• No results found

Identity and Access Management

N/A
N/A
Protected

Academic year: 2021

Share "Identity and Access Management"

Copied!
16
0
0

Loading.... (view fulltext now)

Full text

(1)

Maricopa Association of

Governments-Telecommunications Advisory Group

Notes accompany this presentation. Please select Notes Page view. These materials can be reproduced only with Gartner's official approval. Such approvals may be requested via e-mail — [email protected].

Identity and Access Management

(2)

Gartner: Introduction

„

Gartner is the leader in technology research: objective,

vendor-neutral, trusted, and action-oriented

„

Clients can take action because of our practical approach, rigorous

analysis, and proven methodologies

„

Gartner clients are members and have unlimited access to Gartner

resources - over 650 IT subject matter experts and thousands of

pieces of current written research

„

Gartner is State-approved with a competitively bid State contract

„

A few examples of what Gartner can do for you:

- Make investments in the right technologies

- Understand key technology trends and their implications

- Develop and implement meaningful IT strategies

- Demonstrate IT value and contribute to the enterprise

- Choose vendors to meet business and technology needs

- Identify cost reduction opportunities in your IT contracts

(3)

Gartner: Contact Information

Earl Perkins

Research Vice President

Information Security and Privacy

Shilpi Narang

Senior Account Executive Public Sector

Phone: 408.234.3099

(4)

Identity and Access Management:

Client Issues

1.

What exactly is identity and

access management?

2.

What drives IAM deployments?

3.

The state of the IAM industry

today

(5)

Authenticate Authorize Administer

Identity Management

(Administration)

Access Management

(Real-Time Enforcement) Physical Resources

Applications Databases Security

Systems Directories Operating Systems Identity Admin Accounting (ITSM) NAC Alarm/ Alerting

IAM Defined — User Identities, Transactions,

Roles, Policies and Privileges

Password Management

Audit/Compliance

Enterprise Reduced Sign-On

User Provisioning Role Matrix Management

Metadirectory

Enterprise Access Management Federated Identity Management

(6)

Identity and Access Management

As a Process

Business Process

Workflow process

Access model process

Identity process

(7)

IAM

Defined-The Identity and Access Process

Create Access Model Change Access Model Use Access Model Report Access Model Create Workflow Change Workflow Use Workflow Create Identity Change Identity Monitor Identity Retire Identity Report Identity Policy Use Identity

ACCESS MODEL PROCESSWORKFLOW PROCESS

(8)

Business Drivers: Regulations Impacting IAM

Sarbanes-Oxley HIPAA

FDA CFR Part 11/Annex 11 GLB FISMA CA SB 1398 CA AB 1950 CA SB 1386 PIPEDA EUPD Japan Privacy Basel II Control Frameworks:

COBIT ISO 17799 NIST

Bill 321/2004 Personal Data

Protection Law Bill 3494/2000

Law f/Protection Of Personal Data Nov2000

(9)

Regulatory Compliance

„GLB Act „HIPAA (U.S.) „PIPEDA (Canada) „21 CFR Part 11 (FDA) „NERC „Sarbanes-Oxley

CISO

Business Units

Help Desk

SEC Admin

CIO

Operational Efficiency

& Effectiveness

„ Improved SLA: <24 hrs „ Productivity savings „ User convenience

„ Security admin. reporting

Cost Containment

„Reduce/avoid staff „ Security admin. „ Help desk „Common IAM architecture „Non-IT services

Business Facilitation

„Customer self-registration

„Portal and personalization

„Outsourcing

„Customer retention

„Mobile Content Integration

Risk Management

„Audit management

„Terminations

„Policy-based compliance

(10)

Rating the Identity Management Market —

User Provisioning Vendors

(11)

Open Enterprise Svr eDirectory Nsure DirXML exteNd/ GroupWise

Competitive Market for Identity & Access

Management —Component, Suite Stacks

(12)

Evolving IAM Technology

Needs vs. Availability

„

Customers need

Scalability to larger deployments

Faster deployments

Richer audit, reporting for compliance

Better training, best practice templates

Outsourcing models

„

Vendors are currently designing/providing

Suites of semi-integrated products

Mini-suites of both infrastructure and management

Services for access, provisioning, workflow and audit

(13)

Sample IAM

Implementation Process Timeline

Project Initiation & Scope Definition

Strategy, Architecture, Initial Funding Technology Selection Detailed Project Plan Development Product Implementation ENVIRONMENT PROFILE:

• 5000 users, 100 locations, national network • Corporate HQ, distributed divisions

• Microsoft Windows/Active Directory • MS Exchange, Lotus Notes, SAP

• Web application portfolio, 10 applications 30-45 days 90-180 days 60-90 days Business Requirements Gathering Technical Requirements Gathering Market Research Strategy Document Architecture Development Initial Schedule and Funding Estimate

Project Approval

30-45 days

(14)

IAM in

Information Security Organizations

Security Steering Committee Resource Owners Leadership Analysis/ Design Admin. Security Operations Communications Tech Support Audit Architecture

Identity

Management

(15)

IAM Pitfalls to Avoid

„

Someone to watch your back

(executive sponsorship)

„

Fighting without a cause

(business owners)

„

Building without a blueprint

(project planning)

„

Cooking more than can be

eaten (complexity creep)

„

Promising more than can be

(16)

What Do These Changes Mean to You?

„

The time to consider identity

management as part of your

information security strategy

is past.

„

Identity services, application

security and SOA planning

strategies are merging.

„

The market has matured enough for action — the

degree can now be driven by requirement, not utility.

„

Identity can now be viewed as a strategic asset, with

References

Related documents

Campus Network strongSwan Linux Client Windows 7/8 Agile VPN Client Linux FreeRadius Server Windows Active Directory Server Internet High-Availability strongSwan

HR System FIM LDAP Active Directory/ Exchange SQL Server DB givenName sn title mail employeeID telephone Sammy Dearling 008 givenName sn title mail employeeID telephone givenName

Centrify Server Suite is an enterprise-class solution that secures even the most complex Hadoop environments leveraging an organization’s existing Active Directory infrastructure

Using PBIS Enterprise, you can manage the PowerBroker cell settings for Unix, Linux, and Mac OS X users and groups in Active Directory Users and Computers.. Configuring Cell

Oblix COREid identity products provide critical functionality that extend Microsoft’s Active Directory®/ADAM, Identity Integration Server (MIIS), and SharePoint Portal  to

Parallel Architecture B Parallel Architecture B MS Windows Server 2003 UNIX/Linux MS Windows Client LSASS Login LDAP RFC 1510 UNIX/Linux Client PAM DUA LDAP Login Userid /

Registration Users U n-A uth en tic ate d Self-Care Application Tivoli Identity Manager WebSphere Cluster Application Subcription Users A ut he nt ic at ed Self-Care Application

Windows Azure Active Directory and the Hybrid Enterprise - Today Windows Azure Active Directory On‐premises and private cloud Other apps Other Directories Self‐Service