Identity and Access
Management for the
Real World
By Todd Peterson, IAM evangelist, Dell Software
2nd edition
Dell Software Group 5 Polaris Way Aliso Viejo, CA 92656
Identity and Access
Management for the
Real World
2nd edition
Identity and Access Management for the Real World | 2014 Dell. All rights reserved. Identity and Access Management for the Real World | 2014 Dell. All rights reserved.
5 6
Identity and Access Management for the Real World
Copyright © 2014 Dell, Inc. ALL RIGHTS RESERVED. This document contains proprietary information protected by copyright. No part of this document may be reproduced or
transmitted in any form or by any means, electronic or mechanical, including photocopying and recording for any purpose without the written permission of Dell, Inc. (“Dell”).
Dell, Dell Software, the Dell Software logo and products—as identified in this document—are registered trademarks of Dell, Inc. in the U.S.A. and/or other countries. All other trademarks and registered trademarks are property of their respective owners.
The information in this document is provided in connection with Dell products. No license, express or implied, by estoppel or otherwise, to any intellectual property right is granted by this document or in connection with the sale of Dell products. EXCEPT AS SET FORTH IN DELL’S TERMS AND CONDITIONS AS SPECIFIED IN THE LICENSE AGREEMENT FOR THIS PRODUCT, DELL ASSUMES NO LIABILITY WHATSOEVER AND DISCLAIMS ANY EXPRESS, IMPLIED OR STATUTORY WARRANTY RELATING TO ITS PRODUCTS INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT SHALL DELL BE LIABLE FOR ANY DIRECT, INDIRECT, CONSEQUENTIAL, PUNITIVE, SPECIAL OR INCIDENTAL DAMAGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF PROFITS, BUSINESS INTERRUPTION OR LOSS OF INFORMATION) ARISING OUT OF THE USE OR INABILITY TO USE THIS DOCUMENT, EVEN IF DELL HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Dell makes no representations or warranties with respect to the accuracy or completeness of the contents of this document and reserves the right to make changes to specifications and product descriptions at any time without notice. Dell does not make any commitment to update the information contained in this document.
About Dell
Dell Inc. (NASDAQ: DELL) listens to customers and delivers worldwide innovative technology, business solutions and services they trust and value. For more information, visit www.Dell.com.
If you have any questions regarding your potential use of this material, contact:
Dell Software 5 Polaris Way Aliso Viejo, CA 92656 www.Dell.com
Refer to our Web site for regional and international office information.
Table of contents
Introduction iii
Conventions iv
Chapter 1:
Identity and access management for your world …
not someone else’s
1.1
Chapter 2:
Access Management – After all, if you can’t get to
your stuff, what’s the point?
2.1
Chapter 3:
Identity Governance – Governance leads to agility
3.1
Chapter 4:
Privileged Account Management for the Real World
4.1
Chapter 5:
Look what they’ve done to us now …
iv
Identity and Access Management for the Real World | 2014 Dell. All rights reserved.
iii Identity and Access Management for the Real World | 2014 Dell. All rights reserved.
Introduction
In an ideal world, we'd have the budget and time we need to
get things done. And tomorrow would be predictable. But that's
simply not the case, especially in the IT universe.
As you well know, the world of identity and access
management (IAM) is one of constant change, shrinking
deadlines, minuscule budgets, overtaxed staff and unmerciful
regulations. Unfortunately, the historical approach to IAM
involves piecing together “half solutions,” in hope that
tomorrow’s solutions will address real-world needs.
This short book evaluates what IAM for the real world would,
should and can look like. It delves into the most pressing
IAM issues faced by virtually every organization and offers
actionable, affordable and sustainable approaches to the IAM
challenges you face. At Dell, we help you achieve your IAM
objectives for your real world (not ours), in a way that moves
you and your business towards your goals.
We hope you find value in “Identity and Access Management
for the Real World.”
Conventions
Throughout this book, we've used a number of
conventions to help highlight important points,
provide supporting evidence, or advise you of our
obvious bias. Look for the following conventions:
Real-world example
–
Stories of real organizations, facing
real challenges, and really solving their problems (often the
names have been changed to protect the innocent)
Facts & figures
–
Research-based information that supports
principles discussed throughout the book
Techie alert
–
Definitions and terms used in the identity and
access management industry that may not be familiar to you
(Then again they might.)
Useful tip
–
Information that will help you easily achieve
things discussed throughout the book
Blatant sales pitch
–
Where we get to why we actually wrote
this book. It may be a little biased, but we suspect that the
reason you’re reading this book is to find solutions to your
challenges. This is where we give them to you.
The words of David Byrne in this mid-80’s anthem perfectly capture the sentiment of many organizations trying to keep up with the ever-changing IT security landscape. The more we try to keep up with the latest threat, or apply security to the latest
technology, the more it seems like an elusive destination. While the Talking Heads try to strike an optimistic tone in an increasing complex world, the future is definitely not certain.
There’s the proliferation of new operating systems. Then there’s the explosion of an increasingly mobile workforce and new devices outside of the comfortable control of the organization. We have our old friends— stifling regulations such as SOX, HIPAA, PCI, and many more likely to come. And, of course, there’s the next mega trend that everyone seems to be talking about, such as cloud, BYOD, big data, and the Internet of things. It seems the only constant is change.
We long for the days when security was as simple as a password change every 90 days, following a few complexity rules. User access? That was easy. All you had to do was grant the secure access users needed to do their jobs on a handful of applications and one, maybe two, platforms.
But password management, user access and security are far, far more complex in today’s IT reality. The Talking Heads lyrics seem to echo the desire of many IT pros in dealing with these complex issues… “Give us time to work it out.”
IAM fundamental concepts
There are many major aspects of IT security worth discussing. But we’d like to focus on just one—identity and access management (IAM). IAM is concerned with some fundamental concepts that can be summed up as the four “A”s:
• Authentication – Entails ensuring that the person logging on to a system is who they say they are. This is usually done with usernames and passwords that, when combined, give you some assurance of the authenticity of the person logging on. • Authorization – Involves the parameters placed around what a user is allowed
to do once they are authenticated. Authorization is concerned not with who you are, but why you are logging on and what you are allowed to do. Authorization can be influenced by a range of variables. These can include everything from file and application permission and sharing, to very finely defined access rules based on role, location and even circumstance.
