Forgot password?
|
|
|
|
We were unable to sign you in.
Please verify your user name and password and try again. If you do not have a TEC account, register now.


If you receive errors when attempting to view this white paper, please install the latest version of Adobe Reader.
Consul

"IBM announced a definitive agreement to acquire Consul on December 5, 2006. IBM's market-leading identity and access management solutions enable organisations to provide authorised users access to systems, applications and data - protecting these assets against unauthorised access, reducing administration costs, enhancing the user experience, supporting compliance, and helping improve trust in human identity."
Source : IBM

Resources Related to Identity and Access Management:

The Age of Audit: Identity and Access Management in Provision and Compliance

Identity and Access Management is also known as : Information System, Electronic Identity Management, Identity Management Systems Solutions, Identity Management Solution, Identity Management Systems Interoperability, Identity Mgmt Systems, Identity Management Tools, Identity Driven manager, Identity Management Provisioning, Identity Management System Requirements, Identity Management Process, IAM analysis, IAM application, IAM architecture.

Table of Contents


  1. Introduction
  2. IAM Overview
  3. Seasons of Identity Management
  4. Audit is required for any successful IAM implementation
  5. Life after the initial implementation
  6. How Consul InSight Helps IAM
    1. InSight speaks the language of Identity and Access Management
    2. InSight provides users and data set groupings based on actual access patterns
    3. InSight facilitates the creation of access policy rules based on your security event data
    4. InSight provides continuous event and compliance auditing with detailed reporting
  7. How Audit Enables Compliance
  8. Conclusion
  9. References and further sources of information

1. Introduction

In todays security management landscape, enterprises recognize the value of implementing identity and access management (IAM) solutions to administer user authentication and authorization. Most common are solutions that allow for enterprise Provisioning of users. Such solutions help organizations lower user administration costs, improve the security and protection of key corporate applications and information assets, and ensure compliance with the policies of the enterprise and external governing bodies.

With the sudden increase in regulations and standards, there is now recognition that Audit - often regarded as the "4thA" after Administration, Authentication and Authorization - is a particularly vital component of the IAM process. Audit should not simply be the ability to report on the identity database embedded in a traditional Provisioning solution, but rather the ability to independently collect and monitor how users are accessing information.

This white paper will describe the IAM process and how Audit plays a crucial role before, during or after implementation of an access provisioning solution. Using examples from Consul InSight Security Manager, it will show how the right Audit solution enables large organizations to:

  • Baseline users and IT assets
  • Benchmark access behavior
  • Establish access policy
  • Report policy exceptions
  • Monitor security breaches
  • Archive all log files
  • Audit events, users and data

With InSight, Audit becomes a key enabler for Provisioning and Compliance initiatives.

2. IAM Overview

Identity management is the process of managing information for a user's interaction with an organization. Key identity management functions include adding, updating and deleting user information and permissions for a company's systems, applications and data stores. In general, identity management is thought of as encompassing four A's (source: Gartner, Forrester)

  • Authentication: Enterprises must ensure that users are properly identified and that these identities are validated to IT resources.
  • Authorization: Enterprises must know that users can access only what their job function allows them to access within the enterprise.
  • Administration: Enterprises must have a consolidated, enterprise- wide view and a way to manage user access.
  • Audit: Enterprises must ensure that the activities associated with user access (administration and real-time enforcement) are logged for day-to- day monitoring, regulatory and investigative purposes.

While there are many reasons why enterprises implement a comprehensive IAM solution, there are three key benefits that stand above the rest.

First, enterprises are able to lower user administration and provisioning costs with an IAM solution. They are able to achieve this by automating manual or semi-manual tasks involved in changing access rights, provisioning end users, and eliminating duplicated tasks and reducing the risk of error. This approach will enable the IT staff to focus on core functions, easily scaling administration to the number of users.

Second, enterprises are able to improve the security and protection of key corporate applications and information assets. IAM provides a centralized, authoritative source of user identities, privileges and access information. This offers the enterprise real-time permission and policy enforcement, continuous real-time auditing to detect and remove security risks, and the ability to easily and automatically remove terminated users and revoke their access rights.

