Privileged user management, authentication, authorization, separation of duties, access governance – these all (and more) need to be part of your Identity Management systems. They’re all interconnected, they all depend on properly identifying not only your users but also all of the things they use. In fact, it isn’t the information that needs to be managed, but the access to that information.
At the risk of having to eat my words before the month is up, this should be the last newsletter on predictions (http://www.networkworld.com/news/2011/010311-five-2010-stories-that-nobody.html) for a while. But Idan Shoham and the folks at Hitachi ID Systems brought my attention to a recent paper from Forrester report called “Twelve Recommendations For Your 2011 Security Strategy.”
Note: I didn’t read the original because Forrester wants $500 for it. If you’re a client you might take a peek, though. The quotes below are from Hitachi-ID’s press release about the report.
Of interest to us, the report recommends that organizations consider a move from identity management to information and access management as they prepare their 2011 security strategies. What’s that mean?!?
2011 tech priorities: Are you ready to shake things up?
What they mean, evidently is that “…onboarding and deactivating users in a reliable, timely fashion is not enough.” Oh, I see. Forrester equates Identity Management with provisioning! How quaint.
The report then suggests that “Organizations have to ensure that users get appropriate access rights, both initially and as they move through an organization. Often, you must demonstrate controls around segregation of duties, privileged access, and stronger authentication for Internet-facing applications to meet regulatory requirements.”
Well, shucks. Maybe we should have been talking about that stuff. Oh, wait – we have been! For a number of years now.
Privileged user management, authentication, authorization, separation of duties, access governance – these all (and more) need to be part of your Identity Management systems. They’re all interconnected, they all depend on properly identifying not only your users but also all of the things they use. In fact, it isn’t the information that needs to be managed, but the access to that information.
Shoham (he’s the CTO at Hitachi ID) sees through this when he says: “We at Hitachi ID Systems have always understood that managing identities and managing entitlements are two sides of the same coin.” Hopefully you do to. But a large number of business (as opposed to technical) execs in your organization will read the Forrester report, will get the wrong idea and will try to make your life miserable. Be prepared!




