
COMPLIANCE COUNSELOR
Using role management in provisioning and compliance
Tom Bowers 01.31.2007
Rating: -4.43- (out of 5)




[IMAGE] This article is part of the Identity and Access Management Security School. Visit the Using IAM tools to improve compliance lesson page for more learning resources.
Accurate management of privileges is a key component of compliance, and the process calls for systems that ensure access rights are granted only according to employees roles (i.e. role-based access control) across an entire enterprise. So it's no surprise that compliance issues are driving identity projects that couldn't be justified by return-on-investment principles alone.
In meeting these compliance concerns, role management is well recognized as a best practice for setting such controls. The problem is that as people change roles and gain access to additional systems, corporations are typically very good at getting people what they need, but poor at taking away what is no longer required. This issue is the driving force behind role management.
Compliance issues
The industry has developed a number of compliance-oriented best practices for role management, which focus on the following objectives:
Role management provides the necessary framework for enterprises to efficiently manage access to sensitive data based on workers' roles in the organization. Thus role management becomes an effective tool in meeting compliance guidelines.
The role management process Managing roles within a corporation needs to be set up and managed carefully. I propose a four step process.
Plan:
Deploy:
Audit:
Be prepared to spend two or three months evaluating each business process and its associated roles. You will likely spend an additional month writing the connector for any given application or system. Some enterprises have spent months mapping between data repositories and the roles that should have access to them. Despite the seemingly tedious nature of the work, this research is critical to project success. The old a
To continue reading for free, register below or login
To read more you must become a member of SearchSecurity.com

dage of "if you fail to plan, you plan to fail" is especially true in role management projects.
Lastly, it is likely that you won't find technology to be a barrier in your project; instead, it will be the organization's business processes. That having been said, you will likely find that role management products are still complex and difficult to use. The market is still maturing as vendors improve their own business processes. The effort of deploying a role management product is critical to meeting compliance guidelines. As such, you will find that while meeting those guidelines, you will be improving business effectiveness as well.
Conclusions
In this type of project, you will find that the creation of roles is typically a time-consuming process. There are tools available, however, that can help to automate it. The key to role management project success is to move cautiously, talk with your business units constantly, communicate the project objectives and success factors with end users and management, and focus on business processes as well as the technology. You will affect the way people work, never forget that. Set and exceed their expectations for the project.
About the author:
Tom Bowers, who holds CISSP, PMP and Certified Ethical Hacker certifications, is a well-known expert on the topics of data leakage prevention, global enterprise information security architecture and ethical hacking. He is also the president of the Philadelphia chapter of Infragard, the second largest chapter in the country with more than 600 members. Additionally, Bowers is the managing director of the independent think tank and industry analyst group Security Constructs LLC. His areas of expertise include aligning business needs with security architecture, risk assessment and project management on a global scale. Bowers is a technical editor of Information Security magazine and a regular speaker at events like Information Security Decisions.
[TABLE][TABLE]
 |

|
Rate this Tip
|
To rate tips, you must be a member of SearchSecurity.com. Register now
to start rating these tips. Log in if you are already a member.
|


');
// -->
DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.
|
 |
|
|
 |
|
 |