SlideShare une entreprise Scribd logo
1  sur  14
IBM Security Identity Manager at ATP
Impact of On-boarding 1500 Users in a Highly Customized ISIM System
About ATP
The largest pension fund in Denmark managing public pensions
schemes for 4.7 mill. persons
Total assets worth of DKK 700+ billions (app USD 100+ billions)
Generally regarded as one of the best performing pension funds
world wide with a very high return rate and low cost.
ATP has recently been appointed to take responsibility for most
public welfare payments payouts (”Udbetaling Danmark”)
Yearly payouts app. DKK 180 billions (app. USD 27 billions).
Reducing the cost with app. 30%
Onboarding app. 1500 users from the municipalities
History/Background of the ATP ISIM Installation
ATP was converting the pension system from monolithic
(”Silos”) system to a SAP and WebSphere Portal based SOA
Architecture
ISIM (ITIM 4.5.1) was selected as the IdM Platform to automate
user lifecycle management in Q2 2005
Target goal for Security Administration was to keep same
number of headcounts despite additional systems
The system went live 1/1 2006 supporting Windows AD, 2 SAP
systems and TAM 5.1
HRFeed from SAP HR app. 1000 users
ATP ISIM Primary Focus
Automated Lifecycle Management
Fully automated on/off-boarding of employees/consultants via SAP HR
Identity Feed (HRFeed)
Manual Master for external users and technical accounts
All aspects of lifecycle and pasword management :
New Hire/
contract
registrered
Termination
Account
deletion
Graceperiod
Changes
Administration
of user
accounts
ATP ISIM Primary Focus (cont.)
Role Governance
All ATP Business Platform Roles 100% controlled
Roles modelled in top/down process to fit purpose
The role model is owned and maintained by the business owners
and implemented in ISIM by the Security Administration
Roles are recertified regularly
ATP Role Request Management
Intranet custom tool for requests (general system covering all
kinds of requests)
Requests for roles are routed to the Security Administration via
the Service Management tool (”Helpdesk”)
Request are managed by the Security Administration via the
ISIM console
The ATP ISIM Server Setup
ITDI
WAS
TIM application
TAM
Active
Directory
R/3
Provisioning
Provisioning
Provisioning
Person feed
HR extract
SAP XI
DB2
IDS
Adapter
for TAM
HR feed
Adapter
for SAP
Adapter for
Active
Directory
WEMB
(MQ)
R/3
Multiple Systems
Lotus
Domino
Adapter
for
Kerne
Provisioning
Adapter
for Notes
Provisioning
NAFS
Kerne
Adapter
for
KSPCICS
KSP
CICS
Provisioning
internet
ATP ISIM – Systems Managed
In Production 16 system managed
In Pilot 17 system managed
Production Pilot
Windows AD 1 (Windows AD 1 (non-functional system)
SAP NW (ABP) 9 SAP NW (ABP) 9
Custom "Kerne" (ABP) 3 Custom "Kerne" (ABP) 3
SAP XI 2
Lotus Notes 1 Lotus Notes 1 (non-functional system)
KSP CICS UDK 1
ITAM (ABP) 1 ITAM (ABP) 1
ITIM 3 ITIM 3
Important Customizations
Time Based Roles (managing roles with a start- and end-date)
AD Hybrid Management Model
Groups are managed ”hard” (RBAC model) if placed in specific AD
OUs
Groups outside these OUs are non-managed (can be managed
using Accesses)
Auto Create of AD groups (organization based groups)
Workflow for Management of Unauthorized Accounts
Accounts created outside ISIM are detected on reconciliation
Workflow locks account upon detection and triggers approval flow
Provisioning Policy report in CSV format (weekly via mail)
Migration/Synch tool to manage business objects
(Roles/Policies/Workflows etc.) between environments
(Development/Pilot/Prod)
ATP ISIM – History and Future
Original platform ITIM 32 bit version 4.5.1 2005/1/1
Migrated to ITIM 32 bit 4.6 2007/Q2
Migrated to ITIM 5.1 64 bit 2011/Q4
Upgrade to ISIM 6.0 planned for 2013
The UDK project
Agreement between the goverment and municipalities in
06/2010 to :
Centralize welfare payments into a new organization ”Udbetaling
Danmark” (UDK)
Uniform Processing
Saving target DKK 300 million/year
3 Waves starting 10/2012 covering app. 1500 users
ATP deliver Administrative systems support – e.g. IdM
3 new Systems (2 SAP NW + RACF/CICS via WS)
Public Certificate and other govermental systems
Role Governance based on organization and job role (based on
ATPs role governance model) – app. 50 roles
ATP ISIM System – Important Numbers
Users :
14638 Accounts
Roles :
621 Static and 86 Dynamic Roles (plus 50 UDK roles outside ISIM)
20938 Role assignements (403 Roles)
Policies
15 Identity Policies
2 Password Policies
12 Adoption Policies
906 Provisioning Policies
Employees 2273
Consultants 155
External 521
Technical 101
ATP ISIM System – Process Numbers
Process 2012/07 2012/08 2012/09 2012/10 2012/11 2012/12 2013/01 2013/02 2013/03 2013/04
Account Add 263 722 1460 1244 971 616 2230 2060 2478 450
Account Pwd
Chg
126 125 108 160 210 72 130 202 133 145
Account
Delete
385 183 267 274 374 245 474 370 605 460
Account
Modify
25089 26566 24712 23825 19281 19230 19230 11990 11215 11293
Account
Restore
81 141 358 792 297 460 204 1368 1953 176
Account
Suspend
345 256 191 269 362 361 549 315 574 289
Check
Policies
34989 38548 39333 38285 44803 45861 48413 60604 72459 68954
Person Add 44 148 304 141 2429 92 1309 4344 911 122
Person
Delete
67 36 45 42 63 47 68 63 116 68
Person
Modify
682 1859 3074 3338 2006 1729 2946 6689 2451 1084
Reconciliation 517 512 517 527 539 587 640 579 632 610
14
Questions

