 2002 00:07:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[In the News]]></category>
		<category><![CDATA[Boeing]]></category>
		<category><![CDATA[Liberty Alliance]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Netegrity]]></category>
		<category><![CDATA[Novell]]></category>
		<category><![CDATA[Oblix]]></category>
		<category><![CDATA[OpenNetwork]]></category>
		<category><![CDATA[Reactivity]]></category>
		<category><![CDATA[Security & Identity Management]]></category>
		<category><![CDATA[Sun Microsystems]]></category>
		<category><![CDATA[Waveset]]></category>

		<guid isPermaLink="false">http://test.zapthink.com/?p=132</guid>
		<description><![CDATA[For instance, consulting company ZapThink was very critical of the initial Liberty release, in large part because it fails to respect the privacy of users, said Jason Bloomberg, ZapThink analyst. "It's as much about perception as it is reality," said Bloomberg. "Version one leaves open for discussion how to manage privacy issues surrounding user information. They say it's up to the policies of individual companies, or that it may be further addressed in version two [of the specification]."<p/>Read more at: <a href='http://www.internetweek.com/security02/INW20020718S0008' target='_new'>InternetWeek</a>]]></description>
			<content:encoded><![CDATA[<p>For instance, consulting company ZapThink was very critical of the initial Liberty release, in large part because it fails to respect the privacy of users, said Jason Bloomberg, ZapThink analyst. &#8220;It&#8217;s as much about perception as it is reality,&#8221; said Bloomberg. &#8220;Version one leaves open for discussion how to manage privacy issues surrounding user information. They say it&#8217;s up to the policies of individual companies, or that it may be further addressed in version two [of the specification].&#8221;
<p/>Read more at: <a href='http://www.internetweek.com/security02/INW20020718S0008' target='_new'>InternetWeek</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zapthink.com/2002/07/18/five-things-you-should-know-about-internet-identity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ZapNote: Waveset</title>
		<link>http://www.zapthink.com/2002/06/20/zapnote-waveset/</link>
		<comments>http://www.zapthink.com/2002/06/20/zapnote-waveset/#comments</comments>
		<pubDate>Thu, 20 Jun 2002 00:06:00 +0000</pubDate>
		<dc:creator>Jason Bloomberg</dc:creator>
				<category><![CDATA[ZapNote]]></category>
		<category><![CDATA[Liberty Alliance]]></category>
		<category><![CDATA[Netegrity]]></category>
		<category><![CDATA[Security & Identity Management]]></category>
		<category><![CDATA[Waveset]]></category>

		<guid isPermaLink="false">http://test.zapthink.com/?p=ZTZN-1106</guid>
		<description><![CDATA[Download File]]></description>
			<content:encoded><![CDATA[<p><a href='?file_id=Waveset-062002-ZTZN-1106-1S.pdf' class='download'>Download File</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zapthink.com/2002/06/20/zapnote-waveset/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>XML and Web Services Security</title>
		<link>http://www.zapthink.com/2002/06/20/xml-and-web-services-security/</link>
		<comments>http://www.zapthink.com/2002/06/20/xml-and-web-services-security/#comments</comments>
		<pubDate>Thu, 20 Jun 2002 00:06:00 +0000</pubDate>
		<dc:creator>Jason Bloomberg</dc:creator>
				<category><![CDATA[Report]]></category>
		<category><![CDATA[Access360]]></category>
		<category><![CDATA[Actional]]></category>
		<category><![CDATA[AmberPoint]]></category>
		<category><![CDATA[Baltimore Technologies]]></category>
		<category><![CDATA[BEA Systems]]></category>
		<category><![CDATA[BMC Software]]></category>
		<category><![CDATA[Bowstreet]]></category>
		<category><![CDATA[Cape Clear]]></category>
		<category><![CDATA[Computer Associates]]></category>
		<category><![CDATA[ContentGuard]]></category>
		<category><![CDATA[EDS]]></category>
		<category><![CDATA[Entegrity]]></category>
		<category><![CDATA[Entrust]]></category>
		<category><![CDATA[Flamenco Networks]]></category>
		<category><![CDATA[Forum Systems]]></category>
		<category><![CDATA[Grand Central Communications]]></category>
		<category><![CDATA[Hewlett Packard]]></category>
		<category><![CDATA[Hitachi]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Internet Security Systems]]></category>
