Home > Security Tips > IAM Insights > Making the case for enterprise IAM centralized access control
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

IAM INSIGHTS

Making the case for enterprise IAM centralized access control


David Griffeth, Contributor
07.07.2009
Rating: -3.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In a centralized model, all system access is granted according to one interpretation of policy.  It also streamlines new user creation, modification and termination processes. 

Within today's enterprises, it's common for organizations of all sizes to rely on many different applications to fulfill a variety of business needs. In smaller corporations, the access administration model tends to be distributed across many business lines or system owners. This model does not allow for a functional identity and access management program, meaning it's virtually impossible to manage user access, privilege levels and revocation when necessary.

Eventually, these organizations reach a maturation point where the access administration model must be assessed to determine if it's more efficient to centralize. This article lays out many of the process and security benefits of a centralized model.

The lifecycle of access for employees and temporary workers has three major phases:

  • New access creation: Requiring new accounts on various systems.
  • Access modification: Necessary when employees move from one job to another within the organization, requiring account access and privilege modifications, deletions and/or new accounts.
  • Termination: Removal of all access.

For new access requests in a distributed access administration model, users that need access to multiple applications must make requests to multiple application owners. This often means filling out and submitting a variety of forms, which usually ask for the same data, depending on the system owner's governance process and interpretation of policy. As the system owners receive request forms, they provision the access and notify the end user. Unfortunately, the system owners won't grant access on the same day, so the end user will not have the complete set of access they need to do his or her job until the slowest system owner completes the request.

For more information
Learn more about configuring access control lists.

What are good features to look for in access control software? Read more.

Also, find out more about comparing access control mechanisms and identity management techniques.
When an existing user is terminated or moves within the organization to a different job, the old manager must remember or figure out what systems the user had access to and request the accounts be disabled. The new manager must also fill out all the required forms for access appropriate to the user's new job.

The process inefficiencies are obvious: multiple forms with similar information going to multiple system owners, who each provide access according to their own rules and requirements. If access reviews are required, this means a slew of uncoordinated emails to managers asking for access reviews and approvals.

The security concerns are worse. Each time an employee or contractor moves within the organization or is terminated, the old manager is expected to fill out a variety of forms requesting access modification, making each manager a potential failure point. If there is a process failure, there will most likely be accounts on systems that are inappropriate, or worse, belong to terminated employees.

In a centralized model, all system access is granted according to one interpretation of policy It also streamlines new user creation, modification and termination processes that can be based on one feed from human resources.

For example, when an individual joins the organization there is one request made for all access. The centralized provisioning team will be able to verify the new user is employed and who his or her manager is based on the HR feed. All access is granted at the same time as a single request and the user is ready to work when that request is complete.

When a user moves, there is only one group to notify for access changes and there is no need for a notification for planned termination because the HR feed will notify the centralized provisioning group of all the day's terminations. In the case of termination with prejudice (being fired), there is only one group to call to have all access shut down immediately.

Other advantages include the ability to have a single system access review generated across all systems, the beginnings of automated provisioning, fewer resources required to provision access and quicker turnaround time for requests.

I recommend moving toward a centralized provisioning model around the same time it's determined the company needs a helpdesk function. Moving towards this model will provide sounder information security practices, more efficient provisioning processes and will reduce the risk associated with managers as failure points. It will also put an organization on the road to a full-blown identity and access management program, which is essential to the information security program success of all midsized and large enterprises.

About the author:
David Griffeth is the Vice President of Business Line Integration and Reporting at RBS Citizens Bank, a financial institution that is one of the 10 largest commercial banking companies in the United States ranked by assets and deposits. As part of his responsibilities, David manages the Enterprise Identity and Access Management group and is charged with supporting the bank's growth model while maintaining compliance with several regulatory bodies. Prior to his current position, David consulted on major information risk management projects with large companies such as Fidelity Investments and CIGNA. David earned a bachelor's degree in computer science from Framingham State College and holds several certifications including CISSP and CISA.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
IAM Insights,   Enterprise User Provisioning Tools,   Enterprise Identity and Access Management,   Identity Management Technology and Strategy,   Password Management and Policy,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
IAM Insights
IAM trends: Rebuilding security with provisioning technologies
Using unique device identification for bank website security
Risk-based multifactor authentication implementation best practices
Content-aware IAM: Uniting user access and data rights
Security on a budget: How to make the most of authentication tools
Best practices for a privileged access policy to secure user accounts
Best practices: How to implement and maintain enterprise user roles
Kerberos configuration as an authentication system for single sign-on
How to use single sign-on for Web access control to prevent malware
Identity and access management 2009: Staff cuts, insider threats

Enterprise User Provisioning Tools
IAM trends: Rebuilding security with provisioning technologies
Quiz: Compliance-driven role management
Identity lifecycle management for security and compliance
Choosing management for Active Directory user provisioning
User account best practices for an investment management website
Content-aware IAM: Uniting user access and data rights
Keep files from being deleted by assigning read and execute permission
Is Identity Management as a Service (IDaaS) a good idea?
Top tactics for endpoint security
How to edit group policy objects to give a user local admin rights

Password Management and Policy
Torrent phishing scheme trips up Twitter users
Microsoft, security firms warn of password meltdown
How to find and remove keyloggers and prevent spyware installation
How to encrypt passwords using network security certificates
Two-factor authentication, vigilance foil password theft
Group to shed light on secure identity management threats
How to determine password strength for a website
Prevent password cracking with password management strategies
Brute force attacks target Yahoo email accounts
Best Identity and Access Management Products

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
AAA server  (SearchSecurity.com)
authentication, authorization, and accounting  (SearchSecurity.com)
federated identity management  (SearchSecurity.com)
identity access management (IAM) system  (SearchSecurity.com)
onboarding and offboarding  (SearchSecurity.com)
password synchronization  (SearchSecurity.com)
RADIUS  (SearchSecurity.com)
role mining  (SearchSecurity.com)
role-based access control (RBAC)  (SearchSecurity.com)
user profile  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts