To build a foundation for an automated identity and access management migration, your organization must first define, map, and set clear parameters for IAM implementation. Do this by auditing, preparing, and documenting the following items for migrating manual user access and provisioning to IAM.
Further details for each implementation requirement are listed below.
Compile a list of the critical resources (systems, apps, data) whose user provisioning and access will be managed from your IAM environment. This list will define the scope of your IAM solution. Most in-scope resources can be discovered through your current manual user provisioning system.
It is also important to include any shadow IT apps and cloud storage services that are being used without organizational controls. Shadow IT apps and cloud storage usage can be discovered using several tools, including monitoring browser activity, network traffic analysis, endpoint monitoring, and configuration management database (CMDB) software.
Once compiled, your in-scope list can be prioritized for implementation in your identity and access management environment. Because new applications frequently come on-line and users will always access shadow IT apps and cloud storage, the in-scope list should be regularly updated and applied to your IAM solution.
Each resource on the in-scope list should also be identified as to who its primary IAM stakeholders are. This stakeholder list will be used to determine what roles each stakeholder has in administering user and access provisioning. Possible IAM roles for each stakeholder and their duties include:
Stakeholders should designate the regulatory mandates and other requirements to satisfy the legal, financial, personally identifiable information, security, and other requirements for each resource. This information can be used for designating user access assignments for IAM stakeholders.
As you migrate user provisioning and access management to an IAM solution, audit each resources’ user accounts and document the following items for migration to your IAM environment.
Relevant metrics help cost-justify an IAM system migration. They can also demonstrate how effective your IAM implementation is and to flag areas that need further improvement.
Consider gathering metrics before you start your migration and at critical junctures during and after the migration. Metrics can be used for evaluation and continuous improvement. IAM metrics can be gathered on a resource-by-resource basis or an accumulated basis for all migrated resources. Each metric should also contain a target value based on IAM stakeholder and access requirements.
Here are some important user access provisioning and deprovisioning metrics for IAM implementation and evaluation.
Coordinate with your IAM stakeholders to determine which IAM metrics should be tracked.
Contact Seasoft Security for more information on preparing and implementing an advanced Identity and Access Management solution like Tello. Our IAM experts can perform an organization-specific assessment to help modernize your user access and provisioning environment.
IAM implementation is the process of deploying identity and access management to automate how users are provisioned, deprovisioned, and assigned access to systems, applications, and data. Before implementation, organizations should define the scope of the IAM environment, identify stakeholders and access requirements, audit existing user access, establish access controls, and define measurable success metrics.
To prepare for an IAM implementation, first identify the systems, applications, and data that will be managed by the IAM solution. Then identify stakeholders, document access requirements, audit existing user accounts and permissions, identify source identity providers, define access controls and lifecycle triggers, and establish measurable implementation targets.
An IAM implementation plan should include the scope of the environment, IAM stakeholders and their responsibilities, user access requirements, source identity providers, user lifecycle triggers, access control policies, role or attribute definitions, baseline least-privilege access, and metrics for measuring implementation success.
When defining IAM implementation scope, identify the critical systems, applications, and data whose user provisioning and access will be managed through the IAM solution. The scope should also account for shadow IT applications and cloud storage services. Because applications and user access requirements change over time, the scope should be reviewed and updated regularly.
Key IAM stakeholders typically include IT administrators, support teams, managers, and audit and compliance teams. IT administrators manage IAM configuration and security, support teams handle user and access management, managers approve access requests and changes, and audit and compliance teams help ensure access controls satisfy regulatory and reporting requirements.
Before implementing IAM, audit user accounts and their existing access across the systems and applications being migrated. Document user identities, current permissions, access requirements, roles, lifecycle information, and the source identity providers responsible for user information. This audit provides the baseline for designing automated provisioning and access controls.
Role-based access control (RBAC) helps simplify IAM implementation by assigning permissions to predefined roles rather than managing individual user permissions. Organizations can analyze existing permissions to define common roles and use those roles as baseline access assignments for different classes of users.
IAM automates user provisioning and deprovisioning by using lifecycle triggers from source identity providers such as HR systems and directories. When a user joins, changes roles, or leaves the organization, those lifecycle events can trigger automated changes to the user's accounts and access.
IAM lifecycle triggers are events that initiate automated identity and access changes. Common triggers include a new employee joining the organization, an employee changing roles or departments, or an employee leaving the organization. These events can initiate provisioning, access changes, or deprovisioning.
Organizations should track IAM metrics that demonstrate how effectively access is being provisioned, managed, reviewed, and removed. Important metrics include time to provision, time to deprovision, orphaned account ratio, user access review completion rate, and segregation of duties (SoD) violations.
The principle of least privilege means giving users only the access they need to perform their jobs. During IAM implementation, organizations can establish baseline access for common users and require additional approval or elevated permissions for access beyond that baseline.
You can measure IAM implementation success by establishing baseline metrics before migration and comparing them with results during and after implementation. Useful measures include provisioning and deprovisioning times, orphaned account ratios, access review completion rates, and SoD violations. Each metric should have a defined target based on business, security, and compliance requirements.