		<category><![CDATA[InterTrust]]></category>
		<category><![CDATA[IONA]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Netegrity]]></category>
		<category><![CDATA[Network Associates]]></category>
		<category><![CDATA[Novell]]></category>
		<category><![CDATA[Oblix]]></category>
		<category><![CDATA[OneName]]></category>
		<category><![CDATA[OpenNetwork]]></category>
		<category><![CDATA[Phaos Technology Corp.]]></category>
		<category><![CDATA[PricewaterhouseCoopers]]></category>
		<category><![CDATA[Quadrasis]]></category>
		<category><![CDATA[RSA Security]]></category>
		<category><![CDATA[Sarvega]]></category>
		<category><![CDATA[Security & Identity Management]]></category>
		<category><![CDATA[SeeBeyond]]></category>
		<category><![CDATA[Sun Microsystems]]></category>
		<category><![CDATA[Symantec]]></category>
		<category><![CDATA[Systinet]]></category>
		<category><![CDATA[TIBCO]]></category>
		<category><![CDATA[TruSecure]]></category>
		<category><![CDATA[VeriSign]]></category>
		<category><![CDATA[Vitria]]></category>
		<category><![CDATA[Vordel]]></category>
		<category><![CDATA[Waveset]]></category>
		<category><![CDATA[webMethods]]></category>
		<category><![CDATA[Westbridge Technology]]></category>

		<guid isPermaLink="false">http://test.zapthink.com/?p=ZTR-WS104</guid>
		<description><![CDATA[Security is the immediate roadblock facing widespread implementation of Web Services technologies across the enterprise. As a result, many software vendors are throwing their hat into the XML and Web Services security ring, offering a broad and confusing number of solutions to a variety of real and perceived problems. However, much of this effort amounts to jostling for defensible market positioning ahead of a solid demand for enterprise-class XML and Web Security products and services. As a result, ZapThink believes that the emerging market for XML and Web Services security solutions will be characterized by a period of turbulence, as companies struggle to clarify their messages and shake the kinks out of their product offerings.]]></description>
			<content:encoded><![CDATA[<p><b>Key Findings:</b><br /> 
<ul>
<li> The next roadblock on the path to Web Services adoption is security. Security is today&#8217;s key enabler for Web Services.
<li> The XML and Web Services security market will reach $4.4 billion in 2006, which will represent 65% of the total authentication, authorization, and administration security market. This growth represents an average compound annual growth rate of 300%.
<li> Web Services offer great potential for B2B communication and integration, but the lack of robust security and manageability solutions currently inhibit the ability for companies to conduct business with each other via Web Services over the Internet.
<li> The combination of adequate funding, solid business models, seasoned management teams, and high quality engineering staff leads some startups to offer surprisingly robust XML and Web Services security solutions.
<li> The best positioned companies to be profitable in the XML and Web Services security space are those companies that already have deep technical knowledge of application level security technologies, coupled with a solid customer base.
<li> There will be a spike in demand for Web Services security solutions within the next 12 months.
<li> Web Services will not play a major role in transactional environments in 2002-2003.
<li> The 2003 timeframe won&#8217;t see many multiple-company B2B Web Services, because companies will choose to implement B2B Web Services on a point-to-point basis.
<li> Existing 3A security vendors will incorporate XML and Web Services into their product lines, so by 2006, most 3A security products will support or provide XML and/or Web Services security.
<li> This report must be placed into the context of an overall security strategy. Simply securing all of a company&#8217;s Web Services alone can only provide a false sense of security.
<li> Enterprises must institute policies that apply to their entire enterprise network (including participants invited from outside), and administer that security in a hierarchical fashion.
<li> Next-generation firewalls must be capable of looking at the content of XML streams, and the security mechanisms for such data must be part of that content.
