Home > Security Channel Tips > Identity Management and Access Control > Assisting customers with content-aware IAM decisions
Security Channel Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

IDENTITY MANAGEMENT AND ACCESS CONTROL

Assisting customers with content-aware IAM decisions


Randall Gamby, Contributor
10.12.2009
Rating: --- (out of 5)


Security Channel Update
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Recently there's been a new development in the information security world: content-aware identity and access management (CA-IAM). CA-IAM is the integration of two established, usually separately administered security domains -- identity and access management (IAM) and data protection. The combination of these two domains allows the integration of user access rights and data permissions. Combining these two domains in turn simplifies three separate areas of information security: compliance, data transformation and intelligent user rights. So is it appropriate for your customers?

Today, CA-IAM is a concept, not a product. While a formal deployment is not yet available, solution providers can help customers understand the data and access requirements, user roles and responsibilities and how to classify data. Customers will also need assistance to understand the business benefits, requirements and deployment issues. Solution providers have the envious position of having a broad customer base and experience implementing emerging technologies in diverse environments. This experience has imparted a certain wisdom that's difficult to come by within an enterprise with limited and singular deployment experiences.

More on identity and access management
Authentication FAQ: Podcast with Russ Rogers

Two-factor authentication for SMB customers

Solution providers can act as a trusted partner to help organizations understand why they should take an initial look at how they can reconfigure their existing IAM infrastructure to achieve CA-IAM functionality. This functionality is realized through the integration of the data context analysis capabilities of data protection, the reporting services of security information and event management (SIEM) and the enterprise's access control tools melding with policies and processes to automatically do fine-grained authorization control down to the data level. Even though an enterprise may have all these tools, it's not easy to determine if an organization is at a level of maturity to take advantage of these services. Solution providers can offer an experienced, unbiased estimation on whether CA-IAM functionality is right for an organization. But before a company can start the process of adopting the concept of CA-IAM, solution providers will pose several questions to customers in order to decide whether they would benefit from a CA-IAM architecture:

  • Does the customer have the minimum base-level of IAM services needed to take user access to the next level of granularity?
  • Is the customer's information classified and is the solution provider able to understand the workflows for the information?
  • Are customers willing to take a leadership role in looking at this new concept?
  • Will deploying a CA-IAM project affect the company's operations in a positive way?
  • Does the customer have a corporate culture that will allow it to change its policies, processes and procedures to take advantage of CA-IAM?

If the answer to all of these questions is yes, the organization may be a good candidate.

So what role can the solution provider assume as organizations decide to proceed? All IAM deployments, including CA-IAM, require changes to people, processes and technology. Solution providers can figure out what steps need to be taken and the order to take them in to minimize risks of maintaining the current level of information protection and disruption to the business while providing new functionality. For instance, CA-IAM success demands that an organization understand and have defined processes for its user and data classifications. Solution providers can offer an unbiased evaluation of these processes and classifications as well as advice and help shoring them up prior to moving forward.

CA-IAM can offer benefits for a solution provider's own business, as well. By working with organizations to define their path toward CA-IAM, it develops a deeper understanding of the complexities of the organizations it works with. This allows a solution provider to potentially get involved with other initiatives within the organization and develop the coveted "trusted advisor" status. As the organization identifies new security opportunities in other areas, solution providers can then offer additional guidance to move the organization toward a more mature infrastructure while minimizing mistakes. CA-IAM may not be for everyone, but having a trusted advisor to lead the way will greatly help those that are taking the plunge into the future of IAM.

About the author
Randall Gamby is an enterprise security architect for a Fortune 500 insurance and finance company who has worked in the security industry for more than 20 years. He specializes in security/identity management strategies, methodologies and architectures.

Rate this Tip
To rate tips, you must be a member of SearchSecurityChannel.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
IAM strategy and technology
Despite downturn, channel committed to identity and access management
Security solution providers' priorities in 2009
How to manage guest user authentication when building a wireless network
Partner Program Directory: Authentication vendors
What current authentication methods are in use on the network?
Do any areas of the network not require authentication to access?
Will regulatory requirements affect the type of authentication used?
Have you considered multiple levels of authentication?
Authentication FAQ: Podcast with Russ Rogers
Does the customer need a multi-factor authentication solution?

New and emerging security technologies
Windows 7 security updates and new features
SonicWall announces new managed service provider program
Sophos uses North American channel strategy for new global program
Security solution providers find new opportunities amid bleak economy
How should VARs sell the new firewall technology?
Comparing network firewall inspection technologies

Identity Management and Access Control
Identity management technologies and products to offer customers
Access control compliance and corporate governance considerations
Partner Program Directory: Authentication vendors
The importance of PCI compliance
Tech Watch: Biometric devices
What current authentication methods are in use on the network?
How many users utilize the network resources currently?
Do off-site workers require remote access?
How large is the customer's employee pool?
Will regulatory requirements affect the type of authentication used?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts