Abstract
Network and data security require some mélange of identification, authentication, authorization, and encryption. Are these organizational, network, middleware, or application issues? Who should manage them? We'll talk about these questions, about various strategies for answering them, and about the tradeoffs between proprietary and open-standards approaches.