Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock...

26
Take control of your identities Cyril GOLLAIN, General Manager Brainwave ForgeRock Summit June 2013

description

Presented by Cyril Gollain, General Manager for Brainwave at ForgeRock Open Identity Stack Summit June 2013

Transcript of Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock...

Page 1: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Take control of your identities

Cyril GOLLAIN, General Manager – BrainwaveForgeRock Summit – June 2013

Page 2: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

2010Brainwave creation1st patent

2011Product RTMInnovation award

201220+ customersGartner IAG MagicQuadrant

2013KuppingerCole Leadership CompassGartner Cool VendorInternational Biz Dvp25+ customers

Brainwave

2

A market leader in Identity Intelligence

Page 3: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information – All Rights Reserved.

Second law of thermodynamics

Entropy never decreases

Page 4: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

The User Entropy: Access rights everywhere

Page 5: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

Closing the Loop for Account Management

Request

ProvisionControl

Remediate

5

PLAN

DOCHECK

ACT

Page 6: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

Control?

6

Page 7: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

Our goal: assess & mitigate the User risks

7

Who they are

What theycan do / what

they have doneWhat they have

been allowed to do

Page 8: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

Identity Ledger: Agnostic Data Model

8

Page 9: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

Architecture

Information System

Cloud

Company Policies,

Regulations…

Reports + Insight:• What are my risks?• What needs to be fixed?• Am I compliant?

Page 10: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

Integration with OpenIDM

10

IT Resources

Manual operationsAutomated provisioning

Accounts and fine-grained access rights information

Identities and accessrights assignments

• Access rights reconciliation• Theoretical rights control• Account Recertification process• Remediation process• Controls & Insight

Automated / manualremediation actions

HR and organization-relatedinformationAccess logs

Page 11: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information – All Rights Reserved.

How it works

Brainwave Architecture

Page 12: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

iGRC analytics client

Brainwave Architecture

12

RDBMS

iGRC analytics server

Equinox OSGI batch runtime

XML

Conf

igur

atio

n ex

port

……………………

Consultant

J2EE Web ContainerOSGI Equinox

iGRC Portal

Eclipse RAP

• Page rendering• Data Access (ODA)• Birt Reporting engine• Activiti Workflow engine

iGRC Web Application

End User

HTT

P /

HTM

L /

Ajax

Page 13: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

Business oriented web application

Page 14: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

Business oriented web application

Page 15: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information – All Rights Reserved.

Page 16: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information – All Rights Reserved.

Page 17: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information – All Rights Reserved.

Page 18: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information – All Rights Reserved.

Page 19: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information – All Rights Reserved.

Page 20: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

Page 21: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

Page 22: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information – All Rights Reserved.

Other ways to leverageBrainwave

Page 23: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

« Pull » approach: REST services

Query the Brainwave datawarehouse and instantly publish REST services

23

Page 24: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

« Push » approach: Emailing campaign

Trigger emails messages / reports based on control results, review results…

24

Page 25: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information

OpenIDM Frontend?

25

Page 26: Closed Loop Compliance: Achieving closed loop compliance with Brainwave integration with ForgeRock Open IDM

Brainwave Proprietary and Confidential Information – All Rights Reserved.

Thank you!

Cyril Gollain, + 33 6 13 78 52 04, [email protected]

26