THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.


I
Eugene Ostapenko, Head of Information Security, Risk and Compliance, illion
It is largely possible, but the road is not fast nor simple.
First of all, have a plan. The following article is written to provide a series of specific steps to build a successful AIM program. Don’t rely on a technical solution to solve the process or human problems. It is very tempting to dive into a technical solution expecting it to solve all the problems. A holistic approach comprising of people, process and technology is the key.
The full journey will take at least 2 to 3 years, or even longer. The main considerations are the organisational size, the initial maturity phase, appetite for changes, risk and, last but not least, resources available.
I recommend breaking the IAM capability uplift program into specific measurable phases. Each following phase builds on the previous.
Start by analysing the current state. Review, develop the set of highlevel governance documentation, review current practices, provisioning and de-provisioning processes. Talking to the SMEs and business stakeholders is invaluable to get insights into the current pain points. Recognise that IAM will never solve all the problems. Focus on the achievable.
Follow by establishing a solid foundation for an AIM implementation. A critical success factor of this phase is establishing the scope. Start with a small achievable scope to prove the processes and technology are working. Develop a set of requirements to consider what solution, if any, is needed. If choosing a new solution, deploy out of the box. Avoid customisation.
Commence Phase 2 after running the AIM for at least three months during which focus on resolving governance, process and implementation gaps. The key outcome of this phase is to get quick wins in improving at least some user experience and reduction of support operations in onboarding and terminating user accounts. Some of the specific objectives of this phase are classification of the applications for the next phases, deployment of selfservice capabilities, review and confirm exemptions and approach to track and document.
Phase 3 implementation objective is to get operational sustainability. Establish the actual SLAs and confirm against the Phase 1 objectives, compliance metrics and audits. Define and document Segregation of Duties (SoD) principles and guidelines. Remediate SoD for the highest risk applications. Identify and resolve process exceptions to make sure all agreed entitlements are provisioned and enforced by the solution.
Phase 4 is focusing on longer-term objectives and strategy. Typically, this phase starts after about two years from the project start. The objective of this phase is to future-proof the investment. In this phase, focus on maintaining the list of application exemptions. Do not permit exemptions for newly deployed applications. Continuous operational uplift includes extension of SoD into other high-risk applications. Reporting capability is also an important closure element.
In conclusion, don’t underestimate the importance of management support for a successful IAM implementation.
Focus on business benefits, such as staff access, and hence, productivity is established from day one. Consider other avoided overheads such as reporting, the operational impact for support and lost productivity due to changes and incorrect assignments.