Get a grip on user accounts with role management
Analyze and map employee job functions to the appropriate IT privileges
Computerworld - Provisioning employees with passwords, user accounts and security privileges is the bane of every IT department. It's time consuming, often boring and, increasingly, a security risk in organizations with thousands of employees and dozens or even hundreds of IT systems, many containing sensitive data.
To deal with the problem, companies are increasingly turning to role-management software. This helps analyze and map employee job functions to the appropriate IT privileges, and helps create and manage these roles.
Early in 2007, insurance giant Cigna Corp. needed to standardize the way it assigned IT privileges to its 27,000 employees accessing Cigna's 300 or so applications. The company's traditional method -- giving new employees the same privileges held by employees in similar jobs -- wasn't keeping up with complexity and volume of new account requests.
"Without roles, you're creating IDs helter skelter," says Craig Shumard, the chief information security officer at Cigna. "So when Bill gets promoted, you might say 'Let's give Bill whatever Joe had access to, because Joe had that same job before.' But Joe might have a lot of other privileges accumulated over the years that Bill shouldn't have."
Cigna initially created an in-house provisioning workflow tool that allowed users to initiate the provisioning process by selecting job functions and IT needs via drop-down menus. But Cigna soon realized it needed a more automated system for creating user roles, one which also had reporting and monitoring capabilities.
Cigna selected the Aveksa 3 suite, which includes role monitoring, reporting and management features. The software provides analysis tools for evaluating roles and defining new ones, audit trails for proof of regulatory compliance and automated certification that routes employee role reports to business managers for validation.
Who needs role management, who doesn't?
Large organizations are most likely to want and need role management, because they usually have enough users and user roles that the process has become a burden to the IT staff. This can justify the time and cost of a role-management rollout. Also, companies in regulated industries like finance or healthcare are also good candidates for role management because of the compliance aspects of the software."It obviously helps us out in terms of complying with regulations" like Sarbanes Oxley and HIPAA," says Cigna's Shumard. "But having a role manager is also cost effective."
Still, not every company needs, or can afford, a role management application. Considering that the average cost of a role-management implementation is $1.17 million, according to the Burton Group, an IT analyst firm in Midvale, Utah, there should be a clear need for role management to justify the cost.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Database Activity Monitoring Is Evolving
- Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
- Thinking Outside The Data Warehouse
- This high level, business problem focused eBook uses 5 customer scenarios to show how people and organizations are tackling real issues using IBM...
- Using BD for Smarter Decision Making
- This paper looks at new developments in business analytics and discusses the benefits analyzing big data bring to the business.
- Virtualizing the Client - The HP Way
- HP VirtualSystem delivers best-in-class virtualization, with integrated software, services, infrastructure, and management - all delivered as one proven solution.
Intel and the Intel logo... - Gartner on the Network Infrastructure Market
- The network infrastructure market has evolved rapidly, from one in which most organizations adhered to a single-vendor architecture to a more business-driven network... All Infrastructure Management White Papers
- Distributed Database Security with Real-time Monitoring
- View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
- InfoSphere Warehouse Packs Demo
- These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
- Delivery Management -- Extending Lifecycle Management
- Date: Wednesday, June 20, 2012, 1:00 PM EDT
Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,... - Improve Data Center Efficiency through Building-Performance Lighting and an Intelligent Infrastructure
- IT managers are under pressure to improve efficiency in their data centers. Please join Redwood Systems, CommScope and MegaWatt Consulting to learn how...
- Leverage automation today to reduce IT complexity
- Date: Tuesday, June 5, 2012, 2:00 PM EDT
Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
All Infrastructure Management Webcasts