Seven habits of highly effective identity management
Computerworld -
The emergence of Web-based technologies has forced organizations to change the way they conduct business. They must find new ways and new tools to securely control access to corporate resources and manage the security risks associated with the escalating volume of user administration.
To be successful, companies must integrate their information systems and combine disparate technologies, particularly as a result of business mergers and acquisitions. To accommodate these changes, the IT department must administer a large number of heterogeneous systems and applications, manage a huge influx of new users and adjust their privileges accordingly. To add to this complexity, many organizations have implemented point security solutions, which are often time-consuming and costly for the IT department to integrate and customize.
Integrated identity management systems help IT managers reduce risks, manage user administration demands and adapt to new regulations. Identity management systems with the right requirements can help companies realize benefits across the business, from employees and partners to customers.
The following are seven "must-haves" to look for when selecting the best identity management system for your organization.
1. Role-based user provisioning
User provisioning is the process for managing user identities enterprisewide and beyond. User provisioning encompasses the following:
- Types of users an organization will manage
- Systems, applications and other business resources users need access to
- Levels of access to those resources
- Creation, update and deletion of user accounts
- Measurement of administrative overhead associated with user management
- Metrics for success
User provisioning provides the proper resources to users at minimal cost. It manages a user's work cycle, including things such creating accounts on different systems, extending access to external services and temporarily suspending access or permanently revoking accounts. Effective user provisioning reduces security risks, including weak passwords, and minimizes obstacles to user productivity. User provisioning also provides centralized management capabilities and automation via role-based account creation and workflow access rights to business resources.
2. Managing user identity
Organizations can identify different types of users according to their business functions: employees, customers, suppliers, partners and more. Each user within these groups owns a separate online "identity" that can be managed efficiently to reduce risks and lower business costs.
It's far easier to manage a single user identity than multiple identities for one user. Identities can be managed according to users' needs, enabling the organization to deliver quality and increased customer satisfaction.
Internally, user provisioning tools are implemented by the IT department and integrated with the human resources application. Particular user roles should have predefined access rights. When an employee joins a specific role, his access permissions to business
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
IDC White Paper: CCM for IT Compliance and Risk Management
Learn from industry analysts how IT organizations are using configuration management to meet compliance requirements and instill best practices. Find out how these...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
Keep it Clean: Maintaining the Integrity of your CMDB through Change Detection
Learn how configuration drift can challenge configuration management database (CMDB) integrity and how a configuration audit tool and an effective change management process...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
HIPAA requires businesses that handle personal health information (PHI) to set up strong controls to ensure the security and integrity of that information....
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Configuration Assessment: Choosing the Right Solution
Configuration assessment lets businesses proactively secure their IT infrastructure and achieve compliance with important industry standards and regulations. Learn why configuration assessment is...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
