Digital IdentityIAMIdentity and Access ManagementIT Security

Demystifying Identity Management

Demystifying Identity Management

Demystifying Identity Management

Protecting modern business systems from unauthorised access, and ensuring that data breaches do not occur, requires a multi-faceted cybersecurity strategy. A vital component of the strategy is to ensure that all access to systems and data is controlled by robust identification and authentication procedures. The access requests that need controlled can be from staff, customers, other IT systems, or IoT enabled devices, and other sensor-enabled operational technology and IT systems. Anything that is on your network should have a unique identification account that can be used to grant and control access to specific systems on a needs only basis.

Multiple solutions with varying levels of security and control have been developed to manage and secure access to IT systems. Like most areas of modern life, the field has generated many acronyms that experts use when discussing approaches and solutions. In the sections below, we provide a primer on the three main areas used when talking about identity management, and the subsets within them where appropriate. In follow-up articles we’ll go into each of the three main areas in depth, and outline how Renaissance partners can provide the solutions to deliver secure identity management for organisations of any size.

Identity and Authentication Management (IAM)

Identity and Authentication Management (IAM) is the core foundation of an identity management strategy. IAM solutions deliver the tools to provide a unique account for all entities on the network. They also allow each access account to be secured with techniques like multi-factor authentication, and IAM enables administrators to set access privileges and enforce access policies. User activity can also be tracked and reported on, and this data can be used to plan for future growth and changes to systems and networks.

IAM systems need to work on all platforms in use in modern enterprises. These include on-premise systems, applications deployed across multiple cloud systems, Edge computing systems like IoT devices and concentrators, and also for the numerous devices and remote access methods that are now common.

Within IAM some sub-categories are often discussed. For example:

  • Customer identity and access management (CIAM) - secure access for external customers.
  • Identity Analytics (IA) - real-time monitoring and reporting on suspect activities.
  • Identity as a Service (IDaaS) - cloud-based, self-service identity management solutions.
  • Risk-based Authentication - context-aware IAM that customises access based on the risk of the incoming access request.

We’ll take a closer look at these, and IAM more generally in a follow-up article.

Privileged Access Management (PAM)

Privileged Access Management (PAM) builds on IAM but is designed to ensure that the most critical network accounts and assets have additional protections and scrutiny. Accounts that fall into this category are admin accounts that can grant access rights to others, system accounts that provide full access to IT systems, and any accounts used to access business systems classified as critical. This is not an exhaustive list. Each organisation will have a unique IT landscape, and each will have a view on which systems are critical.

PAM solutions take critical accounts, and other user accounts used to access critical systems, and store them in secure vaults. In order to get the account to access a system, the PAM solution will enforce a workflow that ensures the person or operation asking is allowed access. All requests, whether granted or not, are logged and can be monitored for suspicious activity. PAM systems give access requests on a single-use basis. Any future access attempts cannot use the same login credentials again but have to go through the PAM workflow once more. We’ll cover some of the finer details that PAM solutions deliver in the next article in this series.

Identity Access Governance (IAG)

Identity Access Governance (IAG) is not a technology solution, but rather a policy made up of a set of principles and procedures that organisations should adopt and follow to deliver secure identity management. A good IAG policy will include the use of IAM and PAM systems. It will also identify which accounts and systems that are classified as critical and that need PAM protection.

The IT threat landscape is always changing. So IAG policies need to be reviewed and updated regularly so that new threats and vulnerabilities do not impact on security. An IAG policy is the framework and workflow that ensures that access security is reviewed and kept up to date.

We’ll outline the aspects of a robust IAG policy in the third article of this series.

Conclusion

 

It’s stating the obvious, but security depends on proper identity management, alongside other essential security tools such as border firewalls, anti-malware protection, and more. Gartner estimates that the global market spend on identity management solutions in 2020 will be over $10B. This article gives a high-level overview of identity management. The next two articles in this series will dive into IAM, PAM, and IAG. However, if you want to discuss identity management today, then contact us.