Digital IdentityIdentity and Access Management

Building your Identity Management Process

Building your Identity Management Process

Building your Identity Management Process

In previous articles we outlined the three main pillars of identity management. To recap, they are:

  • Identity and Authentication Management (IAM) - the core of identity management used to verify the identity of users and systems requesting access, authenticate them, and then authorise access to the systems and data they are allowed to use.
  • Privileged Access Management (PAM) - the next level of identity management that audits, monitors, controls, and reports on any privileged accounts that are in use. Privileged accounts are those that can perform actions that impact on other accounts, systems, or data that goes beyond what is needed to conduct day-to-day business tasks. For example, system administration accounts, or accounts with root access to databases. Plus many others!
  • Identity Access Governance (IAG) - the policies, workflows, and procedures that govern how identity and access are agreed and managed on an ongoing basis.

We'll talk more on the third point in this article.

What is IAG?

IAG defines the policies, permissions, and workflows that govern who gets access to data and IT systems that an organisation controls. The IAG provisions put in place are used to decide who should have access and to certify that the access is required for the requested reason. To be clear, this is not for day-to-day access requests. That is the role of IAM and PAM solutions. No, IAG is for executive and managerial decision making around data access and IT security rules. The decision making within an IAG strategy needs to be done within whatever regulatory frameworks the organisation follows. In today’s business environment, that will be at the very least mean taking into account GDPR, PCI DSS, and whatever sector level rules are in force.

What Does an IAG Strategy Need?

Four areas are required for a good IAG strategy and policy. They are:

  1. A process to define roles within an organisation - the right people need to decide on access requests, and on what permission levels they need to do a job. Nobody should have access to data due to their status, or seniority within an organisation. Only those who need access to perform their job function should have access. And if required, their access to critical systems should be via a PAM solution as our previous article outlined. The definition of what is a critical system that needs PAM protection is part of the process that defines roles under IAG.
  2. A definition of processes that need to be followed - the IAG strategy needs to define the methods that are used. So that those with defined roles can request access to the systems they need. This should have different levels for general access to less critical systems, like an email address for everyone, and also more restricted PAM access to other IT systems. The processes should also outline how all access and access requests are monitored, logged, and recorded for future review. Alerting should be in place both electronically and via management chains for any suspicious behaviour.
  3. Ongoing monitoring of existing granted permissions - businesses are dynamic entities. Job roles and their access requirements change over time. IAG policies need to be reviewed frequently and revised to ensure they are up to date. Permissions granted to users and accounts that no longer need them should be revoked.
  4. Continuous monitoring of internal and external environments - internal and external regulations and policies change over time. As do the security threats to IT systems. IAG strategies need to ensure that these changes are captured and dealt with in ongoing reviews.

The Benefits of Having an IAG Policy

Having a well-honed, and frequently reviewed, IAG strategy and set of policy documents for all to follow provides many benefits. Not least of which is making it easier for the organisation to achieve business process and security certifications and reduce the workload when audits are required. Also, following IAG policies will lead to fewer data and IT system related errors, and therefore less time spent dealing with issues due to inappropriate data access. The provisions put in place to deliver IAG also allows for better monitoring of IT systems, faster response times to problems, trend analysis of the captured access data over time, which feeds into better systems design and sizing for future upgrades.

IAG improves productivity for both managers and users. By simplifying and documenting what needs to be done to grant access to an IT system, managers can quickly review and decide on a request, and users don’t have to wait for extended periods to get access if it is granted to them. Having a well-outlined access request policy and workflow also deters policy violations as it is known they will be detected.

Security is generally enhanced when an IAG strategy is in force and frequently reviewed. As the threat landscape and surface area expand, and the threat vectors change, the review process for an IAG strategy and policies will allow for new dangers to be identified and mitigated. This allows for ongoing enhanced risk management to be built in and core to the security processes. All within a process that will have a defines allocation of staff resources and budgets to function.

IAG on the broader Identity Management Landscape

All three pillars of identity management work together and when in place, reinforce each other to make a solution greater than the sum of their parts. The IAG strategy ensures that the IAM tools and policies needed are in place. Both feed into the use of a PAM system to protect critical data and IT systems. Also, the whole identity management provision works alongside other crucial security components like border firewalls, intrusion detection, and anti-malware tools.

Final Thoughts

Renaissance and our partner network can help you define, draw-up, and deploy an IAG strategy for your organisation that fits into your existing security profile. Contact us to discuss your needs.