identity & access management?

Overview

To properly manage your corporate identities, keep everything centralised

Identity and access management is one of the most important areas to get a firm grip on the security of the IT infrastructure and application base.?

When multiple cloud service providers are used, the challenge arises to keep user account management and access control manageable. Most organisations use a directory service, such as Microsoft (Azure) Active Directory, which may or may not be linked to a human resources system. Centralised management of user identities, service identities and role-based access control is important to implement and control policies in this area. The use of decentralised, decoupled identity and access management services makes management and control extremely difficult, for example regarding revoking usage rights or suspending login rights.?

We also want to be able to use modern security techniques, including multi-factor authentication (MFA), risk-based access control and temporary rights elevation systems. We want to be able to integrate authentication and authorisation with external solutions and to let partners and third party’s authentication systems integrate with our systems. And finally, we want to be able to automate user account provisioning and deprovisioning, automate role-based access rights and permissions, and automate the integration of identity and access management systems.?

To do so, user and role management should be centralised. Single sign on to any resource should be mandatory. This can be realised using centralised directory services and IAM systems and, if applicable, third-party identity brokers. 

Activities checklist

Initial:

  • Setting clear IAM security standards and guidelines?
  • Defining a strategy to work with privileged accounts?
  • Automating security controls, such as MFA ?
  • Creating integration services and guidelines for external systems?
  • Automating identity provisioning/deprovisioning?
  • Automating RBAC and permissions?
  • Defining and implementing a process to validate that “least privileged” principle is applied?
  • Defining and implementing a process describing the tasks and responsibilities with regards to identity and access management

Recurring:

  • Reviewing automatically generated messages about detected anomalies?
  • Processing access change requests ?
  • Automating integration with third party systems?
  • Automating SaaS user access control

RASCI

cloud consultanttransformation consultant
cloud architectresponsiblecloud partnersconsulting
cloud security specialistresponsibleDevOps teaminformed
cloud developerinformedbusiness stakeholderresponsible
cloud engineerinformedarchitectureaccountable
cloud analystresponsiblesecurityresponsible
product owner CCoEfinance
managementprocurement
Scroll to Top