enterprisesecuritymag

| | May 2019ENTERPRISE SECURITY8A New Approach To Identity and Access ManagementAs the internet continues to evolve, it is becoming increasingly difficult to maintain control of all the elements that identify who we are as a user. With the proliferation of mobile smart devices and online services offered to consumers, a single individual now has well over two dozen internet-based accounts. Such a high number of accounts pushes the average user to recycle their credentials in their personal and professional lives. The risk to enterprises is apparent as these recycled credentials are exploited, leading to security breaches and financial harm. Many organizations provision new accounts and accesses based on the current needs of the employee. This traditionally begins with human resources, leveraging their onboarding process, and ends with a provisioning action that is typically managed by their IT department. As that employee moves from one position to the other, access is typically granted to new areas and applications. Previous accesses that were granted in past positions are rarely reconciled or reviewed as job titles change. A very common symptom where the identity has been established; however, the access was never truly managed; it was simply granted. This creates larger security exploits if the user's credentials were compromised. Organizations are becoming increasingly aware of this threat and concerned about the impact on financials and perceptions. However, before they can address the issue, they must first understand what identity and access management is. Furthermore, Identity and access must be decoupled, uniquely governed, and no longer unilaterally controlled by a username and password. The access should be provisioned by a predefined set of job expectations. It takes the Role Based Access Control (RBAC) concept to a higher level where workflow is a catalyst to the level of access an individual may require, and only granted when needed. Creating identities that are tightly controlled and access that is tied to a functional purpose. By Christian Aboujaoude, Sr. Director of Enterprise Architecture, Scripps HealthIN MY OPINION
< Page 7 | Page 9 >