Lastly, IAM allows enterprises to accelerate compliance against their own internal security policies and external regulations such as Sarbanes-Oxley (SOX), Health Insurance Portability and Accountability Act (HIPAA), Gramm- Leach-Bliley Act (GLBA) or Basel II. Companies today face a landslide of regulations that require everything from strict data controls to extensive record keeping and auditing to demonstrate compliance. Implementing measurable access security policies and intelligently archiving and auditing vast amounts of security event information to demonstrate compliance are no longer optional.

3. Seasons of Identity Management

While the benefits of IAM are clear and potentially substantial, they do not come without challenges. In fact, the specific challenges will depend on your IAM "season."

Before you decide to adopt IAM, you are in IAM "winter." You have little visibility into who is doing what. Access rights management is balkanized, potentially leaving gaps and inconsistencies. You are never completely certain if the right people have access to the right data. Worse, you are not certain if the wrong people have access to critical data. Additionally, you have several challenges selling management on the investment. Cost savings may be hard to quantify since the benefits may be reaped across many departments. IAM is a long-term investment with a break-even point more than a year out. Many companies are averse to taking on long payback projects. The benefits of improved security and administration processes may be undervalued, making costs difficult to justify. Probably the biggest hurdle is the belief that the current approach to system and user administration is "good enough."

Once you make the decision to implement IAM and start the implementation, you are in IAM "spring." You look forward to reaping all the benefits of IAM, and you have all of the hope, optimism and enthusiasm of springtime.

However, enterprises are then hit with the complexity of the installation - IAM "summer." You may find IAM technologies difficult and expensive to integrate within your existing infrastructure. You realize that you need to understand your current workflows and data architecture. When you realize that you do not have a way to easily gather this information, you are overwhelmed. You start to feel the "summer heat" and ask, "Where do I start?"

"Autumn" follows when your IAM solution is in place and you are managing your operational IAM environment. The summer heat is gone and you are reaping the initial benefits. You begin to consider that IAM can help you improve your security and information protection mechanisms and accelerate compliance with internal policies and external regulations. You start to ask, "Are the right controls in place?" and "Are my controls effective?"

So, which season is the biggest challenge? Like many things in life, the biggest challenge is taking the first step. For example, many of you have been through a decision to change some aspect of your daily routines. You determine that you want to start going to the gym more often, start to run regularly or start to read more. Deciding to go to the gym more regularly is easy. The hard part is deciding which gym, what types of exercise, how often and what time of day. All of these decisions, particularly if you have the daunting task of gathering data to make the decision, can paralyze you to the point of inactivity. This is the same for IAM. The hardest part is getting started. So, how should you get started?

4. Audit is required for any successful IAM implementation

In many instances, the biggest obstacle to your initial deployment is the lack of data. You must establish an information access baseline. You need to understand your current workflows and your data architecture - Who should access which data? Who is actually touching the data? When, where and how are they accessing the data? This entails identifying your users and IT assets and establishing a baseline for access behavior across your enterprise. This baseline is the first step towards understanding roles, groups and profiles in your environment, providing you with the information you need to establish your initial access policies, including roles, groups and authorities.

Much of this information is already available in audit logs across your enterprise. The challenge is collecting and storing the information, making sense of it, and then making intelligent decisions based on it. How do you do this?

Collect :
You need secure and scalable log collection, to consolidate, and archive for a wide variety of platforms - mainframe to appliance, operating systems, security devices, applications, databases.

Translate :
You need a strong, business oriented, technology- independent normalization method that translates cryptic logs into the same language you speak when considering roles, groups and profiles for an IAM implementation - Who, touched What, When, Where, Where to, Where from, and on What.

Analyze :
You need to leverage the collected log files to help to determine logical groups, roles and profiles based on actual access patterns. Grouping templates provides a simple and effective way to organize people, assets and data into common groups.

Baseline :
You then need to establish your baseline. That is, define access policy rules based on security event data and proposed groupings.