• Administration – In order to enable someone to authenticate and to be correctly
Identity and access management for your
world … not someone else’s
“Well, we know where we're goin'
But we don't know where we've been
And we know what we're knowin'
But we can't say what we've seen
And we're not little children
And we know what we want
And the future is certain
Give us time to work it out”
Talking Heads,
Road to Nowhere,
1985
1.3 Identity and Access Management for the Real World | 2014 Dell. All rights reserved. Identity and Access Management for the Real World | 2014 Dell. All rights reserved. 1.4
authorized, there are many managerial tasks that must be performed on an account, often called “provisioning.” Provisioning can literally be thousands of tasks designed to achieve a very elusive balance between security and user productivity. Administration also includes role management or defining and managing the roles that place the right people (or accounts and identities) in the right position to be correctly authorized. Finally, administration includes managing passwords for complexity, frequency of change and ease of reset. • Audit – Includes those activities that help “prove” that authentication,
authorization and administration are done at a sufficient level of security, measured by a set of standards. Audit may be concerned with ensuring PCI compliance, or it may be concerned with satisfying a best practice framework, such as ITIL. Or it may simply be designed to conform to internally developed security standards or policies.
All of the “A”s assume there is an identity established for each user. This identity or account resides somewhere (typically in a directory) so it can be authenticated, authorized, managed and audited. And typically the directory is tied specifically and exclusively to the application or system that controls user access. If all this is done correctly, the four “A”s are easily satisfied.
But we all know that “easily satisfied” is an elusive target. That classic retro pop song rings true today … “And we know what we're knowin', but we can't say what we've seen.”
The real world
The problem comes when diverse technologies are introduced. Almost everyone has Microsoft Active Directory (AD) in their organization acting as the single point of control for Windows-based resources. However non-Microsoft platforms – Unix or Linux, Macs or mainframes – each require their own directories and their own authentication, authorization, administration and auditing. And we haven’t even mentioned the
applications that add to this complexity in the first place. Most applications also require a directory and application-specific ways to satisfy the four “A”s.
Inevitably, each “A” is executed independently on dozens, hundreds or even thousands of systems. It’s not uncommon for a single user to have multiple passwords.
Each password represents another system where authentication, authorization, administration and audit are performed with no regard for the other systems in the enterprise. Analysts estimate a typical user can have as many as 14 passwords.
Today’s IT security complexity is illustrated very effectively by statistics gathered by The Aberdeen Group when surveying thousands of companies on their IAM strategy, success and challenges. (Average company size = 21,100 employees)
• The average IAM initiative has been ongoing for six years. • On average, four “point” solutions are deployed for IAM.
• 57 percent cite “complexity of IT environment” as an inhibitor to achieving IAM objectives.
But logging on, or authentication, is the least of our worries. While each system or application may have its own way to authenticate with its own password rules, each must also have its own authorization structure. It is not uncommon for IT to define roles for each access scenario, on each application. The result is “role bloat.” Every time a new authorization need arises, a new role is defined in the application affected. This is repeated across the entire range of applications. Many organizations end up
with more roles than users. The real world sure can be a mess.
And, unfortunately, the administrative responsibility for ensuring that authentication is set up right and authorization is adequate often falls squarely on IT. That means highly paid and specialized IT professionals often find themselves bogged down in the most mundane of identity administration tasks. Because they have the correct rights and expertise of the inner workings of the application or system, IT specialists end up acting as a highly specialized (and very expensive) help desk. The real issue is that critical IT initiatives are not getting done while these experts are helping end users with access.
Audit is not much better. When it comes time to “prove” that authentication, authorization and administration are playing by the rules, IT specialists are often the only reliable source for the required audit information. It’s enough to make you want to call in sick at audit time.
Reducing complexity is the key to creating an IAM strategy for the real world.
Today’s IT security complexity is illustrated
very effectively by statistics gathered by The
Aberdeen Group when surveying thousands
of companies on their IAM strategy, success
and challenges.
The Dell One Identity family of IAM solutions is entirely focused on reducing complexity. These solutions can help you consolidate disparate identities into a single existing directory, unify authentication across a diverse mix of applications and access scenarios, marry governance with provisioning, or cover the complete range of privileged account management needs. Dell One Identity gives you the simplest, most affordable “real world” solutions.
Who’s running the show anyway?
There’s a real efficiency issue with specialized IT resources being so heavily involved in IAM operations. The fact is that the job of IT professionals is to keep the systems running and users productive, not to be involved in the day-to-day use of specific applications by a specific user. Is the IT specialist responsible for an accounting system really the right person to make decisions on user access and permissions? Obviously not.
So who is responsible for ensuring that those decisions are made correctly? Put simply, it’s the business that has the most at stake for IAM. Decisions on what roles are required in an accounting system and what they represent, who needs to approve actions, and how strongly the data and functions should be secured is ideally the responsibility of the line-of-business personnel and managers. These are the folks that use the application every day, so they have a more complete and holistic understanding of its implications.
But the reality is that specialized IT pros are often those who know “how” to get things done, so it’s mistakenly assumed they also understand “why” they need to happen. Have you ever overheard a line-of-business manager instructing IT to “set up Bill’s access just like Mary’s?” Access is then duplicated, but there is no guarantee that Mary even has the right access in the first place. And what was Mary’s access originally based on? Somebody else? How many obsolete rights exist? Are there exceptions that have crept into the authorization that have never been revoked? There are simply too many unknowns in this common scenario that can put your organization’s security at risk.
But the reality is that specialized IT pros are
often those who know “how” to get things
done, so it’s mistakenly assumed they also
understand “why” they need to happen.
The same holds true for audits. IT pros know how to get the information, but do not need to understand it. On the other hand, the business knows what they need, but rarely understands what IT delivers. It’s an endless cycle where all the parties make very risky assumptions: “I’m sure it’s right.” Usually that actually means, “I think it’s right and hope this doesn’t come back to bite me later.” Unfortunately, the auditor’s teeth can be sharp… and the animal is hungry.
A hierarchy of IAM needs
You might think equating something as mundane as identity and access management with something as important as self-actualization is an overreach, but there
are parallels between Maslow’s Hierarchy of Needs and IAM. If you remember Psychology 101, Abraham Maslow developed a widely accepted theory that human needs can be defined as a pyramid, with each level attainable only if the one below it has been satisfied. According to Maslow, until physiological needs are met, such as food, water and air, the need for safety cannot be addressed. And until you have safety in the form of shelter and protection, your social needs cannot be met. Satisfying social needs is the foundation for self-esteem, which must be satisfied before self-actualization, or reaching one’s full potential, can be realized.
By no means are we implying that deep philosophical theory and IAM technology are in the same ballpark in terms of weight and significance to humankind. But it is a useful analogy that all of us can easily and quickly understand. There are similarities between this hierarchical approach to human development and the progression we all go through with technology, and specifically with IAM.
