* Courion develops Dynamic Communities concept
Last issue, we explored ways to speed up implementation of role-based access control by using data mined from access audit logs to help define broad roles that can be populated by numerous users. It’s a good method and it should help not only with implementation speed but also with selling the whole RBAC project. Still, there’s more than one way to innovate with roles.
Courion co-founder and CTO, Brian Milas can get very wrapped up in the technology of identity (as opposed to, say, the business). His eyes light up as he explains a new way of approaching a problem. And when I met with him at the recent RSA conference, he wanted to talk about RBAC using a new concept he’d developed for Courion called “Dynamic Communities.”
As Milas said, organizations aren’t static, they quickly assemble, disassemble, and re-assemble communities of staff, partners and customers to drive business operations. Trying to keep access controls and authorizations in step on a user-by-user basis is impossible. But trying to keep static roles in place to cover these situations is almost as difficult. The answer, at least according to Milas, is to remove, as much as possible, the static elements. The “Dynamic Communities” technology, he believes, enables the component elements of roles and rules to be assembled real-time based on business, security and operational policies.
This is an implementation of what the Gartner group has called “role matrix management.” That is, assigning roles based on the organization’s management matrix rather than simply on an org chart. The management matrix (if I can simplify) is an ever-changing view of the relationships within the organization based on current projects, duties and responsibilities.
Traditional static rule/role-based access control models require modifications be made at the IT infrastructure through re-coding and re-scripting when people, relationships, policies and infrastructure change. But Dynamic Communities enable the provisioning solution to adapt to change without any manual modification, Milas explained.
These Dynamic Communities are managed by the business owners responsible for each specific community and not by IT. This enables real-time compliance with business policies and quick adaptability to change. The dynamic method of provisioning reduces the number of rules and roles required, and lessens or often eliminates the cost and time of redefining workflows when change occurs – whether to people, responsibilities, relationships, security policies or business policies.
If you use the data mining technique outlined in the last issue to initially create roles and then adopt methods similar to the Dynamic Communities model, your RBAC can be up and running quickly but also constantly redefining itself to meet the current needs of the organization. Think of it as “Just In Time” (JIT) processing for identity management.




