How much money a company makes is directly proportional to how much information it can push to its people — especially for a financial organization. With the right information at right time, the bottom line doesn’t have to be an unhappy place.
But, the inability to offer a secure environment to transfer information directly impacts revenue-making opportunities. HDFC Standard Life (HDFCSL) was not untouched by this simple equation. To promote their life insurance products and services, the business was signing up as many financial consultants as it could. (Financial consultants are like insurance agents who sign up with HDFCSL so that they can help other people plan their insurance, for a fee).
But sitting in their homes or offices, the financial consultants could not access data they needed. Limited access to leads from a HDFCSL promotion in a local mall, for example, hurt them critically. And not having the most up-to-date information on a certain scheme or policy severely affected their credibility — and their chances of getting clients to part with their money.
These were just the business problems. On a security front, it was imperative that the access of a financial consultant that had parted ways with HDFCSL be taken away.
With security worrying them and over five lakh financial consultants banging their doors for access to information, the organization realized it was time to move.
“Our mobile workforce solution first went live in early 2004, soon expanding to a full-scale B2B and B2E initiative for our financial consultants, employees and institutional customers in three years. But with it came the call for a robust, scalable and reusable security framework that could easily accommodate newer applications,” recalls Sunil Rawlani, executive VP of IT, HDFCSL.
Assured Access
Internally, too, HDFCSL was facing the heat. To keep up with the business, the insurance major was hiring internally staff; in fact, the number of HDFCSL employees doubled in a year. With such an influx of new recruits, the costs and the time spent by the managed security services to handle internal user access management went through the roof. The situation was begging for an access management solution. “We have a managed services team that takes care of user access management for about 18,000 employees. A security gap is not being promptly addressed if somebody has not been de-provisioned fast enough. Similarly, there is a productivity issue if a new recruit has not been provisioned fast enough,” says Rawlani.
At the same time, it was getting expensive to administer the system because multiple administrators and helpdesk staff were needed to provision users and help with password management. Regular audits, demanding consolidated and reconciled reports from across applications, worsened the situation.
The IT team at HDFCSL came up with a solution to enable an encompassing yet modular enterprise-wide security framework. The idea hinged around reusing security process frameworks. The result was HDFCSL’s first SOA-based project. “With this, the organization is one of the first insurance companies in India to fully deploy an Identity and Access Management (IDM) solution,” says Rawlani. Importantly, the ability to reuse the components managed the three C’s of the organization: cost, complexity and compliance.
The security framework of the IDM solution was mapped to user roles in various groups and this ensures that changes to someone’s access levels (due to changes in hierarchy) can be dealt with automatically.
“From a user management perspective, we figured out who will manage what and who will approve what. If we have a layer-1 raising a request, then a layer-2 will approve it. This is all based on rules and most of them can be reused. During the development cycle, we implemented SOA principles. New applications can be easily provisioned now thanks to the standardized framework,” explains Sharad Sadadekar, associate VP-IT, HDFCSL.
The HR application was selected as the authoritative source for the IDM as it had the most comprehensive and up-to-date database. It contained all the information of the company’s employees, temporary staff, support partner and contractors, and this was used to create a logical database for the security system. A common attribute was identified across all the applications to help achieve user provisioning and de-provisioning. “The entire project was dependent on this common attribute as it forms a permanent relationship between the HR and the pre-existing object in the database,” explains Thomson Thomas, VP-IT, HDFCSL.
But finalizing on common attributes across applications threatened to be showstopper. Sadadekar recalls the selection of attributes such as the employee ID format as a major pain. Each application was designed with its own set of structures and certain apps either didn’t have it or if they did, then it was in a variety of formats. “We had to manually incorporate these attributes before uploading them in the IDM solution,” he says.
The option of waiting until more order emerged wasn’t as sound as it seems. “In our line of business, the numbers we deal with change drastically. The more we waited for a solution the bigger the problem would have got,” says Thomas.
Managing user accounts was also a huge task. Orphan accounts threatened the business, as there were certain accounts that had illegal or extra rights on applications — with no central auditing facility. “There were accounts we never knew existed. Figuring out issues like these took a lot more time than we thought they would,” says Sadadekar. The most time-consuming phase was user data cleansing. It took almost 30 days to associate user accounts on different systems to a single individual on the identity management system, he adds.
But once those issues were thrashed out, it cleared the way for the future. “We are now know what needs to be done as far as incorporating new applications is concerned. The challenge of tweaking applications will exist, but won’t be as bad. Now it won’t take more than a few days to bring about similar changes to newer applications,” says Thomas.
“We’ll also have better control on the new applications. We have incorporated self-service modules for application administrators and owners. We foresee federated identity as a way to incorporate group businesses and channel partners seamlessly and securely using the standards-based integration,” adds Sadadekar.
Scaling Up
The IDM solution went live in January this year and it addresses the four A’s of security: authentication, authorization, administration and audit. The system has also been able to demonstrate authoritatively to the business that it enjoys greater returns on the investment in addition to securing the most prized asset of the organization: information.
“The cost of manually provisioning and de-provisioning is far greater than doing it automatically. We have been able to recover the cost of solution by just taking into account how much less it costs to manage services over eight months. If we have achieved ROI in just eight months, the project is obviously going to fly,” substantiates Rawlani.
ROI has been a major driving factor for the systems. The IDM solution has clocked a 116 percent in returns in the first year. That is expected to rise to 132 percent in the second year.
“In phase two, we are working on single sign-On. Not all the employees are currently working on single sign-on access. It is still being rolled out, informs Thomas.
As far as financial consultants are concerned, Rawlani feels that there is now confidence that this community can be reached using Web-based and SMS-based interfaces. “With this confidence, we are now looking at an e-learning solution. With secure access and single sign-on, the company is going to drastically cut cost, improve turnaround time and will have standardized way of delivering training to everybody. There will be no disconnect and everyone will have access to the same content and consistent levels of training,” he states.
“It is still evolutionary. There’s a long way to go,” he adds.