Achieving higher levels of self-actualization demands that lower levels be satisfied. IAM is no different.
“Growth takes place when the next step
forward is subjectively more delightful, more
joyous, more intrinsically satisfying than the
previous gratification with which we have
become familiar and even bored.”
1.7 Identity and Access Management for the Real World | 2014 Dell. All rights reserved. Identity and Access Management for the Real World | 2014 Dell. All rights reserved. 1.8
According to our IT hierarchy of IAM needs (Figure 1) and in the real world:
• The foundation for everything is access. If users cannot access systems, or if it is difficult to even create access, nothing else matters.
• Once that access has been enabled, ensuring that it is done securely becomes paramount.
• When security is established control can be added in the form of policies, standards, guidelines, and procedures – the rules that influence and improve security.
• With control in place, management can be added – or the ability to audit and report on all lower levels of the hierarchy.
• Finally self-actualization is achieved as the organization is able to undertake risk management and adhere to external standards.
When all effort is being expended to maintain the foundational levels of the pyramid (access, security, and control) management and governance cannot be achieved. Organizations are challenged as they attempt to navigate the conflict between individuals who know “how” to do the various tasks that move them up the hierarchy, and those who know “why,” and are held accountable for success or failure. IT typically knows how, and the business knows why, with the most at stake. The pyramid is relevant to the “how” and “why” discussion. The narrower a level
is, or the higher it ascends the hierarchy, the less IT can or should be driving the bus, and the more holistically the solution must address needs. As the four “A”s are
addressed in silos, individual systems may be placed anywhere on the hierarchy, but at the governance level, individual systems become irrelevant when compared to the unified whole of the business and the enterprise. Governance does not give a pass to systems still struggling to climb out of access.
So why is it all so hard?
The vast majority of organizations spend most of their time on the day-to-day tasks associated with granting access or securing individual systems. Their never-ending focus seems to be on making IAM processes as efficient as possible. But, once again, the challenge is complexity and diversity.
You know that with every system, a point of authentication and an account must be set up–or “provisioned”–for user access, including a password that must be maintained. These tasks usually fall on IT because they have the rights and tools to set up accounts and enforce password security rules, as well as reset passwords, when necessary.
This complexity is well illustrated by data from The Aberdeen Group, who surveyed thousands of companies with an average size of 21,000
employees on the current state of their IAM approach. Results show a tangled web of complexity that traps organizations in the lower tiers of the pyramid. • On average, surveyed companies supported 198 applications. That’s potentially
198 places where accounts must be set up and managed, 198 different
passwords and password policies, and dozens of IT professionals just to support users on this wide range of applications.
• On average the typical end user must access 27 different applications. Even if only half of those require unique passwords, how many of your users can remember 13 different passwords? And who has to help them when they forget? • On average it takes 12 hours to provision a new user. That’s a full day and a half
The narrower a level is, or the higher it
ascends the hierarchy, the less IT can or
should be driving the bus, and the more
holistically the solution must address needs.
Physiological
Safety
Social
Esteem
Self-actualizationAccess
Control
Security
Management
Governancewhere users are being paid, but don’t have the access they need to do their jobs. And who is responsible for setting up those accounts? How many IT teams must be involved to “fully” provision a user?
• On average it takes 4.9 hours to de-provision a user. That’s more than half a day, giving a disgruntled former employee plenty of time to do damage.
For these reasons, IAM has often been considered the realm of “provisioning” and “single sign-on.” After all, setting up an account and giving a user only one password
should eliminate the need for IT-assisted password resets, at least in theory.
But let’s not forget what should be the top “self-actualization” level in our IAM version of Maslow’s pyramid—governance. Ultimately IAM exists to help organizations achieve business agility. That means the ability to better achieve business objectives such as generating revenue, serving constituents or changing the world through innovation. Agility is dependent on governance – the ability to enforce and know that activities being performed are done according to the rules. And governance cannot be achieved without each of the lower levels of the hierarchy.
You can address each level of the hierarchy for each system in an ad-hoc manner. Or you can seek a unified approach and cohesive product set that grants access, enables security, delivers control, puts management in the hands of the right people, and ultimately helps you achieve governance – across the entire range of systems, user populations, and real-world needs. The Dell One Identity family of IAM solutions does all this and more.
Working things out
I can hear the chorus of IT professionals grappling with complexity…
“There are too many identities.” “I don’t want role bloat.” “This is so inefficient.”
But these concerns are simply no match for technologies available today that can address these complex IAM issues effectively. Diversity is the norm. Dealing with that diversity is the challenge. And it’s up to us to do it in a way that makes life easier for end users, saves money, improves security and helps achieve compliance.
Ever since workplace IT technology emerged and evolved into the highly complex and diverse core capability it is today, organizations have grappled with these challenges. A few options have emerged:
• Do nothing. Many organizations have simply pretended the problem doesn’t exist. They’re content to continue to address complexity through specialized IT teams, doing the best they can with the tools they have, hoping it all works out in the end. Inevitably though, a breach will occur, an auditor will find a material weakness that demands action, or maintaining the IAM status quo will become too expensive.
• Put a bandage on it. When the breach occurs, the auditor comes calling or the accountants raise a red flag, many organizations shop for solutions to address the specific source of the problem. For example, if account management on a single system is the problem, a solution is tailored and implemented to solve it. Unfortunately when the same challenge comes up on another system, the incumbent solution cannot help. So another solution is bought. This bandage approach is extremely common and, while it automates tasks, typically it only preserves the underlying complexity. And specialized IT personnel are still tasked with dealing with the problems.
• Build a framework on top of everything. The traditional approach to the problem is to custom-build a framework that provides a centralized administration point, and satisfies the authentication and authorization needs of a highly diverse enterprise. Typically these solutions are expensive and take years to build. Consequently only the largest and most well-funded organizations have been able to tackle IAM in this way. But these solutions do nothing to reduce the complexity that lies at the core of the problem. They synchronize disparate identity stores and administrative tasks, yet they introduce additional layers of complexity. Plus, they’re so rigid that by the time they are rolled out and things have changed, it’s too late. Unfortunately, these technology-heavy solutions drag IT even deeper into the day-to-day activities associated with IAM.
• Modular and integrated, business-focused IAM. Recently the next wave of IAM technologies has combined the urgency of addressing point problems within a more holistic IAM framework. Because these technologies rely much less on customization—favoring a configurable modeled approach instead—they can be implemented quicker and at a lower cost than “traditional” solutions. And they don’t stand in the way of addressing the next challenge. Wherever you start, adding the next layer is affordable and effective. But the biggest benefit of this IAM approach is that it places power, visibility and control where it should be— firmly in the hands of the business.
