Latest news
So now we have even more confusion because the governance here is of security entitlements, not of runtime access enforcement. Perhaps this new product category would be more accurately called "Entitlement Governance."
If we actually stop to listen to what organizations want, it is efficient and secure administration AND governance. They want to manage security entitlements first and foremost, and identities only insofar as this is pre-requisite to grant entitlements to users.
Which brings me to the starting point: "Identity and Access Management" is misleading, as is "Access Governance." Moreover, the security controls implicit in "governance" must be enforced at every phase of every administration process. The notion of two product categories layered on top of each other, one for governance and another for administration, is neither architecturally sound nor commercially attractive.
I propose a simpler and more accurate label for our market: "Entitlement Administration and Governance," or EAG for short.
And what does EAG mean?
- Focus on granting and revoking entitlements.
- Automate the management of identities, since users must be assigned digital identities before they can be granted entitlements.
- Include a rich set of connectors to pull information about login IDs and security entitlements from existing systems and directories, and to write updates back to those systems and applications as a consequence of approved change requests.
- Automation to setup and tear down identities and entitlements based on an HR data feed
- A request portal so that users can request changes on their own behalf and for others, including recipients, who do not appear in an HR data feed.
- An authorization workflow, to get business users to approve or reject proposed changes.
- Access certification, to invite stake-holders to periodically review and correct security entitlements.
- Policy engines, to prevent violations to segregation of duties and other rules.
- Reports and dashboards, so business users can monitor both enterprise-wide security configuration and the change management process.
I think this is what the market really wants: an integrated solution to manage both identities and entitlements throughout the user lifecycle, with integrated governance (i.e., policy and workflow controls throughout). So, let's stop talking about IAM and focus instead on EAG.
Spotlight

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.