5. Life after the initial implementation

Once your IAM system is in place, the same audit tools and audit process moves you into the next level of identity management implementation - leveraging roles and profiles to improve overall security and accelerate regulatory compliance. What are some of the ways an audit solution can improve security and accelerate compliance?

Improve access policies :
Audit events, users and data and filter collected information against security policy. Policy breaches might indicate where too much access is provided; logon failures might indicate where more access is needed. You can adjust your profiles accordingly.

Improve forensic investigations :
Perform automated, ongoing monitoring of breaches to policy, with the ability to conduct detailed forensic audits.

Facilitate actionable audit :
Act upon severe breaches to policy by disabling the account user ID or enterprise user definition of the person committing the policy breach.

Provide customized reporting for all levels of the organization :
Provide reporting tailored to specific regulations and the needs of security operations and auditors. You also need reports that facilitate easy event auditing and demonstrate policy compliance.

6. How Consul InSight Helps IAM

6.1. InSight speaks the language of Identity and Access Management

Many security vendors speak about "event anomaly," "IP packets," "signatures" and other technical terms. InSight speaks about security events more clearly in a "language" we call the W7 language. All logs are normalized to easily inform you of Who, touched What, When, Where, Where to, Where from, and on What. This is the same language you speak when considering roles, groups and profiles for an IAM implementation. InSight is able to turn cryptic logs into W7 information.

6.2. InSight provides users and data set groupings based on actual access patterns

InSight's user and data classification templates provide standard and regulatory relevant groups for each of the 7 W's: e.g., Who groups, What groups, etc. These templates provide a starting point that can be customized to any business environment and enable you to group your organizational assets into business relevant categories from which to report. These groupings can be consistent with the groups and profiles you use in your IAM efforts. With InSight, the security manager is now able to establish access roles and groups based on the enterprise's actual access patterns.

6.3. InSight facilitates the creation of access policy rules based on your security event data

Once the data is normalized and placed in business relevant groups based on actual access patterns, InSight is able to help create an access policy. InSight's policy templates provide default access policies relevant to either an industry standard, such as ISO 17799, or a regulation such as SOX or HIPAA. By reviewing your actual security event data against InSight'‘s policy engine, you are able to create a set of simple rules that are implemented in an operational W7 access policy. In other words, with InSight you go from cryptic logs, to event auditing and monitoring with logical groups, to an access policy that is a jump-start for your IAM implementation.

6.4. InSight provides continuous event and compliance auditing with detailed reporting

Finally, having used the data from the log files to establish logical access groups and policies, you can use InSight to monitor your entire network. Below you see InSights compliance dashboard. The compliance dashboard provides an easy-to-understand, color-coded matrix highlighting levels of compliance based on user behavior and data access. The dashboard also contains a variance chart that measures policy violations versus goals over time.

When your analysis and review indicate that you need more detail, InSight provides the ability to drill down from the compliance dashboard to detailed reports on who violated your access policy and how. There are more than one hundred different reports available to enable easy event auditing and policy compliance. These reports can serve as a feedback mechanism on your IAM implementation: breaches might indicate where too much access is provided; logon failures might indicate where more access is needed. You can adjust your profiles accordingly.

7. How Audit Enables Compliance

Audit should enable compliance by monitoring who is touching which files and compare that against set policy. For HIPAA, this means monitoring who touches patient data; for Sarbanes-Oxley, who touches financial information; for Gramm-Bleach Bliley and the CA-SB 1386, who touches customer information. For each and every regulation InSight provides the access audit perspective required by law. Most importantly, InSight does this by comparing Who should be allowed to touch What (Policy) with Who does What (logs):

A comprehensive Audit solution like InSight enables compliance by allowing organizations to:

Implement procedures:

  • Implement security policy
  • Employ ISO17799 for compliance
  • Prepare for stringent security audits

Measure compliance:

  • View compliance dashboard
  • Print best-practice reports
  • Track policy exceptions over time

Understand who touches what:

  • Monitor user behavior
  • Audit file access
  • Track compliance breaches

Manage security events:

  • Correlate disparate security devices
  • Manage diverse platform events
  • Consolidate and archive native logs

8. Conclusion

IAM's benefits are clear but with a significant set of challenges. The biggest challenge is getting started. Auditing and creating an information access baseline provides the most effective way to understand users, assets and user behavior toward those assets. Then you can proceed from cryptic logs, to event auditing and monitoring with logical groups, to an information access policy that is a jump-start for your IAM implementation. With this approach, you will be able to document access behavior based on actual security event data, group users and data based on access patterns, and define access policy rules based on security event data and proposed groupings. By improving implementation time, you can improve your overall security infrastructure, accelerate regulatory compliance or internal audit efforts and achieve ROI faster.

9. References and further sources of information

Gartner - "Identity and Access Management Defined", 4 November 2003
URL: www.gartner.com

PricewaterhouseCoopers - "Identity Management - The business context of
security: a white paper."
URL: www.pwc.com/extweb/service.nsf/docid/83ACF0A4CAB036C685256C6A0055D964

Forrester -- The Natural Order Of Security Yields The Greatest Benefits,
July 9, 2004, by Steve Hunt
URL: www.forrester.com

Consul risk management, Inc
Suite 250
2121 Cooperative Way
Herndon, VA 20171
USA
Tel: +31 15 251 3333
Fax: +31 15 262 8070

Consul risk management
Marshalllaan 2
2625 GZ Delft
The Netherlands
Tel: +31 15 251 3333
Fax: +31 15 262 8070

contactsales@consul.com
www.consul.com

Searches related to The Age of Audit: Identity and Access Management in Provision and Compliance:
Access Identity Management Software | Access Management | Access Management Solution | Access Management Solutions | Apply IDM | Apply IAM | Apply IAM Implementation | Apply Identity and Access Management | Apply Identity Management | Apply Identity Management Systems | Apply Identity Management Tool | Applying IDM | Applying IAM | Applying IAM Implementation | Applying Identity and Access Management | Applying Identity Management | Applying Identity Management Systems | Applying Identity Management Tool | Assessment Implementation | Audit Solution | Audit Solutions | Choose IDM | Choose IAM | Choose IAM Implementation | Choose Identity and Access Management | Choose Identity Management | Choose Identity Management Systems | Choose Identity Management Tool | Choosing IDM | Choosing IAM | Choosing IAM Implementation | Choosing Identity and Access Management | Choosing Identity Management | Choosing Identity Management Systems | Choosing Identity Management Tool | Compliance | Compliance | Compliance Breach | Compliance Breaches | Compliance Dashboard | Compliance Dashboards | Compliance Implementation | Compliance Solution | Compliance Solutions | Create IDM | Create IAM | Create IAM Implementation | Create Identity and Access Management | Create Identity Management | Create Identity Management Systems | Create Identity Management Tool | Creating IDM | Creating IAM | Creating IAM Implementation | Creating Identity and Access Management | Creating Identity Management | Creating Identity Management Systems | Creating Identity Management Tool | Data Architecture | Data Architectures | Definition of Sarbanes Oxley | Delegated Administration | Deploy IDM | Deploy IAM | Deploy IAM Implementation | Deploy Identity and Access Management | Deploy Identity Management | Deploy Identity Management Systems | Deploy Identity Management Tool | Deploying IDM | Deploying IAM | Deploying IAM Implementation | Deploying Identity and Access Management | Deploying Identity Management | Deploying Identity Management Systems | Deploying Identity Management Tool | GLBA | Gramm Leach-Bliley ACT | Gramm Leach-Bliley ACT GLBA | Health Insurance Portability and Accountability ACT | Health Insurance Portability and Accountability ACT HIPAA | HIPAA | IAM | IAM Analysis | IAM Application | IAM Architecture | IAM Benefit | IAM Benefits | IAM Business | IAM Deployment | IAM Development | IAM Format | IAM Framework | IAM Gateway | IAM Implementation | IAM Implementation Analysis | IAM Implementation Framework | IAM Implementation Management | IAM Implementation Operations | IAM Implementation Planning | IAM Implementation Process | IAM Implementation Processes | IAM Implementation Solution | IAM Implementation Solutions | IAM Implementation Strategies | IAM Implementation Strategy | IAM Implementations | IAM Information | IAM Innovation | IAM Innovation Networks | IAM Integrate | IAM Integration | IAM Management | IAM Management Process | IAM Management System | IAM Message | IAM Messages | IAM Needs | IAM Network | IAM Networks | IAM Operations | IAM Overview | IAM Overviews | IAM Planning | IAM Policy | IAM Process | IAM Processes | IAM Requirements | IAM Risk | IAM Security | IAM Services | IAM Software | IAM Solution | IAM Solutions | IAM Standard | IAM Strategies | IAM Strategy | IAM Systems | IAM Training | Identity Access Management | Identity Access Manager | Identity and Access Management | Identity and Access Management IAM | Identity and Access Management IAM Solution | Identity and Access Management IAM Solutions | Identity and Access Management Architecture | Identity and Access Management Definition | Identity and Access Management IAM | Identity and Access Management Policy | Identity and Access Management Series | Identity and Access Management Services | Identity and Access Management Software | Identity and Access Management Solution | Identity and Access Management Solutions | Identity and Access Management Summit | Identity and Access Management System | Identity and Access Management Technologies | Identity and Access Management Tools | Identity and Access Management Training | Identity and Access Manager | Identity Driven Manager | Identity Driven Networking | Identity Lifecycle Manager | Identity Management | Identity Management Access Control | Identity Management Analysis | Identity Management Applications | Identity Management Architecture | Identity Management Authentication | Identity Management Business | Identity Management Comparison | Identity Management Consulting | Identity Management Definition | Identity Management Deployment | Identity Management Development | Identity Management Directory | Identity Management Features | Identity Management Framework | Identity Management Functions | Identity Management Implementation | Identity Management Industry | Identity Management Innovation | Identity Management Innovation Networks | Identity Management Integrate | Identity Management Integration | Identity Management Management | Identity Management Process | Identity Management Management System | Identity Management Manager | Identity Management Market | Identity Management Needs | Identity Management Networks | Identity Management Operations | Identity Management Overview | Identity Management Planning | Identity Management Policy | Identity Management Problem | Identity Management Process | Identity Management Processes | Identity Management Product | Identity Management Products | Identity Management Program | Identity Management Provisioning | Identity Management Requirement | Identity Management Requirements | Identity Management Server | Identity Management Service | Identity Management Services | Identity Management