Diversity is the norm. Dealing with that
diversity is the challenge.
1.11 Identity and Access Management for the Real World | 2014 Dell. All rights reserved. Identity and Access Management for the Real World | 2014 Dell. All rights reserved. 1.12
The real-world approach to IAM
The last option above is obviously preferred, but what about all of the attempts you’ve already made using the other approaches? You can’t simply pull the plug on your existing investments, retrain your entire staff and start fresh. But what you can do is use a business-centric, real-world approach the next time you are compelled to take action.
For example, if you already have an IAM framework in place, reducing complexity by consolidating Unix, Linux and Mac OS X identities and authentication into Active Directory can dramatically improve efficiency. If you have several point solutions for specific needs, addressing the next need with a modular and integrated solution will yield large benefits down the road – and might just solve those nagging inadequacies of existing solutions.
And don’t forget, compliance will always uncover the next thing for you to worry about. Most initial compliance findings are associated with non-secure authentication and administration practices. Inevitably authorization rises to the surface when the others are well covered. Implementing authorization capabilities that are business centered, modular and integrated for both end users and privileged users is prudent.
Focus on IAM for the real world.
Like every IT professional, you’ve got a lot on your plate. But the choice to focus on IAM for the real world can reap significant rewards. Forward-thinking IAM can be achieved through a modular and integrated approach, and with visibility and control in the hands of the business, not solely IT.
Three major areas of IAM, each with numerous sub-capabilities include:
1. Access management – Simplifying account management, including popular IAM capabilities such as:
• Account creation, modification and termination (provisioning) • Password management and resets
• Single sign-on (SSO) including Web SSO and federation • Strong authentication
• Reducing the underlying complexity of diverse ad disparate systems 2. Privilege management – Understanding and controlling administrator activities, including common capabilities such as:
• Least-privilege access • Separation of Duties (SoD) • Privilege safe technologies
• Session audit and keystroke logging
3. Identity governance – Managing access to business-critical data and capabilities including:
• Access request and fulfillment • Attestation and access certification • Data access management
• Role engineering
• Governance of privileged accounts and administrative-level access Subsequent chapters in this book will address each of these in more detail. Suffice it to say that every organization must be concerned with all three. Regardless of any organization’s IAM maturity, none have everything perfectly executed. There is always room for improvements, and making them with an eye towards real-world IAM will increase security, facilitate better compliance and improve operational efficiency. That’s IAM for today and tomorrow.
A million dollars for your passwords
One of the United States’ largest banks estimates that it was spending a million dollars a month on password resets alone. This cost was largely due to the bank’s many retail tellers frequently accessing several Unix-based applications to do their jobs. By its nature, Unix systems do not share identity data (such as username, password and unique identifiers or attributes) so each system required its own login. Consequently each teller had multiple passwords to remember – and often forget. Add to this challenge the fact that the tasks of maintaining this access fell to the Unix IT team, which was a much more expensive resource than the bank’s traditional help desk staff. When a teller forgot one of his or her 13 passwords, costly IT resources were required to help them get back to work. Unfortunately, this happened a lot. Adding to the inefficiency was the fact that maintaining the lifecycle of these myriad identities also fell to expensive IT resources. This usually resulted in delays in account setup, modification and, most importantly, termination.
The bank was one of the early adopters of technology to consolidate Unix identities and authentication into the ubiquitous single identity offered by Microsoft Active Directory (AD) for Windows-based systems. Simply by eliminating these Unix identities in favor of the single AD identity, each teller now had only one password
One of the United States’ largest banks
estimates that it was spending a million
dollars a month on password resets alone.
to remember, and the Unix IT team no longer had to deal with identity lifecycle management. In addition, password resets and account management activities could be performed by the much less expensive Windows help desk.
Upon rolling out this “get to one password” strategy, the bank experienced an immediate 35 percent decrease in help desk costs. This positive trend continued to improve as the strategy perpetuated itself through the retail teller organization and other areas of the bank.
Dell One Identity
The Dell One Identity family of solutions from Dell Software include each of the capabilities discussed above. But One Identity is different from all other IAM solutions. It includes the breadth to cover not only access management, but also identity governance and privilege management. One Identity is also different from IAM frameworks because it offers the business-centric, modular and integrated approach that has been so elusive in legacy solutions.
One Identity can claim numerous recognitions including:
• In 2013, Dell was designated by Gartner as a “visionary” in the 2013 Magic Quadrant for Identity Governance and Administration – positioned the furthest in the Visionaries quadrant for completeness of vision. (In 2013, Gartner consolidated two separate Magic Quadrants "Magic Quadrant for User Administration and Provisioning" and "Magic Quadrant for Identity and Access Governance.")
• Named the “Overall Leader” by Kuppinger Cole in its 2013 Leadership Compass for Access Governance and a “Leader” for the Identity Provisioning market segment • Named SC Magazine’s “Best Bet” for Identity and Access Management 2009-2011 • Named Editor’s Best Management Suite by Windows IT Pro in 2011
• The fastest growing IAM offering as determined by IDC at nearly 40 percent growth • Manages more than 6,000 customers representing more than 110 million “identities” • Pioneered the Active Directory bridge, sudo privileged account management,
Active Directory management, and access governance spaces
• Offers the most complete offerings for privileged account management and single sign-on
For more information on One Identity, visit us at
software.dell.com/solutions/identity-and-access-management/.
Gartner Inc, "Magic Quadrant for Identity Governance and Administration," published December 30, 2013. Gartner does not endorse any vendor, product or service depicted in its research publications, and does not advise technology users to select only those vendors with the highest ratings. Gartner research publications consist of the opinions of Gartner's research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.
2.2
Identity and Access Management for the Real World | 2014 Dell. All rights reserved. Identity and Access Management for the Real World | 2014 Dell. All rights reserved.
2.1
Access Management – After all, if you
can’t get to your stuff, what’s the point?
Westley:
"Give us the gate key."
Yellin:
"I have no gate key."
Inigo Montoya:
"Fezzik, tear his arms off."
Yellin:
"Oh, you mean this
gate key."
The Princess Bride – 1987
It’s all about access … isn’t it? The only reason technology exists is to make people’s lives easier. The only reason IT exists is to make people’s use of technology easier. And the only reason everything is so difficult these days is that there are outside forces that demand that someone control who can do what with technology. It could be the threat of a nefarious party from outside of your organization trying to steal data, break systems, or just prove a point. Or it could be insiders stumbling across information that you would rather they not see. Perhaps it’s the threat of some pencil-pusher throwing the book at you for some rule you never knew existed. No matter what the scenario, the need to manage access is ubiquitous.
