SAML
Home > Financial Services Information Security Definitions - SAML
SearchFinancialSecurity.com Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

SAML



Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

DEFINITION - SAML (Security Assertion Markup Language) is an Extensible Markup Language (XML) standard that allows a user to log on once for affiliated but separate Web sites. SAML is designed for business-to-business (B2B) and business-to-consumer (B2C) transactions.

SAML specifies three components: assertions, protocol, and binding. There are three assertions: authentication, attribute, and authorization. Authentication assertion validates the user's identity. Attribute assertion contains specific information about the user. And authorization assertion identifies what the user is authorized to do.

Protocol defines how SAML asks for and receives assertions. Binding defines how SAML message exchanges are mapped to Simple Object Access Protocol (SOAP) exchanges. SAML works with multiple protocols including Hypertext Transfer Protocol (HTTP), Simple Mail Transfer Protocol (SMTP), File Transfer Protocol (FTP) and also supports SOAP, BizTalk, and Electronic Business XML (ebXML). The Organization for the Advancement of Structured Information Standards (OASIS) is the standards group for SAML.

CONTRIBUTORS: Gerard Enter
LAST UPDATED: 17 Jan 2008

Read more about SAML:
- SearchSecurity has a collection of links related to SAML.
- OASIS provides more information about SAML and its standards status.


Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Protecting third party processes on all levels
Financial firms have numerous third party partnerships, but these partnerships come with security risks. Compliance expert Richard Mackey explains how...
Case study: How outsourcing services enable PCI DSS compliance
Qualified Security Assessor Spyro Malspinas recounts his consulting experience with ACME and explains how a decision to outsource can lead to some...
SAML ratification enables vendor interoperability
Ratification of the Security Assertion Markup Language (SAML) opens the door for vendors to begin developing and shipping products that support the...

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CTCI (Computer-to-computer interface)  (SearchFinancialSecurity.com)
Computer-to-computer interface (CTCI) is a digital communications protocol that allows customers of the NASDAQ (National Association of Securities...
DROP (delivery of real-time execution information protocol)  (SearchFinancialSecurity.com)
DROP (delivery of real-time execution information protocol) is a feature of various NASDAQ (National Association of Securities Dealers Automated...




About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts