
September 18, 2012 • Garrett Garitano
Identity and access management crush. An interesting discussion came up recently on the Gartner Identity & Access Management XChange on LinkedIn. A participant asked for a breakdown of the elements that make up Identity and Access Management (IAM). A number of opinions were offered, most differing only slightly from the others. Perhaps the most different […]
An interesting discussion came up recently on the Gartner Identity & Access Management XChange on LinkedIn. A participant asked for a breakdown of the elements that make up Identity and Access Management (IAM).
A number of opinions were offered, most differing only slightly from the others. Perhaps the most different take on it was one respondent who provided a link to a lengthy paper that made a case for IAM being an amalgamation of two separate, yet symbiotic platforms — Identity Management and Access Management. While I can see his point, I think that in today’s world of business the two really need not and should not be separated.
Here’s how I see the components of IAM:
Ideally, all of these elements should be made available through an actionable service catalog that uses an internal "application store" approach, thereby enabling both managers and individual users to request new or updated access through a user-friendly, shopping cart style self-service provisioning portal tied to an automated approval management system. This encourages more consistent maintenance, which in turn increases overall security effectiveness while creating an audit trail of changes and approvals… and that’s what IAM is all about.
Get a Free Copy of the Top 10 Identity Management Best Practices WorkbookBegin your identity management initiative by following what corporate compliance experts recommend for the workflow automation of businesses processes, self-service administration and IT operations.