Identity Management and Compliance in OpenShift (45 minutes session) | Breakout session
Compliance is often the first question for anyone implementing Red Hat OpenShift but also the hardest to answer. An even harder question to answer is how to implement identity management compliance for OpenShift, but the question is really about bridging the gap between people who write compliance requirements, people who audit those requirements, and people who implement the technology.In this session, targeted to security specialists responsible for reviewing OpenShift deployments and those trying to build a compliant solution with OpenShift, I2019ll provide a map to help explain what compliance really means, how OpenShift is deployed, and how OpenShift technology is implemented to meet compliance requirements, including examples from National Institute of Standards and Technology (NIST) 800-53, NIST 800-63 and the Criminal Justice Information Services (CJIS), mapped to a technology implementation. This map will help auditors better understand the compliance of identity management in OpenShift.The content for this session is based on my blog post: tremolosecurity.com/openshift-compliance-and-identity-managem
Marc Boorshtein
CTO Tremolo Security, Inc.
Marc has nearly fifteen years of identity and access management experience as a software engineer, product developer and consultant. Marc is experienced building, deploying and managing identity systems from all major vendors across numerous industries as well as working with security teams to analyze compliance and remediate issues. Marc has previously spoken at Google DevFest 2016, The Information Security Systems Association conference and given multiple briefings on identity management for OpenShift Commons.
Room 152
Wednesday, 3rd May, 16:30 - 17:15