Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > What mistakes are made when implementing enterprise IAM systems?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What mistakes are made when implementing enterprise IAM systems?

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 01 July 2007
What are some of the biggest mistakes organizations make when implementing enterprise IAM systems?

>
EXPERT RESPONSE
There are three big mistakes an organization can make when implementing identity and access management (IAM) systems: not conducting a complete risk assessment of the systems being secured, not checking compatibility of the IAM system with current network and IT systems and failing to verify that the system will scale as their business grows.

Before implementing any IAM system, an organization must decide what data it wants to protect, who owns that data and how it fits into the organization's data classification policy. Too many companies implement either too little or too much access management. They end up either putting too much emphasis on securing systems with low risk data, which is overkill, or not putting enough security on high-risk data, which opens the company up to malicious access by hackers.

Creating a data classification policy that defines what is low- and high-risk data is essential to implementing any IAM system. Low-risk data might include marketing information used for sales modeling that describes customer preferences, but can't be tied back to individuals and used for identity theft. High-risk data would include customer and employee information, or details of financial transactions, which could lead to identity theft or monetary loss.

The next priority is to make sure the system meshes with the current IT infrastructure and architecture. Any IAM installation is a major project that touches every piece of an organization's IT plumbing in one way or another. It doesn't make sense to rip out the kitchen sink just to fix the faucet. Consider your platform of choice. If the company favors Linux, then LDAP might be the best choice. If it's mostly Windows-based servers, then Active Directory is the logical choice.

Don't count on an IAM to be the glue to knit together different systems. If the organization features diverse or mixed platforms, figure out how to keep IAM systems and the directory of authentication credentials on an isolated server -- independent of different platforms.

Another part of checking your infrastructure is planning. Active Directory requires a considerable amount of homework in advance to set up groups and organization units and directories before installation of hardware, servers, hosts and software can begin.

The third common mistake, not planning for scalability, can be detrimental if your company is growing. Today, you might have 10 employees. In a few years, if the business is successful, there might be 10,000. Can the IAM system handle the growth, or will performance slow to a crawl because it doesn't have the capacity? What if your company acquires another enterprise and has to absorb whole departments? Active Directory and LDAP can expand for growth, but they still require advance planning so groups can be created.

Basically, failure to plan ahead for growth and infrastructure changes are the biggest mistakes to make when implementing an IAM.

For more information:

  • In this tip, which is a part of our Data Protection Security School, contributor Tom Bowers explains how to conduct a data classification assessment.
  • In this expert Q&A, Joel Dubin reviews essential components of an access management strategy and reveals how to deliver the plan to executives.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Identity Management and Access Control
    What are the pre-requisites for implementing single sign-on (SSO) in an organization?
    To what exactly would a request for biometric data from an insurance provider pertain?
    Is it possible to support users to have their own IDs with root privilege so they aren't sharing a root password?
    What is the purpose of RFID identification?
    CardSpace vs. user IDs and passwords
    Biometrics vs. biostatistics
    What are the dangers of using radio frequency identification (RFID) tags?
    What are the risks of connecting a Web service to an external system via SSL?
    What should an internal support model for identity management look like?
    How are biometric signatures more than a fingerprint scanner?

    Enterprise Data Protection
    How to avoid DLP implementation pitfalls
    Quiz: Data loss prevention
    PCI DSS 1.2 clarifies wireless, antivirus use
    Sophos to acquire mobile data protection company Utimaco
    Should users have a removable boot drive for online banking?
    Unified communications trigger data leakage dangers, survey finds
    NitroSecurity covers its bases with RippleTech deal
    Easing e-discovery preparation by mapping enterprise data
    Quiz:: E-discovery and security in the enterprise
    Growing Mac use prompts call for better security

    Creating and Managing Information Security Policies
    Exploring Microsoft's Network Access Protection policy options
    How to avoid DLP implementation pitfalls
    What's your advice for getting other business units to contribute to crafting an effective information security policy?
    Security Awareness Training Essential Part of Infosec Program
    Is it necessary to grant a full administrative privileges to a security administrator?
    How to lock down instant messaging in the enterprise
    Worst practices: Bad security incidents to avoid
    Thompson calls for marriage of data and security management
    Companies Collecting Too Much Customer Data Increase Exposure
    Interview: Arizona CISO David VanderNaalt
    Creating and Managing Information Security Policies Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    cut-and-paste attack  (SearchSecurity.com)
    data splitting  (SearchSecurity.com)
    deperimeterization  (SearchSecurity.com)
    Google hacking  (SearchSecurity.com)
    masquerade  (SearchSecurity.com)
    snooping  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts