Entitlement management: Access control on steroids
Entitlement management tools bring fine-grained access control to another level
By
Denise Dubie
,
Network World
, 12/03/2007
- Share/Email
- Tweet This
- Print
Faced with looming regulations such as the Health Insurance Portability and Accountability Act and the Sarbanes-Oxley Act,
Craig Shumard, chief information security officer for healthcare provider Cigna, knew he needed better tools for role-based access control.
"In the past many employees would just dole out access rights based on a peer's profile, but it is not efficient nor is it
prudent from a security and regulations standpoint to give employees more access than they need to applications and data," Shumard says. "We only want to dole out the minimum access employees need to do their job effectively and only
for as long as they need to do that job."
When his search began more than five years ago, nobody was offering what he needed. The limitation of his prior role-based
access control tool was that it was "only as good as the day you do it because people are constantly moving, companies are
realigning and functions are changing," he explains. Role-based access control was fundamental to his company's business processes,
but the system he had "was a massive process with a lot of moving pieces that became a struggle to maintain."
Read a related story on how to develop an entitlement management strategy.
Today, Shumard uses software from Aveksa to automate fine-grained authorization that involves 1,800 multi-layered roles and 2,400 sub-roles. The tool makes it possible
for staff to stay on top of doling out, updating and pulling back roles and access rights to employees, he says.
"Fine-grained authorization and entitlement management allows you to externalize security from the applications and helps
drive out complexity and improve policy-based management. It is not a trivial thing," Shumard says.
For example, when a new employee comes on board, Aveksa integrates with Cigna's human resources database to automatically
provision pre-defined roles, but also to de-provision those same users if their jobs change or they leave the company. The
Aveksa workflow tool is used by the security team to pull together role owners, application stewards and managers to keep
roles up to date and systems secure from unauthorized access, he says.
The software runs on a Linux operating system and Oracle database, and is also available as an appliance. Pricing for Aveksa
3 Enterprise Access Governance Suite starts around $140,000 for 1,000 users and 25 applications. But Aveksa features a Web-based
interface that not only IT security staff can use, but which business managers can also tap into to create and review roles.
"What a customer service representative does today can change by tomorrow so we had to expand how we defined roles and automate
the process of keeping them up to date," Shumard says.
Taking on entitlements
Aveksa is one of a number of vendors in a new product category known as entitlement management. The benefits of entitlement
management include improving security, particularly when it comes to protecting data from internal misuse, reducing risk and
achieving compliance.
Partner Content
Blue Stripe Software
www.bluestripe.com/
Improving Application Performance Troubleshooting
Diagnosing why an application is slow is hard, at times taking days or weeks to isolate and resolve. This paper explains the challenges involved using current management tools, provides a 'wish list' for application management and analysis, and explains the need for an application system-wide approach that monitors entire applications, not components.
Download Whitepaper
Virtual Vigilance: Managing Application Performance in Virtual Environments
This paper highlights the impact of virtualization on application performance. "Managing Application Performance in Virtual Environments" states: "Best-in-Class organizations are predominately taking actions around improving visibility across both physical and virtual systems, assessing the business impact of application performance and understanding interdependencies of applications in virtualized environments."
Download Whitepaper
Application Service Requests: The Missing Link for Pragmatic ITSM
Forrester Research analyst Glenn O'Donnell and BlueStripe co-founder Vic Nyman discuss a breakthrough approach to application problem management. Learn the new approach for ITSM problem management, which provides: Rapid isolation of application slow-downs to specific components for quick problem resolution, 24/7 monitoring for proactive notification of potential issues before end users are impacted and much more.
Register for Webcast
Comment