 |
The set of processes, procedures and technologies of
IT systems is a fundamental component to achieve the
possible integration of all IT resources.
Identity management is the set of business
processes, and a supporting infrastructure for the
creation, maintenance, and use of digital
identities. Identity and access management refers to
the processes, technologies and policies for
managing digital identities and controlling how
identities can be used to access resources.
Identity management and the provisioning of access
to company resources involve the careful execution
of three processes:
-
the access model process
-
the workflow process and
-
the identity process.
The access model process maps established business
policies to roles and rules to be used when creating
and managing an identity. Relevant factors include
information security policies, separation of duties
(SOD) rules, customer requirements and external
influences, such as government and industry
regulations. The workflow process takes established business
policies, such as business processing and approval
requirements, and establishes the step-by-step flow
of how an identity is created. The identity process is where the mapping of the
roles, rules and workflow for a specific user come
together to create an account (or set of accounts)
on a target or more likely, a set of target
platforms. This ensures that the user will have all
the account attributes and privilege assignments
needed to access company resources. Each process
includes 6 common actions: create, use, change,
report, log and retire.
Improved User Experience
The right identity and access management solution
will greatly enhance the users’ experience, helping
them to control their on-line identities because
they will no longer be required to manage a hoard of
passwords. An integrated identity and access
management solution also enables simplified sign-on
so users can move seamlessly across applications and
even domains. Such a system will even create a
“circle of trust” in which participating
organizations can verify the authenticity of users
in a federated model. The results will be
productive, satisfied users.
-
Investment Protection - Enhanced Integration
Seamless integration into an organization’s
heterogeneous e-business environment is critical.
Identity and access management solutions will act
much like “middleware”, enabling organizations to
manage digital identities across their diverse and
expanding infrastructure. A standards based approach
will play an important role in this enhanced
integration, ensuring investment protection and
dramatically reducing the risk of custom
integration.
-
Cost Savings - Multi-purpose Platform
Organizations will be able to manage multiple
authentication options (i.e. Tokens, smartcards,
certificates, passwords, etc.) from a single
platform, providing choice in any environment and
enabling web services to leverage the platform.
-
Cost Reduction
- Centralized Administration
The right identity and access management solution
will enable organizations to simplify the management
of digital identities and security policies with one
administrative model. This translates into lower
administrative costs and reduced resource burden.
-
Risk Mitigation - Enhanced Security
Identity and access management solutions will ensure
greater levels of security to match the grooving
risk of exposure and high stakes involved in
e-business and web services. The solutions will
shift fluidly with an organization’s perimeter
protecting the business at application level.
|
 |