Improving the Procurement Process

I see a lot of RFPs. That’s a good thing in my business, and we are excited to respond to them and participate in the opportunity.

I see a lot of RFPs. That’s a good thing in my business, and we are excited to respond to them and participate in the opportunity. While working on an RFP recently, I realized that there was a surprising lack of questions across the board about security and on SSO and Access Management. There were questions about what supported protocols, application integration, architectures, hardware recommendations, etc., but nothing focusing what the system does in action. For example, when a user logs in, and the company is then responsible for their session, how secure is that session?

Really, there is little point of doing a multi-factor authentication system that includes risk analysis, if once the user is authenticated a simple XSS or other attack can trick the browser into passing session cookies to an attacker, which the attacker can just replay.

I am surprised that I don’t see more questions about what the solution does to defeat these possible attacks including timeouts, http_only, cookie domain settings and various other settings to secure the session after authentication.  I almost never see questions asking about alternative session schemes other than cookies. More “what if” or “how” questions could help improve the procurement process by adding more real-world data that would help separate “the men from the boys.”

I believe that we should all begin to focus on the security of our session management software in more detail. What do you think?  Why does it appear we are no longer focused on the fundamentals of security and instead are too interested in playing buzzword bingo inside of a RFP? I have even come across instances where it was suggested that the best technique for timeout security was to make sure the device the user is using for authentication locks itself after a specific time (a response I find both laughable and scary at the same time.).

Without asking the question of session security in the procurement process, a key security capability in the solution could easily be missed.

Written by

Aaron Berman

CA Community

Aaron is a security evangelist focused on Single Sign-On and Directory. He has spent most…

Published in


View this topic
  • James Holland

    This is great. Hooray for Disney’s imagineers!

    become a new brand in the share market research with its accurate research. Proven
    itself always right whether market is bull or bear. Last week all paid clients
    booked handsome profit in NIFTY, BANKINIFTY & STOCKS. Now for the coming
    week we expect more correction can come in NIFTY as the IRAQ issue is getting
    more tense, If it happens more then you will see a sharp fall in all world marketNSE BSE, STOCK TIPSbecause as we know all world run on
    crude & most of the crude comes from IRAQ. So be ready for a sharp fall so
    sell will be the best strategy for next week also. Traders can make a sell
    position in NIFTY around 7600-7650 with stoploss 7750 for the target of
    7300-7200.One can also make a sell call NIFTY 50 stocks as per NIFTY levels. You
    can also take our two days free trial to check our accuracy. For further updates
    you can visit our website.



  • king lear

    testing comment functionality, please do not publish this

  • Love the personal pic 🙂

    • CAHighlight

      Thank you!

  • Plutora Inc

    This is a good case study. 2.3 sec’s off a login transaction is big.

  • While the analysts were hyping DevOps, I posted the oversight of not including security as part of that discussion as you are highlighting here. Instead of just talking DevOps, it should be DOS (what’s old is new again 🙂 – DevOpsSec. As a previous AppDev person, it’s the app, who’s using it, why and where rather than the device and having the service available.

    As you rightly point, out Security should be baked into the solution.

    Nice Post and Timely!


    • CAHighlight

      Thank you for your feedback Michele. Agreed – security cannot be overlooked. Appreciate your input!

  • Mitesh

    I would love a printed copy

  • Lars Johansson

    I love the idea of BYOID! This makes me choose if I am almost anonymous (with my Hotmail Nicname) or official with identity from an official organisation. My Identity Provider will attach identity with right level of LoA according to the need of the Service provider.

    • CAHighlight

      Thank you for your comment. BYOID has tangible benefits for end users and relying parties but it also has to be weighed in the balance with potential risks and liability concerns. It will be interesting to see how BYOID plays out in the enterprise.