Cyber SecurityIdentity and Access Management

A Closer Look at Identity Management Options

A Closer Look at Identity Management Options

A Closer Look at Identity Management Options

In a previous article, we outlined the three pillars of identity management at a high level. They are:

  • Identity and Authentication Management (IAM) - the core of identity management used to verify the identity of users and systems requesting access, authenticate them, and then authorise access to the systems and data they are allowed to use.
  • Privileged Access Management (PAM) - the next level of identity management that audits, monitors, controls, and reports on any privileged accounts that are in use. Privileged accounts are those that can perform actions that impact on other accounts, systems, or data that goes beyond what is needed to conduct day-to-day business tasks. For example, system administration accounts, or accounts with root access to databases. Plus many others!
  • Identity Access Governance (IAG) - the policies, workflows, and procedures that govern how identity and access are agreed and managed on an ongoing basis.

In this article, we will take a closer look at the first two items, and provide an outline of how Renaissance's partner Senhasegura can help deliver robust IAM and PAM. I'll discuss IAG in a future article.

What an IAM Solution Delivers

As outlined above the core purpose of IAM is to deliver identification, authentication, authorisation, and then ultimately secure access to business systems.

Establishing identity is usually done via a user ID. With each person, or operation that needs to access IT systems, given a single login account. Often in business settings, these User ID's are created and stored in directory services such as Microsoft Active Directory. With federation to cloud services so that the ID can be used for access across cloud and on-premise IT systems.

Each user ID needs to be authenticated before access to any systems. Authentication is typically done via one or more of these methods:

  • Passwords - the traditional password, and the simplest form of authentication. The best practice is to use separate, secure passwords that are hard to guess via brute force methods. Password management solutions that generate strong, random passwords, and enter them for users are a great addition to any IAM policy.
  • Multi-factor authentication - in addition to secure passwords, multi-factor authentication ensures that additional information is required to authenticate a user ID. So even if a strong password is compromised, more information is needed to authenticate successfully.
  • Biometrics - biometric data such as fingerprints and face scanning are increasingly being used to authenticate user IDs. This lessens the burden on users, especially on mobile devices, where strong passwords can be hard to enter. Especially when a secure password management solution isn't in place to automatically enter passwords.
  • Cryptographic key backed certificate - Some automated access, for example, between IT systems without human intervention, often uses certificate-based cryptographic keys to ensure that the requests are from a recognised system.

Once a user ID is authenticated successfully, then the IAM solution needs to authorise the ID to access specific IT systems, applications, and data sources on the network. Access should only be allowed to the bare minimum of systems needed to perform a user's job. Additionally, the device and location that a user ID authenticated from should be factored into the authorisation granted. For example, a desktop PC in an office could be given more trusted access, than that allowed from a personal laptop connecting from a random location on the Internet.

IAM systems enable user IDs of various types to be provisioned and managed. Such as accounts for staff, contractors, clients, and suppliers. So that each group can access the systems they need, and nothing more.

Most IAM solutions also provide the ability to do analytics on authentication requests, reporting, and also work across multiple systems, including those based in the cloud. Increasingly, cloud-based identity management systems are being used to allow for rapid deployment and scaling as needs change.

Using PAM to Protect Your Most Valuable Assets

 

The IAM solutions that deliver the functionality outlined above provide the security and authorisation required for many information workers and others who need to access business systems and applications. Some user ID's and systems are so critical and have so much power to effect change, that they should be given additional protection. This is where PAM comes in.