Skip the navigation
)

Get a grip on user accounts with role management

Analyze and map employee job functions to the appropriate IT privileges

By Sue Hildreth
September 23, 2008 12:00 PM ET

Computerworld - Provisioning employees with passwords, user accounts and security privileges is the bane of every IT department. It's time consuming, often boring and, increasingly, a security risk in organizations with thousands of employees and dozens or even hundreds of IT systems, many containing sensitive data.

To deal with the problem, companies are increasingly turning to role-management software. This helps analyze and map employee job functions to the appropriate IT privileges, and helps create and manage these roles.

Early in 2007, insurance giant Cigna Corp. needed to standardize the way it assigned IT privileges to its 27,000 employees accessing Cigna's 300 or so applications. The company's traditional method -- giving new employees the same privileges held by employees in similar jobs -- wasn't keeping up with complexity and volume of new account requests.

"Without roles, you're creating IDs helter skelter," says Craig Shumard, the chief information security officer at Cigna. "So when Bill gets promoted, you might say 'Let's give Bill whatever Joe had access to, because Joe had that same job before.' But Joe might have a lot of other privileges accumulated over the years that Bill shouldn't have."

Cigna initially created an in-house provisioning workflow tool that allowed users to initiate the provisioning process by selecting job functions and IT needs via drop-down menus. But Cigna soon realized it needed a more automated system for creating user roles, one which also had reporting and monitoring capabilities.

Cigna selected the Aveksa 3 suite, which includes role monitoring, reporting and management features. The software provides analysis tools for evaluating roles and defining new ones, audit trails for proof of regulatory compliance and automated certification that routes employee role reports to business managers for validation.

Who needs role management, who doesn't?

Large organizations are most likely to want and need role management, because they usually have enough users and user roles that the process has become a burden to the IT staff. This can justify the time and cost of a role-management rollout. Also, companies in regulated industries like finance or healthcare are also good candidates for role management because of the compliance aspects of the software.

"It obviously helps us out in terms of complying with regulations" like Sarbanes Oxley and HIPAA," says Cigna's Shumard. "But having a role manager is also cost effective."

Still, not every company needs, or can afford, a role management application. Considering that the average cost of a role-management implementation is $1.17 million, according to the Burton Group, an IT analyst firm in Midvale, Utah, there should be a clear need for role management to justify the cost.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Infrastructure Management White Papers
Database Activity Monitoring Is Evolving
Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
Thinking Outside The Data Warehouse
This high level, business problem focused eBook uses 5 customer scenarios to show how people and organizations are tackling real issues using IBM...
Using BD for Smarter Decision Making
This paper looks at new developments in business analytics and discusses the benefits analyzing big data bring to the business.
Virtualizing the Client - The HP Way
HP VirtualSystem delivers best-in-class virtualization, with integrated software, services, infrastructure, and management - all delivered as one proven solution.

Intel and the Intel logo...
Gartner on the Network Infrastructure Market
The network infrastructure market has evolved rapidly, from one in which most organizations adhered to a single-vendor architecture to a more business-driven network...
All Infrastructure Management White Papers
Infrastructure Management Webcasts
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
Improve Data Center Efficiency through Building-Performance Lighting and an Intelligent Infrastructure
IT managers are under pressure to improve efficiency in their data centers. Please join Redwood Systems, CommScope and MegaWatt Consulting to learn how...
Leverage automation today to reduce IT complexity
Date: Tuesday, June 5, 2012, 2:00 PM EDT

Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
All Infrastructure Management Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs