The purpose of this article is to explain the features of IAM.
Core Features of IAM
In order to understand Identity and Access Management and how it will function within an organization it is important to explore its core functions. Depending on which sources you read, the market growth for Identity and Access Management is somewhere between 12 and 18 percent. This is faster than some areas of cyber security like enterprise network firewalls because cyber security professionals who are sensitive about data and the people who are accessing it are realizing that more tools are needed to protect their organizations. Identity and Access Management tools adds another layer to the security onion of protection. In fact, it adds a lot of protection to an organization’s security posture. The six core functions listed below attempt to answer how Identity and Access Management solutions work to protect an organization’s digital assets.
Policy Management Feature
The core function that the Policy Manager feature provides is the ability to store the business rules behind the security needed for digital identities and the access they require. The idea behind the business rules, or policies for identities, is that people should only have access to what they need access to in order to fulfill their job requirements. This creates a separation of duties in a logical format for the digital way of working. These policies are created within and for the specific department in coordination with Human Resources and Executive Leadership.
Policy Administration Feature
Policy Administration is the feature that automates the rules within policy management and creates workflows for approval. For an example, when an employee is promoted, an e-mail requesting approval from an HR Manager, former manager, and new manager may be required. Once all parties have approved the promotion and required access changes, the employee’s former access becomes revoked and new access requirements are applied.
User Access Provisioning Feature
The User Access Provisioning function automatically applies access requirements to identities across all directories. Once approvals are received for a user add/change/remove, provisioning of permissions and credentials are created across all enterprise applications, folders, and resources to allow a user to have access on day one.
Virtual Directory Feature
Virtual Directory Services are becoming more and more critical in successful identity and access management projects as organizations are moving more workloads and applications to the cloud. Virtual Directory Services allow the organization to build a comprehensive directory of all identities used across the enterprise. In turn, this function works with User Access Provisioning and Policy Administration by collaborating on identity information to provide the necessary resources to individuals who need them.
Privileged Account Management Feature
Privileged Account Management is an important aspect of Identity and Access Management implementations because it manages the most critical identities within the organization: super user, domain administrator, local administrator, application accounts, service accounts, database accounts, and credentials used for managing the infrastructure (i.e. firewalls, network switching, storage arrays, virtualization, etcetera). The privileged account management function ensures that IT administrators access only resources that are required for their function and because their role is so vital, that all activity is logged and recorded and sent to the Security Monitor function.
Security Monitor Feature
The Security Monitor function records all activity and changes within the identity and access management solution. Its purpose is to ensure that changes are not being made outside of the workflow of the identity and access management solution. Attempts to make changes directly to users are recorded and an alert is sent to the Security Incident and Event Management (SIEM) tool in order to alert a Security Analyst that policies are being abused and action needs to be taken.
The overall goal of an identity and access management solution is to provide the right user with the right permissions to what they need in order to do their job and nothing else. Identity and Access Management solutions are perfect for those organizations who are looking to implement the Principal of Least Privilege. The different functions discussed provide the capability to implement a successful identity and access management solution. These functions should be a core focus for anyone who is considering an identity and access management implementation for their organization.