enterprisesecuritymag

February - 2020ENTERPRISE SECURITY| | 9JML (Joiner, Mover Leaver) processes. These sit at the core of an IAM capability, and typically are the domain of HR who own the digital identities themselves and are the business function where the identity lifecycle starts and ends. Identities are connected to the assets by way of the business processes, so an initial approach would be to identify your crown jewels, those critical information assets you want to protect most, and build prioritization around the processes that act upon them and the roles(and their identities) that are required by the process.Smarter use of functionalityFrom a technology perspective, many companies with tight budgets do not need to buy in special tools to affect IAM, remember it's a framework and much of it can be achieved with a smarter use of functionality that is inherent within existing systems or tools, Active Directory for example. It depends on how deep you need to go. For example, if your risk profile requires that you need 802.1X network access control, then you may think about solutions such as Cisco's ISE (Identity Services Engine). If you use cloud services, you may need to look at Identity Federation and Cloud Access Security Bokder (CASB).For larger enterprises with a complex and diverse infrastructure and a high threat profile, where for example a hybrid RBAC/ABAC (Attribute-Based Access Control) model is required, is when IAM specific solutions come into play.IAM now extends well beyond the confines of just logging into and accessing files within a corporate network. The construction industry has mechanical excavators that are started with a thumbprint and PIN code. Through IAM, the system confirms the operator's identity and that they are trained, licensed and authorized to operate that particular unit on that site at that particular time, before starting. Once running, the system will track how long the unit is in operation, feedback on the operator's performance and ensure they are taking appropriate breaks, and implement a controlled shutdown if necessary.It's impossible to discuss IAM in just a few pages, there indeed many large books on the subject, but to summarize, IAM is a framework, with many solutions, which are decided by the business needs, and when planning IAM the first rule is begin with the end in mind', what is it you are trying to achieve, once you get that right, you are halfway there. ESIAM is not a product or solution, it is a framework, a principle and to implement it effectively needs an understating of some key fundamentalsIan Hill
< Page 8 | Page 10 >