Manageable identity

April 2012 Access Control & Identity Management

For a considerable period of time, identity management solutions were technology focused implementations geared towards automating user access management processes. The reality of the situation unfortunately saw a growing businesses despondency with the perceived lack of business value being derived from deployed identity and access management solutions. The shortfall on derived business value can primarily be attributed to:

The massive integration undertaking required, involving expensive skills and expensive technology, when integrating all IT systems in a company with an identity management service.

Data quality from feeder systems, usually human resources systems, that drive automated user access management processes is often very poor. Employee records are either so lacking in detail or the existing details are so ambiguous that it is often impossible to derive usable provisioning and access management data for business systems integration.

The line of business demands involvement in user access management processes, such as reviewing who has what access.

With the immediate pressures of legislative compliance, IT executives are looking more closely at identity management solutions to provide their organisations with a set of easy to use processes that will allow line of business to manage access to IT resources themselves.

Provisioning of access now no longer has a need to be fully automated. Organisations have the choice of adopting a combination of a direct automated approach to provisioning accounts and access through integration with their directory services while also utilising a manual process where tickets are submitted with a IT service desk for account access assignment to other systems.

This hybrid approach allows for a shortened identity management service implementation time. Thereafter all IT systems can be configured with a single set of processes used throughout the organisation for requesting access, approving access and reviewing access to IT resources. In some cases provisioning can initially take place through a service desk, but then can be moved over time to an automated provisioning integration when the need arises.

Many best practices (King III, COBIT, etc) and legislation (Sarbanes Oxley, POPI, etc.) requires that identities and their applicable access be managed. These requirements promote the request to access, approval of requests and assignment of access to be stored electronically and to be easily reported on. With this data electronically recorded it is possible to frequently review access assignments, allowing line of business to ensure that their direct reports always have the right access, but never allowing access to accrue beyond that necessary for their job role.

When the core of an identity management system is focused upon the achievement of these access governance goals, it is simple to motivate such a solution to a business audience. More importantly it is also easier to show business a quick return on investment. Identity management in the future will focus on ensuring continuous compliance. As identity information changes, for example an employee’s job title, the access must immediately be reviewed by the line manager, ensuring that there is no prolonged period during which the organisation is exposed to risk.

For more information contact Ubusha Technologies, +27 (0)82 882 0351, [email protected]





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

New State of Physical Access Control Report from HID
HID Global Editor's Choice Access Control & Identity Management News & Events
HID released the 2024 State of Physical Access Control Report, identifying five key trends shaping access control's future and painting a picture of an industry that has been undergoing considerable transformation.

Read more...
Smart intercoms are transforming access control
Access Control & Identity Management Products & Solutions
Smart intercoms have emerged as a pivotal tool in modern access control. They provide a seamless and secure way to manage entry points without the need for traditional security guards to validate visitors before granting them access.

Read more...
Easy, secure access for student apartments
Paxton Access Control & Identity Management Surveillance
Enhancing Security and Convenience at Beau Vie II Student Accommodation, a student apartment block located at Banghoek Road, Stellenbosch, with Paxton's access control and video management solution

Read more...
Invixium acquires Triax Technologies
News & Events Access Control & Identity Management
Invixium has announced it has acquired Triax Technologies to expand its biometric solutions with AI-based RTLS (Real-Time Location Systems) offering for improved safety and productivity at industrial sites and critical infrastructure.

Read more...
ControliD's iDFace receives ICASA certification
Impro Technologies News & Events Access Control & Identity Management
The introduction of Control iD's iDFace facial biometric reader, backed by mandatory ICASA certification, underscores the commitment to quality, compliance, and innovation.

Read more...
The future of workplace access
HID Global Access Control & Identity Management
Mobile credentials are considerably more secure than physical access control, because they eliminate the need for physical cards or badges, support multiple security protocols, and add layers of protection on top of basic card encryption.

Read more...
Integrated, mobile access control
SA Technologies Entry Pro Technews Publishing Access Control & Identity Management
SMART Security Solutions spoke to SA Technologies to learn more about what is happening in the estate access world and what the company offers the residential estate market.

Read more...
Bespoke access for prime office space
Paxton Access Control & Identity Management Residential Estate (Industry)
Nicol Corner is home to a six-star fitness club, prime office space, and an award-winning rooftop restaurant. It is also the first building in South Africa to have its glass façade fully incorporate fritted glazing, saving 35% on energy consumption.

Read more...
Next-generation facial recognition access control system
Enkulu Technologies Products & Solutions Access Control & Identity Management Residential Estate (Industry)
With a modern and innovative design, iDFace is the ideal device for monitoring and controlling people entering and exiting a building using facial recognition technology, including liveness detection, for enhanced security.

Read more...
Long-distance vehicle identification
STid Security Products & Solutions Access Control & Identity Management Residential Estate (Industry)
The STid SPECTRE reader can identify vehicles up to 14 metres away, across four traffic lanes, ensuring secure access to an estate without disrupting the traffic flow.

Read more...