If you recall our hierarchy of IAM needs, the foundation for everything is access. When access is broken, no amount of security, control, management or governance matters. This chapter will address the foundational concepts of access or, as discussed in Chapter One, the first two of the four “A”s of IAM: authentication and authorization. It’s a simple equation… Authentication + Authorization = Access. Even though it may be simple, it’s much easier said than done.
So why is it all so hard?
The vast majority of organizations spend most of their time on the day-to-day tasks associated with granting access. Their never-ending focus seems to be on making IAM processes as efficient as possible. But, once again, the challenge is complexity and diversity.
You know that with every system, a point of authentication and an account must be set up (“provisioned”) for user access, including a password that must be maintained. These tasks usually fall on IT because they have the rights and tools to set up accounts and enforce password security rules, as well as reset passwords, when necessary.
The evolving enterprise
Gone are the days of all users on premises. No longer do average users require access to only a handful of IT-controlled applications. And control over this business-enabling technology is rapidly moving beyond the direct control of the organization and into the realm of third parties, such as outsourced service providers and software-as-a-service (SaaS) vendors. Plus there’s the trend of mission-critical data and applications owned and managed by partners or vendors.
Today users can be anywhere and everywhere, and the applications and data they must access can run the gamut from fully within your control to entirely outside of
Chapter 2
your influence. Simply granting someone appropriate access based on what they need and how they are logging in has now become an endlessly moving target.
But let’s not forget what the purpose of technology is in the first place – helping your organization reach its goals. Ultimately IAM exists to help organizations achieve business agility. That means the ability to better achieve objectives such as generating revenue, serving constituents or changing the world through innovation. Agility is dependent on governance – the ability to enforce and know that activities being performed are done according to the rules. And governance cannot be achieved without security.
Access management exists to efficiently execute the tasks that enable users to do their jobs and ultimately enable the business. Unfortunately, every organization, even the most agile, has pockets of difficulty on the access and security fronts that are preventing them from reaching higher levels of control, security and governance.
The wide world of access management
These “keeping the lights on” activities – also known as access management – cover the gamut of needs across the full range of systems. These activities must be performed on each and every system for each and every user before any additional value can be realized. This diversity and redundancy stands in the way of efficiency. For example, why does it take a day and a half to fully provision a user? It’s because provisioning is performed individually on each system by specialized IT resources that may be following their usual—yet potentially outmoded—practices. The same holds true for passwords.
A large government agency calculated the complete cost to manage user access across its Windows and Unix/Linux environments. Taking into account labor costs, physical resources, the cost of downtime and other factors, it was found that each individual IT-assisted access management activity cost more than $300. When applied to its 250,000 users, the annual expense was staggering.
Some of the most common access management principles include:
• Provisioning –setting up, lifecycle management, and retiring of the mandatory user accounts that enable access. To many, provisioning is considered the end-all be-end-all of IAM.
• Password management –processes for establishing and enforcing password policy, including expiration frequency and password complexity, as well as anything done to facilitate changing and resetting passwords. This is a constant headache for help desk techs.
• Single sign-on – creating a single login scenario for users to eliminate multiple passwords. Single sign-on is perhaps the most misunderstood aspect of identity administration.
• Strong authentication – those things done to ensure that user logins are as secure as possible. This may include stronger password policy, encryption technology to protect the password in transit, or adding additional “factors” to more advanced identity verification.
So when you step back and look at what impacts all these common access management principles, you find that each of them is impacted by the: • Number of systems they must be executed on
• Diversity of those systems
• Amount of manual work typically required of IT • Number of IT teams that must be involved • Business importance of the system in question
In other words, as things get more complex and as systems become more
incompatible, the more difficult they are to get right... and the more impossible it is to properly address security and achieve governance and business agility.
Provisioning
Account setup, changing, and retiring are significant challenges, particularly with user population growth and the diversity and increase of systems that must be accessed. Manual processes demand dedicated IT staff for each system. Workflows are often based on how they have done things in the past. Provisioned rights are rarely anything more secure than “give Joe the same access that Jane has,” even though there is no guarantee that Jane even has the correct access in the first place. It’s a burden for IT, a productivity killer for end users, and an auditor’s compliance-violation poster child.
“Traditional” IAM frameworks aren’t much better. While they are designed to automate provisioning enterprise-wide, by their very nature, they require everything custom-built. Account definitions, authorization roles, business logic, workflow, and approvals all must be customized for each and every system. Consequently if and
It was found that each individual IT-assisted
access management activity cost more than
$300. When applied to its 250,000 users, the
annual expense was staggering
2.5 Identity and Access Management for the Real World | 2014 Dell. All rights reserved. Identity and Access Management for the Real World | 2014 Dell. All rights reserved. 2.6
when the framework is finally up-and-running, requirements have changed and the customization starts over.
A large investment firm recently chose to go the IAM framework route for provisioning. The customized solution required a team of nearly two-dozen Java developers working full time to build the required provisioning
capabilities. After more than 18 months (imagine the cost of this team of highly paid full-time professionals) the company has succeeded in automating provisioning for only one system and has been unable to automate de-provisioning on that same system. The hundreds of other applications within the scope of the project remain untouched.
Obviously, a real-world approach to provisioning would navigate the complexity of even the largest and most diverse enterprise. It would be rapid to deploy and nimble enough to quickly adjust to changing requirements. And it would remove the shortcomings of relying on IT for everything by automated process and putting control in the right hands. Dell One Identity Manager solution delivers provisioning that satisfies all of those demands.
Single sign-on
Single sign-on is the next most visible area of identity and access management. But single sign-on (SSO) is many things and no one definition covers all use cases and
all available technologies. Essentially, SSO means reducing the number of logins required to access multiple, diverse applications. There are many technologies and several common strategies that can all legitimately claim the title of SSO, namely: • True SSO – authentication to multiple systems with a single login and a single
credential shared by those systems and generated upon that login. True SSO is what Microsoft has created for Windows systems with Active Directory (AD) and
is commonly offered by AD bridge technologies for non-Windows systems that leverage the AD credential.
• Enterprise SSO (or form-fill SSO) – technologies that store diverse passwords and automatically enter them when a login action is undertaken. These types of solutions typically cover the widest range of systems, however, they are inferior from a security standpoint to true SSO.
