|
|
|
A Methodology for Implementing Continuous Roles Based Access Governance
Executive Summary The management of user access has long been an extraordinarily complex challenge for organizations. Central to this challenge is the concept of creating defined user roles. Used correctly, roles provide a means of simplification, and allow organizations to tailor enterprise access to the needs of the business. The result, in a perfect world, is greater IT operational efficiency, business agility and improved security through a set of preventative controls. In practice, nearly every organization has struggled with how to define and implement access roles that will meet the objectives of the business. Because of this, the promise of IT administrative operational efficiency and improved security has remained out of reach. In many cases, role management at the application or information resource level has resulted in role proliferation, which has actually led to increased complexity and inefficiency. Adding to this problem is the ad hoc nature of how roles are managed over time. With the amount of change that occurs to access within a typical organization, roles can become ineffective if they are managed in a static fashion (on a project basis). The solution is to take a completely different approach to the creation, implementation and maintenance of roles through a business-centric, continuous process for enterprise role-based access governance.
|




Click Here to read the complete Whitepaper...