Software | Identity Management Solution | Identity Management Solutions | Identity Management Standard | Identity Management Strategies | Identity Management Strategy | Identity Management System | Identity Management System Requirement | Identity Management System Requirements | Identity Management Systems | Identity Management Systems | Identity Management Systems Analysis | Identity Management Systems Architecture | Identity Management Systems Deployment | Identity Management Systems Development | Identity Management Systems Framework | Identity Management Systems Innovation | Identity Management Systems Innovation Networks | Identity Management Systems Integration | Identity Management Systems Management | Identity Management Systems Management Process | Identity Management Systems Management System | Identity Management Systems Needs | Identity Management Systems Networks | Identity Management Systems Operations | Identity Management Systems Planning | Identity Management Systems Process | Identity Management Systems Processes | Identity Management Systems Software | Identity Management Systems Solution | Identity Management Systems Solutions | Identity Management Systems Strategies | Identity Management Systems Strategy | Identity Management Technologies | Identity Management Technology | Identity Management Tool | Identity Management Tool Analysis | Identity Management Tool Architecture | Identity Management Tool Deployment | Identity Management Tool Development | Identity Management Tool Framework | Identity Management Tool Innovation Networks | Identity Management Tool Needs | Identity Management Tool Operations | Identity Management Tool Planning | Identity Management Tool Process | Identity Management Tool Processes | Identity Management Tool Software | Identity Management Tool Solution | Identity Management Tool Solutions | Identity Management Tool Strategies | Identity Management Tool Strategy | Identity Management Tool Systems | Identity Management Tools | Identity Manager | Identity Metasystem | Identity MGMT Systems | Identity Paradigm | Identity Selector | IDM | IM Implementation | Implement IDM | Implement IAM | Implement IAM Implementation | Implement Identity and Access Management | Implement Identity Management | Implement Identity Management Systems | Implement Identity Management Tool | Implement Security Policy | Implementation Analysis | Implementation Management | Implementation Process | Implementing IDM | Implementing IAM | Implementing IAM Implementation | Implementing Identity and Access Management | Implementing Identity Management | Implementing Identity Management Systems | Implementing Identity Management Tool | Implementing Security Policy | IMS Implementation | Insight | Integrate IDM | Integrate IAM | Integrate IAM Implementation | Integrate Identity and Access Management | Integrate Identity Management | Integrate Identity Management Systems | Integrate Identity Management Tool | Integrating IDM | Integrating IAM | Integrating IAM Implementation | Integrating Identity and Access Management | Integrating Identity Management | Integrating Identity Management Systems | Integrating Identity Management Tool | IT Asset | IT Assets | IT Compliance | Message Implementation | Monitor IDM | Monitor IAM | Monitor IAM Implementation | Monitor Identity and Access Management | Monitor Identity Management | Monitor Identity Management Systems | Monitor Identity Management Tool | Monitoring IDM | Monitoring IAM | Monitoring IAM Implementation | Monitoring Identity and Access Management | Monitoring Identity Management | Monitoring Identity Management Systems | Monitoring Identity Management Tool | Oxley Compliance | Password Synchronization | Policy Compliance | Provisioning/De-provisioning of Accounts | Sabanes Oxley | Sarbaines Oxley | Sarbanes | Sarbanes Compliance | Sarbanes Oaxley | Sarbanes Oxley | Sarbanes Oxley Articles | Sarbanes Oxley Auditing | Sarbanes Oxley Auditor | Sarbanes Oxley Benefits | Sarbanes Oxley Checklist | Sarbanes Oxley Compliance Requirements | Sarbanes Oxley Compliance Software | Sarbanes Oxley Compliance Solution | Sarbanes Oxley Control | Sarbanes Oxley Courses | Sarbanes Oxley Effects | Sarbanes Oxley Impact | Sarbanes Oxley Implementation | Sarbanes Oxley Information | Sarbanes Oxley Legislation | Sarbanes Oxley Overview | Sarbanes Oxley Policy | Sarbanes Oxley Provisions | Sarbanes Oxley Regulations | Sarbanes Oxley Reports | Sarbanes Oxley Requirements | Sarbanes Oxley Rules | Sarbanes Oxley Sections | Sarbanes Oxley Services | Sarbanes Oxley Software | Sarbanes Oxley Summary | Sarbanes Oxley Technology | Sarbanes Requirements | Sarbanes Oxley | Sarbanes-Oxley SOX | Sarbanes-Oxley ACT | Sarbanes-Oxley Audit | Sarbanes-Oxley Compliance | Sarbanes-Oxley Compliant | Sarbanes-Oxley Report | Security Audit | Security Audits | Security Compliance | Security Event Management | Security Information Management | Security Policy | Self-service Password Reset | Service Paradigm | SOX | SOX Sarbanes Oxley | Standards Implementation | Support IDM | Support IAM | Support IAM Implementation | Support Identity and Access Management | Support Identity Management | Support Identity Management Systems | Support Identity Management Tool | Supporting IDM | Supporting IAM | Supporting IAM Implementation | Supporting Identity and Access Management | Supporting Identity Management | Supporting Identity Management Systems | Supporting Identity Management Tool | Systems Implementation | Track Compliance Breach | Track Compliance Breaches | User Provisioning | Vulnerability Assessment | Vulnerability Management | What is Identity and Access Management | What is Identity Management | What is Sarbanes Oxley Compliance | Workflow Automation |

©2013 Technology Evaluation Centers Inc. All rights reserved. Search powered by Google