• Password synchronization (or same sign-on) – technologies that make sure that all passwords across multiple systems are the same. Password synchronization still requires individual logins for each system, however, it ensures that the user only has to remember one password, albeit entered each time access is required. • Federated SSO – solutions for access that cross organizational boundaries.
Federation solutions trust the user identity and rights that originate from outside of the requesting organization–such as between a vendor and supplier or between partnering companies. Federation scenarios require an identity provider (IDP) or the party supplying the identity and a service provider (SP), or the party granting the access.
• Web SSO – single sign-on to web applications on the Internet or on premise, accessed via a browser either on premises or remotely.
Every environment is different, but it is safe to assume that no environment is adequately served by a single SSO solution type. In fact, even within specific types of SSO, different applications can have different requirements. For example some web applications use a standard called SAML to provide authentication, while others leverage Microsoft’s WS Federation. Still others use proprietary means of authentication and can only be served with a form-fill SSO solution.
Consequently, a real-world approach to SSO will provide the best SSO option for each and every affected application. This may mean AD-based true SSO for Unix and Linux systems and SAP, password synchronization for a mainframe, a combined and broad web SSO and federation solution for web applications, and an enterprise SSO solution for the rest.
Password management
If we didn’t have a need for secure and controlled authentication, none of the challenges of IAM would exist. But we need security and we need the assurance that the person logging on is the approved user. In other words, at a minimum, we need passwords. And someone has to manage those passwords.
Single sign-on is the next most visible area
of identity and access management. But
single sign-on (SSO) is many things and no
one definition covers all use cases and all
available technologies.
Nothing kills productivity or needlessly diverts IT resources better than a forgotten password. Each password reset costs every organization a different amount, but odds are it isn’t the best use of IT’s time or talents. Conservative estimates place the cost of a single IT-assisted password reset in the neighborhood of $25. In a large organization with tens of thousands of users each with a dozen or more passwords, the tab can grow quickly.
Single sign-on is one approach to alleviate the password burden. Another, complimentary approach is to remove the resetting of passwords from IT and place it in the hands of the end users. IAM for the real world adds self-service password resets and granular password policy to provisioning and single sign-on, as well as to governance capabilities (discussed in later chapters). Dell One Identity can help your organization do SSO the right way with a complete range of SSO options and adjacent technologies that offer benefits achieved through streamlined logons.
Strong authentication
The natural next step is to strengthen authentication beyond the native capabilities of individual systems or in excess of the typical username and password login. Many organizations choose to introduce additional levels of authentication assurance for specific users, such as contractors. They may also choose stronger authentication for highly sensitive needs, such as for privileged access or for regulated transactions. Access can also be requested in scenarios outside of IT’s direct control, such as for remote and mobile users.
Strong authentication can take the form of extending a more secure authentication method, such as Active Directory’s Kerberos authentication, to systems with less secure methods, such as Unix and Linux systems. It can also be adding a second factor to usernames and passwords. A real-world approach to IAM will make strengthening authentication simple, affordable and easy to manage without sacrificing security.
What if you could get to one identity?
The government agency discussed earlier faced the challenges of provisioning, single sign-on and password management that result from extreme complexity and diversity. Account management, password resets and group management were difficult for its Active Directory environment, which only required one identity per user. Those essential tasks were nearly impossible for its Unix and Linux systems, which required a distinct identity for each user on every server. By placing a bet on Active Directory, the agency fully automated account and group management, dramatically relieving IT of a previously obtrusive workload. It also moved password resets away from IT by enabling end users to reset their own forgotten passwords. Finally, the agency removed the need for Unix and Linux systems to have their own identity stores, opting instead to link them to the single AD identity through an Active Directory bridge. That meant that the account management activities performed through automated tools on AD would automatically affect access to Unix and Linux systems. Active Directory groups could now be used to control that access, and a user self-service password reset performed on the AD identity would grant seamless access to Unix and Linux.
The agency reported a savings of more than $40 million in the first year of this unified and automated identity administration approach.
The benefits of this unified approach to access management are fairly obvious. The fewer identities there are to administer, and the better you are able to administer them, the higher your IT organization can move up the hierarchy pyramid. So how can you achieve this when complexity is the rule and you may already have tools, or even an IAM framework, in place?
I’ve seen many organizations similar to the example above that have faced those exact same challenges. Without fail, the key to successful access management has been to follow a few basic principles:
• Automate what matters most. In most organizations, the largest and most important identity store to administer efficiently is Active Directory. Typically, every user has an AD account. AD groups are used to control access to important Windows resources, such as Exchange. And the AD password is the one users remember because they use it every day. But managing AD can be difficult without help. Tools exist to help you manage AD users and groups efficiently and securely. • Enable users to help themselves. Simply implementing an AD-based self-service
password reset solution can dramatically improve operational efficiency. At an estimated $25 per IT-assisted reset, the return on investment of a self-service solution is rapid and significant.
The agency reported a savings of more
than $40 million in the first year of
this unified and automated identity
administration approach.
2.9 Identity and Access Management for the Real World | 2014 Dell. All rights reserved. Identity and Access Management for the Real World | 2014 Dell. All rights reserved. 2.10
• Extend AD. If AD has challenges, Unix, Linux and Mac OS X systems have them in spades. By their very nature, Unix-based systems do not share a common identity store like AD. Consequently every server has a distinct identity for every user. That means many passwords to remember and generally, only highly paid Unix IT staff are able to reset forgotten passwords. Active Directory bridge technologies remove the identity burden from Unix, Linux and Mac, and allow them to participate as a “full citizen” in AD, much like a Windows resource. So the administrative activity performed through an AD-optimized tool automatically takes care of account creation and termination, group enrollment, and identity lifecycle management needs required for Unix access. And a self-service password reset in AD automatically restores access to the Unix system. • Start with SSO where it will have the biggest impact. Single sign-on can make
a significant difference, particularly where user satisfaction and IT efficiency are concerned. However, universal SSO can be difficult to achieve. Choose the systems and access scenarios that are causing the most inefficiency and biggest security risk and implement SSO starting there. Often SSO for web applications, remote users, and federated scenarios will yield significant and immediate positive results.
• When in doubt, use strong authentication. For those users and access scenarios that concern you the most, consider adding a two-factor authentication
solution. But be cautious and choose a solution that doesn’t add to the IT workload and doesn’t require additional complexity to increase security. This approach firmly supports the modular and integrated strategy that is so critical to IAM success. An AD-optimized administration solution can be implemented stand-alone, as can a self-service password reset solution or an AD bridge. However when combined, the benefits are amplified. None rely on a proprietary “framework” for success. In fact, dozens of organizations with established IAM frameworks have seen an accelerated return on investment. They optimize access management for AD
and extend it to many non-Windows systems, eliminating the need for cumbersome custom integration and inferior management of access to AD, Unix, Linux and Mac.