<li> Companies planning on using Web Services across the firewall will necessarily have to resolve the resulting security issues first. </ul>
<p> <b>Table of Contents:</b><br /> 
<ul>
<li> I. Report Scope
<li> II. Context for Security in the Web Services Model
<ul>
<li> 2.1 The ZapThink Web Services Roadmap
<li> 2.2 Security: The Key Enabler for Web Services
<li> 2.3 Context: Security Products &#038; Services
<li> 2.4 Context: Web Services Management and Infrastructure Products
<li> 2.5 Context: Global Identity Services
<li> 2.6 Context: Digital Rights Management Technologies
<li> 2.7 Context: Directory Servers </ul>
<li> III. Technology Landscape
<ul>
<li> 3.1 XML security and the shift to Service-oriented computing
<li> 3.2 Principles of Application Security
<ul>
<li> 3.2.1 Application level security requirements
<li> 3.2.2 Authentication
<li> 3.2.3 Authorization and Access Control
<li> 3.2.4 Confidentiality
<li> 3.2.5 Data Integrity
<li> 3.2.6 Non-Repudiation </ul>
<li> 3.3 IT Security Precursors
<ul>
<li> 3.3.1 Encryption and Decryption
<li> 3.3.2 Symmetric-Key Encryption
<li> 3.3.3 Public-Key Encryption
<li> 3.3.4 Digital Signatures
<li> 3.3.5 Digital certificates
<li> 3.3.6 Authentication with certificates
<li> 3.3.7 How CA Certificates Establish Trust
<li> 3.3.8 Managing Certificates
<li> 3.3.9 Kerberos
<li> 3.3.10 Using HTTP
<li> 3.3.11 Secure Sockets Layer (SSL) </ul>
<li> 3.4 XML Security Efforts
<ul>
<li> 3.4.1 XML Signature
<li> 3.4.2 XML Encryption </ul>
<li> 3.5 Web Services Security Efforts
<ul>
<li> 3.5.1 SAML
<li> 3.5.2 XACML
<li> 3.5.3 XKMS
<li> 3.5.4 X-KRSS
<li> 3.5.5 X-KISS
<li> 3.5.6 WS-Security </ul>
</ul>
<li> IV. Market Segmentation
<ul>
<li> 4.1 Web Services Security Platforms
<li> 4.2 Web Services Infrastructure Management Vendors
<li> 4.3 Secure Integration/EAI Vendors
<li> 4.4 Global Trust Services
<li> 4.5 Identity Management/Authorization/Single Sign-On Vendors
<li> 4.6 Access &#038; Policy Management Vendors
<li> 4.7 PKI Vendors
<li> 4.8 Web Services Security Toolkit Vendors
<li> 4.9 Software XML Firewalls
<li> 4.10 Private Web Services Network Providers
<li> 4.11 Enterprise Security Services
<li> 4.12 Security Service Providers </ul>
<li> V. Current State of the Market
<ul>
<li> 5.1 Approaches to the Market
<ul>
<li> 5.1.1 Focused technology startups
<li> 5.1.2 Established Web Services vendors
<li> 5.1.3 Larger public vendors </ul>
<li> 5.2 Customer perspective </ul>
<li> VI. Business &#038; Technology Trends
<ul>
<li> 6.1 Long Term Trends: Relationship to the 3A Security Market
<li> 6.2 Long term trends: relationship to Web Services market
<li> 6.3 Inhibitors to the Growth of the XML and Web Services Security Market </ul>
<li> VII. Conclusions
<ul>
<li> 7.1 Key Notes
<li> 7.2 Decision Points
<li> 7.3 Figures
<li> 7.4 Tables </ul>
<li> VIII. Vendor Profiles
<ul>
<li> 8.1 Web Services Security Platforms
<li> 8.2 Secure Integration Vendors
<li> 8.3 Global Trust Services
<li> 8.4 Identity Management/Authorization/Single Sign-On Vendors
<li> 8.5 Access &#038; Policy Management Vendors
<li> 8.6 Software XML Firewalls
<li> 8.7 PKI Vendors
<li> 8.8 Enterprise Security Services </ul>
<li> A. Related Research
<li> B. Supporting Resources
<li> C. Trademark Notice and Statement of Opinion
<li> About ZapThink, LLC </ul>
<p><a href='?file_id=XMLWSSecurity-062002-ZTR-WS104-1.pdf' class='download'>Download File</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.zapthink.com/2002/06/20/xml-and-web-services-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

