VIRTUAL PRESS OFFICESTM
(011) 807 3294   itnews@itweb.co.za | Advertise on ITWeb   Tue, 1 Jul 2008
You are here Home Security

Lack of planning can hamper governance and compliance efforts

Enterprises need to follow best practices to reap the real benefits of identity and access management solutions

The complexity of identity and access management (IAM) software requires adequate planning to ensure the benefits filter through to the entire business.

According to Karel Rode, Principal Consultant for the Security Practice at IT management company CA, IAM is not off-the-shelf software. Rather than providing plug-and-play functionality, IAM is complex software that requires substantial planning and often staged deployments for success.

"While the benefits of IAM deployments - such as increased security, reduced IT costs and improved compliance and agility - have been well documented, planning is key to ensure that IAM has a positive impact on all business areas."

The reason for IAM`s complexity is that it has a company-wide impact. It could, for example, affect organisational structures and business strategy, impact application development processes, influence compliance activities and shape customer interactions.

According to the IT Policy Compliance Group, firms with better IT governance enjoy much better performance than other organisations when it comes to satisfying and retaining customers and growing their revenues and profits.

The group`s research found that companies with the most mature practices typically have 17% higher revenues, 14% higher profits, 18% higher satisfaction rates and a staggering 96% lower financial loss from the loss or theft of customer data.

"The importance and benefits of IAM are clear; however, we are still finding organisations grappling with their IAM initiatives," adds Rode. To this end, Gartner [1] has identified a set of high-level best practices that provide guidance for ensuring the success of IAM initiatives.

Grouped in three broad categories - planning and budgeting, design and deployment - the research firm based its best practices on insights gathered over the past few years and lessons learned from clients:

* Planning and budgeting practices: Aspects to consider include creating a cross-unit IAM programme with senior-level commitment and establishing a phased approach to delivering IAM solutions.

* Design practices - Repositories and role lifecycle management: During the design phase organisations need to, among others, strive for the fewest number of identity repositories, separate the authoritative repository from the enterprise directory and match the organisation`s culture and operations with a role framework.

* Deployment practices: Factors that need to be taken into account in terms of deployment include exploiting reduced or single sign-on infrastructures, using new authentication methods in unacceptably risky situations and monitoring the IAM market for managed services offerings.

"As the effects are potentially so broad, careful planning across all impacted areas is essential. The IT organisation needs to factor business, technical, political and regulatory issues into their planning to ensure the ongoing success of governance and compliance programmes," concludes Rode.

Enjoyed this story? Subscribe to ITWeb's Security News newsletter.
CA

CA (NASDAQ: CA), one of the world`s largest independent software companies, provides software solutions to unify and simplify IT management. With CA`s Enterprise IT Management (EITM) vision and expertise, organisations can more effectively govern, manage and secure IT to optimise business performance and sustain competitive advantage. Founded in 1976, CA serves customers in virtually every country in the world. For more information, please visit www.ca.com.

 
 
  POST YOUR COMMENT

busy

 

Industry news

 

 

SecureData updates BEE status:
In November 2009, Secure Data commissioned Honeycomb to conduct a BBBEE verification of the organisation. The BBBEE rating is based on the Codes of Good Practice on Black Economic Empowerment released by the DTI. Based on this, Secure Data is a Level Four Contributor, allowing a recognition level of 100%.

 

Magix empowers clients to fight against fraud with continuous, non-invasive auditing and monitoring solutions designed to take the hard work out of risk management. Visit our website to see the various solutions we specialise in. 

 


Sponsored links


SMEXA 2010
3-4 August 2010| The Forum, Bryanston
Booking fee: R4 155.00 (excl VAT)
An itSMFsa Event in Partnership with ITWeb
Routes to Recovery through IT Service Management
SMEXA 2010 will focus on what organisations can expect from the South African economy in 2010 and beyond. Attendees will gain insight into how soon the South African economy will recover and what ITSM can do for their business.

The exhibition running alongside the conference will provide delegates with an opportunity to evaluate top ITSM suppliers and their services and solutions

Click here to book your place today!

Diamond sponsor

Platinum sponsor Gold sponsor


Publications

The BSA’s figures for software piracy in this country need adjusting. It could start by surveying some South Africans.

 

Valerie Geen

GREEN IT

Baby steps