[Log In] []

Exploring the science and magic of Identity and Access Management
Saturday, April 20, 2024

IAM Lifecycle Management for (Take Your Pick)

Identity
Author: Mark Dixon
Friday, May 6, 2011
3:58 pm

We in the IAM world do a fairly good job of addressing “User Lifecycle Management” and “Role Lifecycle Management” issues, but are generally abysmal in other areas that beg to be governed by full-functioned, easy to use, lifecycle management principles.

What are lifecycle management principles?  I propose that the following apply:

  1. Application of standard, repeatable, and easy-to-use methods for creating, configuring, changing, approving, invoking and terminating objects.
  2. Ability to execute these methods directly or through delegated administration functionality.
  3. Ability to verify correct operation through process transparency and consistent audits.
  4. Ability to easily manage objects individually or in large sets.

In order to benefit from lifecycle management principles, objects need to have characteristics such as these:

  1. a beginning
  2. an end
  3. dynamic configuration over time
  4. need of approvals for creation, changes and termination
  5. operative dates/times for each step in the lifecycle
  6. object versioning

Given these two lists, what types of objects in an Identity and Access Management system beg for Lifecycle Management?  At least these:

  1. Users
  2. Roles
  3. Entitlements
  4. Policies (for provisioning, access control, authorization and audits)
  5. Managed Systems (applications, systems, devices, etc.)
  6. Workflows/Processes
  7. Forms
  8. Configurations

Wouldn’t it be great if there was a single coordinated, cohesive user interface for providing lifecycle management of all these objects? Certainly, there are significant differences between object types, but the processes of keeping them all under control over time have more similarities than differences.

We still think too much in silos, rather than in integrated architectures.  If we are to ever reach the worthy objectives of ease of use, rapid implementation and effective administration, we must successfully conquer this lifecycle management problem.

 

 

Comments Off on IAM Lifecycle Management for (Take Your Pick) . Permalink . Trackback URL
 
Copyright © 2005-2016, Mark G. Dixon. All Rights Reserved.
Powered by WordPress.