IAM is still evolving

Opinion
Sep 17, 20103 mins

* Identity management has grown far beyond its initial function of a gatekeeper

Did you know that “Identity and Access Management is undergoing a metamorphosis”? That’s what Deloitte’s “2010 Financial Services Global Security Study” concludes. What does that mean?

Before exploring that, I need to correct something from last week. I attributed Dave McKee, director, senior media strategy at Schwartz Communications, as the source of my data but it was actually Brian Cleary, Aveksa’s vice president of products and marketing, who unearthed the information. Thanks, Brian!

The Deloitte survey seems to corroborate the other studies and opinions I’ve been bringing you lately, as it states:

“Governance, Risk and Compliance (GRC) tend to be the driving forces behind IAM. Key issues, borne out by the top internal/external audit findings, are access certification, knowing who has access to information, whether it is appropriate, and documenting it — and strong governance that establishes automated, continuous processes for managing user access to information resources. IAM is a significantly higher priority for large organizations with more than 10,000 employees (63%) compared to small organizations with less than 1,000 employees (35%). Geography also influences respondents’ responses: IAM is less of a priority in the United Kingdom (35%) than in other parts of the world, particularly the United States (67%) and Japan (65%).”

But what’s the metamorphosis?

The report goes on: “In the early days of information security (over the last decade), IAM performed the function of a gatekeeper, essentially keeping the bad guys out. But IAM has evolved far beyond that, not only in authentication but in the level of granularity of access as well as in the ability to track back, stroke by stroke, what events took place, when, and by whom.”

Hey, the business guys are starting to notice us!

Deloitte adds: “IAM has evolved to the point that solutions can be business enablers, allowing the organization to aggregate identities across the enterprise into a single view, simplify user access to multiple applications, reduce IT costs and increase productivity. Organizations are beginning to look at IAM for customers (i.e. using IAM tools for customer identification).”

It’s nice to finally get this recognition but there is a cautionary note in the report: “IAM processes and practices tend to be expensive and thus require buy-in from the lines of business to ensure its success. The security function needs to learn how to sell itself in order to get the required funding for IAM initiatives.”

I hate to say I told you so, but, well, I did.