Dell One Identity
The Dell One Identity set of solutions is a comprehensive collection of modular and integrated tools to address your real-world access
management needs, regardless of where on the hierarchy of IAM needs you currently sit. Dell enjoys deep expertise in Active Directory, and we pioneered the Active Directory bridge space. Dell IAM solutions can help your organization move up the pyramid to security, control, management and, ultimately, governance – all with the endgame of enabling business agility.
For access management, the Dell One Identity family includes:
• Optimized Active Directory security and management – Active Roles is the industry leader in AD administration that includes account management, group management, security and many other IT-enabling capabilities that overcome the native weaknesses of AD.
• Active Directory bridge – The Privileged Access Suite for Unix includes the most robust and long-standing AD bridge on the market. It removes the need to administer identity on a box-by-box basis for Unix, Linux and Mac OS X systems. Plus, it enables advanced security and manageability features only available through AD.
• Single sign-on – Dell One Identity has the industry’s most complete set of single sign-on options. This includes Cloud Access Manager, a unified SSO solution for access to web applications on premises and remotely, regardless of application or authentication needs, such as federations and SaaS. Dell One Identity also includes solutions for true SSO, password synchronization and enterprise SSO. • Multifactor authentication – Dell One Identity includes Defender, a
one-time password solution that builds on existing AD infrastructure for an easily implemented and managed alternative to passwords only.
• Virtual directory services – Dell One Identity overcomes the challenges of
incompatibility and complexity presented by multiple disparate identity stores. This is done through a virtual directory server that removes the burden of integration from the directory itself, and facilitates rapid and thorough integration and migration. Would you like more information on access management solutions within the Dell One Identity family? Try a free online demo, download a 30-day trial, or visit us at software.dell.com/solutions/identity-and-access-management/.
Dozens of organizations with established
IAM frameworks have seen an accelerated
return on investment. They optimize access
management for AD and extend it to many
non-Windows systems.
Identity Governance – Governance leads
to agility
How often do our efforts at governance seem like the futile attempts of the boys in the band to find the stage in the 1984 comedy, This is Spinal Tap? How often do those we rely on for governance seem to be speaking a different language? And how often do we, in spite of our best intentions and efforts, find ourselves wandering through the maze of our organization, hoping to stumble across the stage door that leads to our dream gig?
For our discussion, governance is defined as business-enabling activities that move technology beyond simple efficiency tools into the realm of confidently and correctly providing access and performing administrative activities. This also means all this is done with the full knowledge and endorsement of the organization, while satisfying any internal or external regulations. Providing all these requirements are met, governance acts as the framework for how those activities should be done. Put simply, governance is ensuring that:
• The right people… • Have the right access… • To the right resources… • At the right time… • In the right way…
• With all the other right people knowing what’s going on and saying it’s okay. In a perfect world, getting it right would be easy. The risks of inappropriate access or activity would be minimal because all of it would be controlled by the right people with complete visibility. Your organization could easily satisfy compliance requirements. If an auditor asks for information, or you need a periodic entitlement recertification, you could generate an accurate and user-friendly report with just a few mouse clicks. But, unfortunately, we don’t work in the perfect world. We work in the real world.
In the real world, governance is a major challenge. In fact, governance can’t even be considered until access, security, control and management have been achieved. If simply provisioning access is difficult, leveraging that access to enable business agility – the goal of governance – is impossible. If all your time is spent remedying a forgotten user password, for example, how are you going to ensure that the correct controls are in place so that the user had the appropriate access in the first place? And that’s just a couple of components of being compliant. The real challenge is proving compliance.
Once again, the challenge is complex.
Chapter 3
"You go straight… down the hall,
turn right… go about 30 feet, jog
to the left… straight ahead… turn
right for the next two corners…
first door says ‘Authorized
Personnel’… You’re musicians,
aren’t you? Rock and roll… Hello
Cleveland! Hello Cleveland!”
Backstage maintenance guy,
Derek Smalls, and Nigel Tuffnel
"This is Spinal Tap" – 1984
3.3 Identity and Access Management for the Real World | 2014 Dell. All rights reserved. Identity and Access Management for the Real World | 2014 Dell. All rights reserved. 3.4
Several key “governance” factors are involved in a typical audit. They may take different forms, but it all boils down to:
• Provisioning – making the process of thoroughly and correctly granting access across the entire environment as efficient as possible. This includes the more important security-related action of “de-provisioning.” While provisioning itself is an access management activity, without provisioning done right, governance is impossible.
• Workflow – showing the steps from access needed to request to fulfillment, ensuring compliant processes are followed throughout
• Attestation – fulfilling the periodic requirement to review all access entitlements (or rights) and certify their appropriateness
• Policy – documenting and enforcing the underlying rules that govern user access to applications and data, as well as showing that those rules comply with established regulations
• Approvals – ensuring all the right people approve access requests before it is fulfilled While access management is primarily concerned with simply getting things done (see Chapter Two), governance addresses getting those things done the right way.
The elephant in the room
There’s an old story about a bunch of blindfolded people being let into a room with an elephant and asked to identify it based on only what they can feel with their hands. One felt the elephant’s tail and declared, “it’s a rope”. Another, feeling the elephant’s side stated, “It’s a wall!” The trunk was identified as a snake, the leg as a tree, the tusk as a spear, and the ear as a fan. We’ll pretend that none could smell or hear… but that’s beside the point. Each person’s perception of the elephant was limited to what they were able to experience directly.
Governance is similar.
It seems that the default approach to governance is limited to what an organization is experiencing at the time, or what they are able to most easily comprehend, measure and control. For many, governance may be confined to the narrow scope of satisfying the auditor’s finding of the day. For others, governance may be influenced by a specific security breach or incident. And to still others, governance may be focused on the organization’s “crown jewels,” those applications or data sets that are the most important to achieving business agility. All are absolutely appropriate and all are equally important. However, just like the elephant in the room of the blindfolded, a narrow focus will leave out critical pieces of the bigger picture.
Therefore, governance must be concerned with the whole of IT, not just the easy parts. Governance for the real world should be focused on:
• User access to all applications • User access to all types of data • Administrator access to all systems
The root of the problem
The challenges associated with governance are all too common in today’s highly complex and security-conscious landscape. Basically governance can be illustrated by a “closed loop” model.
User account
A
cc
ess
At
test
Pr
o
vi
si
o
n
Policy Role"96 percent of breaches were avoidable
through simple or intermediate controls."
