Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint...

23
Identity-aware Infrastructure Identity at the Center of Security, Compliance & IT Operations Darran Rolls, CTO & CISO

Transcript of Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint...

Page 1: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Identity-aware InfrastructureIdentity at the Center of Security, Compliance & IT Operations

Darran Rolls, CTO & CISO

Page 2: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

SailPoint at a Glance

World’s largest, dedicated IAM vendor• Based in Austin Texas, USA• Operations in 15 countries• 300 Partners worldwide• Customers in every vertical

The leader in identity governance

Page 3: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA
Page 4: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Identity Governance market leadership

GartnerMagic Quadrant for IGA, 2017

ForresterWave for IMG, 2016

KuppingerCole Report, Leadership Compass, 2017

Page 5: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Evolution #1Delegate

Administration

Generation #2Automated

Provisioning

20041998 2018

Generation #3Identity

Governance

20 Years of Identity Management Evolution

Page 6: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Evolution #1Delegate

Administration

Generation #2Automated

Provisioning

20041998 2018

Generation #3Identity

Governance

20 Years of Identity Management Evolution

ü Business user focused

ü Full lifecycle

ü Embedded controls

ü Securing & managing

all access

Page 7: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Copyright © SailPoint Technologies, Inc. 2017. All rights reserved.

Securing & Managing Access

Page 8: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Securing & Managing Access

People Access Data

Unstructured

Structured

ApplicationPeople

Applications

Devices

Authentication

Bio-Metric

WebBased

SAMLBased

PasswordBased

PKIBased

OAuthBased

Authorization

ApplicationSpecific

AttributeBased

SystemDefined

VaultedCreds

GroupBased

RoleBased

Page 9: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Identity & Access Governance

People Access Data

Bio-Metric

WebBased

SAMLBased

PasswordBased

PKIBased

OAuthBased

ApplicationSpecific

AttributeBased

SystemDefined

VaultedCreds

GroupBased

RoleBased

Who has Access to What and Why…

Page 10: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Identity & Access Governance

People Access Data

Bio-Metric

WebBased

SAMLBased

PasswordBased

PKIBased

OAuthBased

ApplicationSpecific

AttributeBased

SystemDefined

VaultedCreds

GroupBased

RoleBased

Automation, Delegation and Self-service

Page 11: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Identity & Access Governance

People Access Data

Bio-Metric

WebBased

SAMLBased

PasswordBased

PKIBased

OAuthBased

ApplicationSpecific

AttributeBased

SystemDefined

VaultedCreds

GroupBased

RoleBased

Visibility & Control = Identity Governance

Page 12: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Identity

Governance

Program Objectives

Page 13: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

NIST 800-53 Control Groups

Page 14: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Identity Governance Program Objectives

Enabling efficient & accurate user access

Protecting access to applications and data

Staying compliant amidst mounting regulations

Cloud and on-premise applications and data…

IncreasedProductivity

Lower Security Risk

SustainableCompliance

Page 15: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Objective #1: Increased Productivity

• Joiner MOVER & leaver controls…

• Fine-grained access control…

• Delegated administration…

• End-user self-service…

IncreasedProductivity

Page 16: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Objective #2: Lower Security Risk

• Understanding access risk…

• Password management…

• File & access governance…

• De-provisioning & security response…

Lower Security Risk

Page 17: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Objective #3: Sustainable Compliance

• Access reviews…

• Detective and preventive policy controls…

• Data ownership & responsibility…

• Reporting & analytics…

SustainableCompliance

Page 18: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Identity-aware Infrastructure

Page 19: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Copyright © SailPoint Technologies, Inc. 2017. All rights reserved.

Page 20: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

Understanding Key Relationships

DataEntitlementAccountIdentity

Darran Rolls

[email protected]

Group=Accounting

\\Shares\HR(read)

\\Shares\Corp(read write)

Group=Users \\Shares\doc3(read)

RACF1232123

SYSDBA

Data Profile1

Data Profile2

SYSOPER Data Profile3

Identity Account Entitlement Data

Page 21: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

SIEM & DLP

Applications & Infrastructure

Mobile DeviceManagement

Identity-enabled Infrastructure

Integrated ResponsiveEcosystem

DataGovernance

User Behavior Analysis

PrivilegedUser Mgmt.

GRC

IT ServiceManagement

Shared Context& Actions

Security Infrastructure Identity Governance & AdministrationOperations Infrastructure

Page 22: Identity-aware Infrastructurepublishingext.dir.texas.gov/portal/internal/resources... · SailPoint at a Glance World’s largest, dedicated IAM vendor • Based in Austin Texas, USA

EndpointManagement

Access Management

Privileged Account Mgmt.

SIEM

Systems Management

Service Management

GRC

Enterprise Mobility Management

User Behavior Analysis

SailPoint Open Identity Platform