
March 13, 2018 • Garrett Garitano
You want to improve your cybersecurity defenses. There’s just one problem. There are many different security products and projects you could start. Is access governance the right project? To guide you through the decision-making process, use the questions in this article. Know Your Organization’s Priorities and Context: Going Outside the IT Department Your IT project […]
You want to improve your cybersecurity defenses. There’s just one problem. There are many different security products and projects you could start. Is access governance the right project? To guide you through the decision-making process, use the questions in this article.
Know Your Organization’s Priorities and Context: Going Outside the IT Department
Your IT project ideas do not exist in a vacuum. Instead, they need to be seen in the broader context of your company’s resources and goals. Ignoring this context is one of the reasons why IT professionals are sometimes labeled as not being business oriented. Before you propose an access government project, get the lay of the land using the following three questions.
1) What are the organization’s goals for the year?
Highly successful organizations focus on goals, and your company is no different. Examples of company-level goals include:
If you are in a public company, check the organization’s annual report. If that document is not available, ask other managers about the division’s goals.
2) What is the organization’s appetite for technology and innovation?
Does your organization love to innovate and experiment with new technologies? In that case, securing approval for an access governance project is going to be a walk in the park. At least, so you might imagine.
In reality, there are always more exciting ideas available than resources. To discover your organization’s actual appetite for new technology, look for the following points:
3) What is the organization’s change management process for technology and cybersecurity?
Funding an access governance project is no small decision. You will be changing some of the core security processes and technologies in your company. Before you start investigating supplies, find out the internal process for implementing change.
The following points will get you headed in the right direction.
Define Your Approach to Access Governance in Three Questions
By going through the steps described above, you will understand your company’s goals, resources, and interest in technology. To fund access governance adequately, make sure you answer the following questions.
1) What access governance software solution will you use?
Your software development team probably does not have the capacity or expertise to build an access governance solution in-house. That means you will need to buy a solution. Of course, we recommend Compliance Auditor. It is made with the needs of auditors and corporate governance in mind.
How do you make sure you are making a smart buying decision? Use these resources:
2) What implementation effort is required to put access governance into place?
Buying new technology is only the start of the project. You will also need to organize an implementation project. At a minimum, think through the following points:
Now, what happens after the project is complete?
3) Who will own enterprise responsibility for access governance after implementation?
Once the access governance project is complete, who will take responsibility for keeping it going? Forgetting this point is a typical failure project in many technology projects. We recommend nominating a single manager to oversee access governance for the next year. At that point, you can reassess if your arrangements need to change.