Source − 2011 Data Breach Investigations Report, Verizon RISK Team with cooperation from the US Secret Service and the
Dutch High Tech Crime Unit
"48 percent of respondents rated the odds of
experiencing a compliance risk within the
next 18 months as “high” or “very high.”
Source – State of Compliance 2011, PWC
As discussed earlier, each system requires access; therefore each system can be subject to governance. Access is the result of provisioning that is controlled by policy and streamlined through the use of roles or other attributes. Compliance demands attestation to the appropriateness of the access, which in turn feeds into continued maintenance of the identity lifecycle for continued access. The operable word here is “each” system. Just as executing the four “A”s across a diverse large mix of systems is the source of inefficiency, and ultimately security vulnerabilities, this same diversity (or complexity) makes approaching governance on an ad-hoc basis inadvisable. What do you start with, and what do you leave out? There are simply too many ingredients required to make the soup, and too many cooks in the kitchen.
The “real world” of governance for the vast majority of organizations looks like this: • Many and varied systems (applications, data sources, capabilities, etc.) that users
must access to do their jobs
• Too many different ways that access is granted
• Many different IT teams with too narrow an area of expertise • Too little knowledge from the business of how these things work
• Too little knowledge from IT as to why they need to work in a certain way, and what the implications are if they don’t
• Too much reliance on “this is the way we’ve always done it”
• Too much blind verification … “If Joe has the same access as Sally, it must be right…right?”
• Too much security policy developed by those that implement it (IT) rather than those on the hook if it goes wrong (the business)
• Too little visibility by the business into what access people have and how they got it A real-world approach to application access governance includes prerequisites to governance like good provisioning, strong policy, adequate visibility, and a complete understanding of who can access what. All this would be tightly coupled with the ability for the right people to easily have access to the information they
need to do precisely that – govern. Only the Dell One Identity family of IAM solutions and Dell One Identity Manager provides these governance-enabling capabilities without the heavy overhead of a cumbersome and rigid framework, or the myopic inadequacy of a focus only on one area, one type of user, or one aspect of governance.
Too many closed loops
Many organizations take a stance that governance begins and ends with user access to applications. It’s understandable since applications are highly visible. Applications are most easily understood and have been targets for governance initiatives and vendor solutions for many years. And applications absolutely must be governed. But how many applications do you have and how many “closed loops” do you end up with? How many manual processes exist that put the IT team and line-of-business personnel on different pages? How difficult is it to provide even the most basic governance information?
User account A cc ess Attest Pro visi on Policy Role User account A cc ess Attest Pro visi on Policy Role User account Acc ess Attest Pro visi on Policy Role User account A cc ess Attest Pro visi on Policy Role User account A cc ess Attest Pro visi on Policy Role User account Acc ess Attest Pro visi on Policy Role User account A cc ess Attest Pro visi on Policy Role User account Acc ess Attest Pro visi on Policy Role
In the real world, unifying governance for all applications can move you miles closer to agility. Ideally, you want them to be tied to an equally unified enterprise provisioning approach with a single source of the truth for policy, workflow, roles and approvals.
All applications
A
cc
ess
At
test
Pr
o
vi
si
o
n
Policy Role“ 57 percent of surveyed organizations cite
complexity of IT environment' as an inhibitor
to achieving IAM objectives. The average
IAM initiative has been ongoing for six years."
Source Aberdeen Group
Figure 2: Traditional approaches to governance implement separate closed loops for each system or scenario that must be governed.
Figure 3: A unified approach to governance provides a single closed loop that encompasses all access needs.
3.7 Identity and Access Management for the Real World | 2014 Dell. All rights reserved. Identity and Access Management for the Real World | 2014 Dell. All rights reserved. 3.8
But applications are only part of the story. A very large percentage of data at any organization can be classified as unstructured.
Unstructured data exists outside of the strictly organized confines of a database. Unstructured data can be spreadsheets, PDFs, videos, audio files, PowerPoint presentations or Word documents.
These can contain benign information that’s not governance demanding, but very often they contain critical data regulated by compliance. For example, spreadsheets that contain personally identifiable information such as Social Security Numbers, birthdates and addresses must be governed. Proprietary information, such as trade-secrets, plans and financial performance, often exists in PDFs and PowerPoint presentations. Unfortunately unstructured data exists in myriad places – many outside of the control of IT. File shares, NAS devices, and SharePoint sites may contain sensitive unstructured data. In many cases, the best an organization can do to govern these resources is to roughly control access to the server or file share itself – a lowest common denominator approach that either is too restrictive for efficiency, or too lenient for compliance.
So governance of access to unstructured data often follows the same path as application access governance: disjointed, nonexistent, manual or inconsistent. Bottom line, doing the best you can with what you have is not good enough. Our closed loop governance model reflects the challenges of provisioning, providing appropriate access and attestation. These challenges are magnified as the diversity of locations for unstructured data expand and more of those locations slip out of the control of IT – the ever-popular SharePoint gone wild! In some areas closed loops exist. In others they don’t.
Unstructured data
A
cc
ess
At
test
Pr
o
vi
si
o
n
Policy Role Unstructured data Acces s Attest Provi sio n Role PolicyThe number of circles representing governance of unstructured data could be much larger than those representing application access. And the potential for rogue storage locations, non-governed access permissions and sensitive data being innocently put at risk is extremely high.
In the real world, it makes no sense to address governance of unstructured data independently of application access. The users are the same, the roles that should control access should be identical, and the line-of-business personnel that are on the hook to attest to access don’t change when the app or data being accessed is different or more difficult to govern.
Privileged accounts—such as the Unix root account, an application
administrator account, or the superuser account required to administer any system—are a governance nightmare. Their high level of access rights, their anonymous nature and the lack of visibility makes them high risk. (We’ll have a more thorough discussion of privileged account management in Chapter Four.)
If governance of unstructured data is difficult, then governance of privileged access is nearly impossible when approached in the disjointed manner so often applied to shared superuser access. Remember our hierarchy of IAM needs. Application access has matured to the point that, if you want governance, you can get it. Data governance is in a similar state, though less visible. However, the vast majority of privileged account activities are mired at the access and security levels of the hierarchy, barely dipping their toes in control or management. Governance for privileged access struggles to achieve a closed-loop model.
Acce
ss
Attest
Pro
vi
si
o
n
Role Policy PolicyFigure 4: It is difficult to implement a closed loop governance model on disparate sets and locations of unstructured data.
Figure 5: Governance for privileged access typically struggles to achieve a closed-loop model.