enterprisesecuritymag

| | February - 2020ENTERPRISE SECURITY8IAM--IT'S A BUSINESS PROBLEMBy Ian Hill, Global Director of Cyber Security, Royal BAM Group [AMS: BAMNB]Identity and Access Management (IAM) sits at the heart of what many cybersecurity professionals believe as the modern security thinking, primarily because Identities themselves are considered as the new security perimeter, certainly from the perspective of a "Zero Trust" model. There is also increasing emphasis within standards requirements such as ISO27001:2013, which dedicates an entire section (A.9) to the subject. Yet, there is much confusion as to how it works and should be implemented, particularly from the perspective of an existing enterprise environment.Many businesses spend a lot of money solutionizing IAM only to end up with something that fails to meet expectations. The actual solution lays in understanding what it's trying to achieve and the nature of identities or to be more precise digital identities. IAM is not a product or solution, it is a framework, a principle and to implement it effectively needs an understating of some key fundamentals. A digital identity is just a set of attributes used to represent an external entity, aka a real person and IAM is fundamentally about managing that identity from a what, why, how, who, where and when perspective, with specific emphasis on the `who' are they and are they allowed in (authentication), `what' are they allowed to do once in (authorization).Understanding business goals and objectivesLike most things cybersecurity, it's about people, processes, and technology in the form of business processes, roles, and assets. Typically the most common manifestation of IAM is through RBAC (Role-based Access Control). The key to understanding this is firstly to understand the business goals and objectives because of the business functions by way of a set of business processes, which in most cases require people and assets (logical as well as physical). It is the relationship between these three that is the key to RBAC because the person (identity) performs a role required by one or more business processes, which require that the role has a specific level of access privileges to one or more assets, required by the processes. To be effective this requires clearly defined and understood business processes, roles & responsibilities, and assets. It is also important to note that processes and assets both require owners, who decide what privileges are allowed within each.And this is where we can run into problems. The challenge for many businesses is knowing where to start without trying to boil the ocean or being tempted into cyber-bling sprawl by the inflated promises of vendors. It's a business problem that needs to be addressed objectively from the business perspective, has a clear objective of what you want to achieve from an IAM capability within the risk context of the business goals and objectives.PrioritizeIt's important to prioritize critical processes, roles, and assets and adopting a recognized methodology such as the SABSA framework will help guide a strategy to identify these. It also requires support and buy-in from the whole business and particularly from HR, because from a process perspective, if you are going to start anywhere it's the In My Opinion
< Page 7 | Page 9 >