Top Banner
The 7 Tenets of Successful Identity Governance Tim Dickinson, Sr Manager Customer Success
50

The 7 Tenets of Successful Identity Governance

Mar 14, 2022

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: The 7 Tenets of Successful Identity Governance

The 7 Tenets of Successful Identity GovernanceTim Dickinson, Sr Manager Customer Success

Page 2: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Agenda

Who is Tim and why is he here?

Cybersecurity and Identity Governance

The 7 Tenets of successful Identity Governance

Q&A

Page 3: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Who is Tim and why is he here?

20 years working in customer-facing Technical Support and Customer Success for telecom, networking, business software, satellite communications, and cybersecurity

Nortel, CA Technologies, and SailPoint across North America, Europe, Asia, and Australia

6 years in network and identity security

Cybersecurity is a large and growing area of IT, and Identity Governance is a discipline of cybersecurity

Page 4: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 4

COMPANIES HAVE DATA

THEY WANT TO PROTECT

Page 5: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

The threat landscape has changed

31%of breaches

involved insiders

Page 6: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

The threat landscape has changed

229days

to detect a breach

31%of breaches

involved insiders

Source: Verizon Data Breach Report, 2018

Page 7: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

The way we work has also changed

72%of enterprises support BYOD

for all employees

Page 8: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

The way we work has also changed

72%of enterprises support BYOD

for all employees

$141Bestimated spend on cloud services

in 2019

Page 9: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

The way we work has also changed

72%of enterprises support BYOD

for all employees

$141Bestimated spend on cloud services

in 2019

80%of corporate data is unstructured

Sources: Bitglass, International Data Corporation, Gartner

Page 10: The 7 Tenets of Successful Identity Governance

Devices

Your disappearing perimeter

Mainframe InfrastructureDirectory AppsSaaS & CloudHR Systems

EMPLOYEESIT STAFF

Page 11: The 7 Tenets of Successful Identity Governance

Devices

Your disappearing perimeter

Mainframe InfrastructureDirectory AppsSaaS & CloudHR Systems

EMPLOYEESIT STAFF

Page 12: The 7 Tenets of Successful Identity Governance

Contractors

Devices

Your disappearing perimeter

Mainframe InfrastructureDirectory AppsSaaS & CloudHR Systems

EMPLOYEESEx-Employees IT STAFF Suppliers Customers

Page 13: The 7 Tenets of Successful Identity Governance

How do we make access secure?

INVENTORY & COMPLIANCE

Who has access?

RIGHT PEOPLE

Page 14: The 7 Tenets of Successful Identity Governance

How do we make access secure?

POLICY & AUTOMATION

INVENTORY & COMPLIANCE

Who should have access?

Who has access?

RIGHT DATARIGHT PEOPLE

Page 15: The 7 Tenets of Successful Identity Governance

How do we make access secure?

POLICY & AUTOMATION

INVENTORY & COMPLIANCE

Who did have access?

ACTIVITY & AUDIT

Who should have access?

Who has access?

RIGHT DATA RIGHT ACCESSRIGHT PEOPLE

Page 16: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

What is Identity and Access Management?

The right individuals can access the right resources at the right times for the right reasons.

• Create, delete, and manage identities

• User access (log on)

• Federation (Single Sign-On)

• Services that depend on identity entitlements

Page 17: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

What is Identity Governance?

IAM with better visibility to identities and access privileges and better controls to detect and prevent inappropriate access. Driven by the requirements of new regulatory mandates such as:

• Sarbanes-Oxley Act (SOX) and C-SOX

• Health Insurance Portability and Accountability Act (HIPAA)

• General Data Protection Regulation (GDPR)

• Personal Information Protection and Electronic Documents Act (PIPEDA)

Page 18: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Areas of Identity Governance

AccessRequest

PasswordManagement

ComplianceControls

Role Management

ProvisioningFulfillment

DataGovernance

IdentityAnalytics

IG

Page 19: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Identity Governance growth

14% CAGRaverage since 2015

$20.9Bpredicted global IG market by

2022

Source: Orbis Research, 2017

Page 20: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Key tenets of successful Identity Governance

7

Page 21: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Key tenets of successful Identity Governance

User Experience2

Identity Context3

Model-based Governance4

Risk-based Controls5

Approach to Connectivity6

Comprehensive Approach1

Consistency7

7

Page 22: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 1: Comprehensive approach

AccessRequest

PasswordManagement

ComplianceControls

Role Management

ProvisioningFulfillment

DataGovernance

IdentityAnalytics

IdentityPlatform

Page 23: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 2: User experience

Page 24: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 2: User experience

Page 25: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 2: User experience

Page 26: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 2: User experience

Page 27: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 3: Identity context

Identity Account Entitlement Data

Page 28: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 3: Identity context

DataEntitlementAccountIdentity

Tim Dickinson

[email protected]

Group=Accounting

\\Shares\HR(read)

\\Shares\Corp(read write)

Group=Users \\Shares\doc3(read)

RACF1232123

SYSDBA

Data Profile1

Data Profile2

SYSOPER Data Profile3

Identity Account Entitlement Data

Page 29: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

SIEM & DLP

Applications & Infrastructure

Mobile DeviceManagement

TENET 3: Identity context

Integrated ResponsiveEcosystem

DataGovernance

User Behavior Analysis

PrivilegedUser Mgmt.

