Path to effective & achievable Identity Governance...Identity Governance is about involving the...

25
Path to effective & achievable Identity Governance Matthew Ulery VP of Product Management

Transcript of Path to effective & achievable Identity Governance...Identity Governance is about involving the...

Page 1: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Path to effective & achievable Identity GovernanceMatthew Ulery

VP of Product Management

Page 2: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Identities have evolved, beyond heartbeats…

2

Internal Employees

External Partners/Contractors

Applications/Services

Devices Servers, Mobile &

BYOD

Things (IoT) Customers

Page 3: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

IDENTITY

Mobile

EmployeesUsers, Devices,

Things, Services,Relationships, Roles…

IDENTITY

CustomersUsers, Devices,

Things, Services,Relationship, Experience

IDENTITY

IDENTITY

IDENTITY

IDENTITY

IDENTITY

IDENTITY

IDENTITY

Growing complexity and velocity

PartnersTech Support, Financial,Delivery, Development,

Services…. etc.

IDENTITY

IDENTITY

IDENTITY

IDENTITY

IDENTITYIDENTITY

IDENTITY

IDENTITY

Internal

Employees, Data

Services, Applications

Page 4: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Employees

Identity PoweredSecurity

CustomersB2C

PartnersB2B

IDENTITY

IDENTITYIDENTITY

An Identity-Centric Approach

Page 5: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

OrganizationalScale

Organizational Complexity

Productivity, Operational Efficiency

IAM 1.0Risk & Compliance

IAM 2.0

Evolution of Information Security

To Drive Perimeter Controls To Drive Identity Insight To Leverage Intelligence

Transforming Approach

Identity-centric Security

IAM 3.0

Page 6: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Avoid compliance audit finding?

Business enablement?

Risk reduction?

Breach avoidance?

Losing track of the goal… what is yours?

Enable business while managing risk, with compliance

as a by-product

Page 7: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Where this began…

Automated Provisioning

“ … let’s automate all our manual processes and

SoD policies…”

“ …cost per application is high, is there a simpler

approach…”

Page 8: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Automated existing manual process – where they the right processes?

Balance of focus on business enablement over risk management

High cost of maintenance due to over customization

8

Automated Provisioning Challenges

Too often started with technology without business & risk assessment

Page 9: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Where we are…

Automated Provisioning

Access Governance

“ … why automate provisioning, why not address with requests

and certification…”

“ …but certification is not addressing risk & I still have

my manual processes…”

Page 10: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Identity Governance is about involving the business in your access and entitlement decisions – an expansion, not a replacement for Identity Management

Page 11: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Ineffective, “rubber-stamp” certifications

Greater workload for business manager

Cost of manual processes remain

Risk blind-spots between certification cycles

11

Access Governance Centric Challenges

Simpler, but less capable is not effective

Page 12: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

“I need insight into who really needs their access, and who has it but isn’t even using it.”

Page 13: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

13

Decision Support“I need assistance when making decisions. Is this a regular request? Do other people in this role have similar access?”

Page 14: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

JAN FEB MAR APR MAY JUNE JULY AUG SEP OCT NOV DEC JAN FEB MAR APR

Access certification completed!

Bob’s access added

Risk blind-spots from point in time certification

14

BLIND UNTIL NEXT REVIEW

Bob’s access removed

Access certification completed!

Bob’s access added

BLIND UNTIL NEXT REVIEW

Bob’s access removedBob’s access removed

Access certification completed!

Bob’s access added

BLIND UNTIL NEXT REVIEW

Bob’s access removed

Page 15: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

“How can we close these blind-spots while still lowering costs?”

Page 16: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

16

When needs evolve, you must adapt…

Page 17: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Beyond point in time governance

Automated Provisioning

Access Governance

Adaptive Access Governance

Page 18: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

18

Achieving Adaptive Governance

1

2

Change Driven: Reduce the cost and annoyance of certifications, with micro-certifications based on changes as they occur

3

Outlier Focused: Lower certification workload by focusing on high risk and special cases – feedback lessons learned

Pragmatic Automation: Right level of automation or orchestration based on risk and business need

Page 19: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

JAN FEB MAR APR MAY JUNE JULY AUG SEP OCT NOV DEC JAN FEB MAR APR2 0 1 7

Automatically approved based on role definition

Hired with initial entitlements

Entitlement request

2 0 1 8

End of year certification supported by micro-certifications throughout the year

Adaptive Governance

20

Changed Dept

New Roles assigned – mgr approval

Transition window begins with SoDchecks

Transition window ends triggering micro-certification

Employee attempts to access previous entitlements: micro-certification?

Employee granted entitlement outside process: micro-certification!

Page 20: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Entitlements granted outside approved roles

High cost and/or high risk entitlements

Automate decisions based on previous activity and policy

Detect and respond to anomalous activity

Focus on outliers, exceptions 2

Page 21: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Automation vs OrchestrationThe right balance

AutomationOrchestration

-VS-

3

Page 22: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Adaptive Governance A Living Practice

Response Control

Policy

Monitor

Page 23: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Holistic view of identity – beyond the carbon based life form.

Go beyond point in time to real-time.

Demonstrate value to the business with intelligence driven decision support.

Flexibility to adapt to how your organization works.

Actively enhance risk management while improving efficiency.

Define success as more than just an audit pass - that is the by-product.

24

Take Aways -

Page 24: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Micro Focus Confidential

Page 25: Path to effective & achievable Identity Governance...Identity Governance is about involving the business in your access and entitlement decisions –an expansion, not a replacement

Micro Focus Confidential