Identity access intelligence solutions pinpoint access privilege abuse

Opinion
Jun 8, 20125 mins

The more things change, the more they stay the same — at least when it comes to managing access to corporate data resources. When I started as an internal IT auditor some 20 years ago, it was a real challenge to fully understand who in the company had access to what information resources, whether or not they truly needed to have those privileges, and whether they used those privileges. This issue is as important today as it was back then and perhaps even more so.

The process of reviewing access permissions to databases, flat files and applications was — and very much still is — a grueling process of extracting permissions information and digging through spreadsheets and home-grown reporting tools. This task has become more of an imperative in recent years with the addition of regulatory mandates, the migration of resources to the cloud, and the increasing practice of BYOD.

TECH DEBATE: Dictate the mobile device or let the user decide?

Beyond compliance requirements to manage and monitor access to resources, organizations are concerned about the ever-present threat of the “trusted insider.” The majority of insider incidents are perpetrated by employees, contractors, or other trusted business partners with “authorized access” who are performing what would seem to be authorized actions but with malicious intent. As was the case when I was an auditor and is still the case now, it’s damn near impossible to determine malicious intent until the damage is already done. (See my previous article: “Be on the lookout for the malicious insider.”)

Identity and access management (IAM) tools solve part of the problem, but unfortunately, the many complex scenarios that are examined during the access review process can yield many false positives and false negatives.

For example, let’s look at the healthcare field, which is under enormous pressure to maintain patient privacy. The automated and manual access management tools (and the people interpreting the results) may not be able to differentiate between appropriate and inappropriate access to patient records.

Consider the case of a nurse who is assigned to care for a patient in the intensive care unit. The nurse rightfully has access to the patient’s electronic health records while the patient is in ICU. As the person’s condition improves and he is transferred to another hospital ward, he is no longer in the care of the ICU nurse. At that point, this specific nurse’s access rights to the patient’s records should be revoked, and access rights should be assigned to the nurses in the patient’s new ward.

Admittedly, this is a complicated scenario, but it’s also realistic. It’s the kind of conditional access scenario that plays out in various organizations every day. Job roles change, and access privileges need to keep pace with those changes.

Now there is a new way to look at access privileges and who is doing what, and when. Unlike traditional IAM products that don’t look at trends, there is identity access intelligence (IAI). IAI complements and improves the IAM process by leveraging big data intelligence about actual rather than expected usage and privileges. IAI helps organizations identify real unauthorized user access to applications and systems, albeit after the fact. Specifically, IAI can identify “user privilege creep,” where users accumulate unrelated job function privileges over time, as well as “behavioral fingerprinting” of access to resources, which is the correlation of time and order of system and application access.

Gartner, in its report “Identity and Access Intelligence: Making IAM Relevant to the Business,” defines IAI as “the process of gathering data about identity and access, and converting it to information and knowledge for action-oriented insight and intelligent decision making in IT and business.” Put another way, IAI leverages advanced data analytics to mine identity, rights, and activity data for business intelligence that is useful not only for IT operations, but also for broader business operations.

Veriphyr Inc. is one vendor that provides a SaaS approach to the IAI market. The Veriphyr service allows organizations to identify their users’ underlying access patterns and “over privileged” accounts that can lead to security risks and compliance violations within applications, databases and systems. Organizations upload their activities log data and access rights data to Veriphyr, and the vendor correlates the information and applies analytics that visually reveal “the outliers” — the actual behavior of specific people that could be indicative of inappropriate access to sensitive data or business applications.

Organizations can pinpoint the people and suspicious activities that warrant further investigation. Moreover, it’s easy to see where people have access privileges assigned but they rarely if ever use. These privileges should be revoked to prevent potential abuse. This kind of visibility improves both access governance and the ability to make informed decisions about potential business risk around user access to sensitive data resources.

Gillette Children’s Specialty Healthcare is in the early stages of applying Veriphyr’s services to improve and simplify the hospital’s privacy breach detection and user access compliance services. Paul Higby, who is responsible for the hospital’s change management and IS security, says the process is part of the healthcare provider’s continual commitment to protecting its patients’ highly sensitive personal health information. “By analyzing actual activity rather than expected activity and access information from directories, applications, systems, and policy repositories, Veriphyr will provide Gillette intelligence that we need to prevent data leaks and privacy violations,” according to Higby.

In short, identity access intelligence solutions help highly regulated organizations to transform identity, rights, and activity data into actionable intelligence that can be used to enhance privacy, assure compliance and reduce risk.

Brian Musthaler is a principal consultant with Essential Solutions Corporation. You can write to him at Bmusthaler@essential-iws.com.

______________________________________________________________

About Essential Solutions Corp:

Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.