GRC

IT ServiceManagement

Identity Context@ Center

Security Infrastructure Identity GovernanceOperations Infrastructure

Page 30: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

SIEM & DLP

Applications & Infrastructure

Mobile DeviceManagement

TENET 3: Identity context

Integrated ResponsiveEcosystem

DataGovernance

User Behavior Analysis

PrivilegedUser Mgmt.

GRC

IT ServiceManagement

Identity Context@ Center

Security Infrastructure Identity GovernanceOperations Infrastructure

Page 31: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

SIEM & DLP

Applications & Infrastructure

Mobile DeviceManagement

TENET 3: Identity context

Integrated ResponsiveEcosystem

DataGovernance

User Behavior Analysis

PrivilegedUser Mgmt.

GRC

IT ServiceManagement

Identity Context@ Center

Security Infrastructure Identity GovernanceOperations Infrastructure

Page 32: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

SIEM & DLP

Applications & Infrastructure

Mobile DeviceManagement

TENET 3: Identity context

Integrated ResponsiveEcosystem

DataGovernance

User Behavior Analysis

PrivilegedUser Mgmt.

GRC

IT ServiceManagement

Security Infrastructure Identity GovernanceOperations Infrastructure

Integrated Responsive Ecosystem

Page 33: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

IdentityPlatform

AccessRequest

PasswordManagement

ComplianceControls

Role Management

ProvisioningFulfillment

DataGovernance

IdentityAnalytics

TENET 4: Model-based governance lifecycle

Page 34: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

AccessRequest

PasswordManagement

ComplianceControls

Role Management

ProvisioningFulfillment

DataGovernance

IdentityAnalytics

AUDIT:Compliance

& Audit

IT:Automation& Controls

HR:JoinersMoversLeavers

BIZ USER:User

Self-service

TENET 4: Model-based governance lifecycle

RoleModels

ClassificationModels

ChangeControlModels

Risk Models

AutomationModels

Page 35: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 5: Risk-based controls

Page 36: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 5: Risk-based controls

Credit Score

Page 37: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 5: Risk-based controls

IdentityRisk Score

100

Page 38: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

TENET 5: Risk-based controlsLow Risk Profile Medium Risk Profile High Risk Profile

Page 39: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Identity & Access Management

IntegrationModule

IntegrationModule Connector FrameworkIntegration

Module

Identity & Access ManagementIdentity Platform

Access Request

PasswordManagement

ComplianceControls

Role Management

IdentityAnalytics

Data AccessGovernance

TENET 6: Approach to connectivity

Page 40: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Identity & Access Management

IntegrationModule

IntegrationModule Connector FrameworkIntegration

Module

3rd PartyProvisioning

Platform

Identity & Access ManagementIdentity Platform

Access Request

PasswordManagement

ComplianceControls

Role Management

IdentityAnalytics

Data AccessGovernance

TENET 6: Approach to connectivity

Page 41: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Identity & Access Management

IntegrationModule

IntegrationModule Connector FrameworkIntegration

Module

Mobile Device Mgmt.

Platform

3rd PartyProvisioning

Platform

Identity & Access ManagementIdentity Platform

Access Request

PasswordManagement

ComplianceControls

Role Management

IdentityAnalytics

Data AccessGovernance

TENET 6: Approach to connectivity

Page 42: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Identity & Access Management

IntegrationModule

IntegrationModule Connector FrameworkIntegration

Module

Mobile Device Mgmt.

Platform

ServiceMgmt.

Platform

3rd PartyProvisioning

Platform

Identity & Access ManagementIdentity Platform

Access Request

PasswordManagement

ComplianceControls

Role Management

IdentityAnalytics

Data AccessGovernance

TENET 6: Approach to connectivity

Page 43: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Identity & Access Management

IntegrationModule

IntegrationModule Connector FrameworkIntegration

Module

Mobile Device Mgmt.

Platform

ServiceMgmt.

Platform

3rd PartyProvisioning

Platform

Identity Platform

Access Request

PasswordManagement

ComplianceControls

Role Management

IdentityAnalytics

Data AccessGovernance

TENET 6: Approach to connectivity

Page 44: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Cloud / SaaS / Mobile

Enterprise / On-prem

TENET 7: Consistency

Page 45: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Convenience Automation Controls

Cloud / SaaS / Mobile

Enterprise / On-prem

TENET 7: Consistency

Page 46: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Cloud / SaaS / Mobile

Enterprise / On-prem

Structured & UnstructuredData & Access

TENET 7: Consistency

Page 47: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Recap: Areas of Identity Governance

AccessRequest

PasswordManagement

ComplianceControls

Role Management

ProvisioningFulfillment

DataGovernance

IdentityAnalytics

IG

Page 48: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Recap: Key tenets of successful Identity Governance

User Experience2

Identity Context3

Model-based Governance4

Risk-based Controls5

Approach to Connectivity6

Comprehensive Approach1

Consistency7

7

Page 49: The 7 Tenets of Successful Identity Governance

Copyright © SailPoint Technologies, Inc. 2017. All rights reserved. 49

Questions?

Tim [email protected]

@Tim_SailPointwww.linkedin.com/in/Timinator

Page 50: The 7 Tenets of Successful Identity Governance

Hope you enjoyed the presentation!

Please take a moment and complete our Speaker Survey at: www.pdsummit.ca

Feedback is a gift and its the only way we can make PDS 2019 even better!