Contenu connexe

Similaire à IBM Security Identity Manager Onboards 1500 Users

Bhawani prasad data integration-ppt
Bhawani prasad data integration-pptBhawani prasad data integration-ppt
Bhawani prasad data integration-pptBhawani N Prasad
 
Data integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcuttaData integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcuttaBhawani N Prasad
 
Aspans Tech Pitch Book
Aspans Tech Pitch BookAspans Tech Pitch Book
Aspans Tech Pitch Bookkadyrsizov
 
Topic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdfTopic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdfluxasuhi
 
Business breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERPBusiness breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERPERPScan
 
Computerised accounting plus_one_chap_12_15_2
Computerised  accounting plus_one_chap_12_15_2Computerised  accounting plus_one_chap_12_15_2
Computerised accounting plus_one_chap_12_15_2Prasad Melattur
 
November 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDANovember 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDAJBug Italy
 
Solution Manager Deployment
Solution Manager DeploymentSolution Manager Deployment
Solution Manager DeploymentTony de Thomasis
 
IBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best PracticesIBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best PracticesRoland Merkt
 
WAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESAWAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESAillustrosystems
 
SAP Influence Council 2009
SAP Influence Council 2009SAP Influence Council 2009
SAP Influence Council 2009Tony de Thomasis
 
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017Jose Gascon
 
Ch2 v70 config_overview_en
Ch2 v70 config_overview_enCh2 v70 config_overview_en
Ch2 v70 config_overview_enconfidencial
 
Standard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM softwareStandard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM softwareAxios Systems
 

Similaire à IBM Security Identity Manager Onboards 1500 Users (20)

Bhawani prasad data integration-ppt
Bhawani prasad data integration-pptBhawani prasad data integration-ppt
Bhawani prasad data integration-ppt
 
Data integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcuttaData integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcutta
 
OG and Monitors
OG and MonitorsOG and Monitors
OG and Monitors
 
ABT / DSM System
ABT / DSM System ABT / DSM System
ABT / DSM System
 
Aspans Tech Pitch Book
Aspans Tech Pitch BookAspans Tech Pitch Book
Aspans Tech Pitch Book
 
Tally9erp
Tally9erpTally9erp
Tally9erp
 
Mis ppt level 2
Mis ppt level 2Mis ppt level 2
Mis ppt level 2
 
Mis ppt level 2
Mis ppt level 2Mis ppt level 2
Mis ppt level 2
 
Topic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdfTopic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdf
 
Business breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERPBusiness breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERP
 
Computerised accounting plus_one_chap_12_15_2
Computerised  accounting plus_one_chap_12_15_2Computerised  accounting plus_one_chap_12_15_2
Computerised accounting plus_one_chap_12_15_2
 
November 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDANovember 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDA
 
Solution Manager Deployment
Solution Manager DeploymentSolution Manager Deployment
Solution Manager Deployment
 
IBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best PracticesIBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best Practices
 
WAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESAWAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESA
 
SAP Influence Council 2009
SAP Influence Council 2009SAP Influence Council 2009
SAP Influence Council 2009
 
Network Operation Center
Network Operation CenterNetwork Operation Center
Network Operation Center
 
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
 
Ch2 v70 config_overview_en
Ch2 v70 config_overview_enCh2 v70 config_overview_en
Ch2 v70 config_overview_en
 
Standard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM softwareStandard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM software
 

Plus de IBM Danmark

DevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinleyDevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinleyIBM Danmark
 
Velkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia RønhøjVelkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia RønhøjIBM Danmark
 
Smarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-AndersenSmarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-AndersenIBM Danmark
 
Mobile, Philip Nyborg
Mobile, Philip NyborgMobile, Philip Nyborg
Mobile, Philip NyborgIBM Danmark
 
IT innovation, Kim Escherich
IT innovation, Kim EscherichIT innovation, Kim Escherich
IT innovation, Kim EscherichIBM Danmark
 
Echo.IT, Stefan K. Madsen
Echo.IT, Stefan K. MadsenEcho.IT, Stefan K. Madsen
Echo.IT, Stefan K. MadsenIBM Danmark
 
Big Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonBig Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonIBM Danmark
 
Social Business, Alice Bayer
Social Business, Alice BayerSocial Business, Alice Bayer
Social Business, Alice BayerIBM Danmark
 
Numascale Product IBM
Numascale Product IBMNumascale Product IBM
Numascale Product IBMIBM Danmark
 
Intel HPC Update
Intel HPC UpdateIntel HPC Update
Intel HPC UpdateIBM Danmark
 
IBM general parallel file system - introduction
IBM general parallel file system - introductionIBM general parallel file system - introduction
IBM general parallel file system - introductionIBM Danmark
 
NeXtScale HPC seminar
NeXtScale HPC seminarNeXtScale HPC seminar
NeXtScale HPC seminarIBM Danmark
 
Future of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian NielsenFuture of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian NielsenIBM Danmark
 
Future of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve SibleyFuture of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve SibleyIBM Danmark
 
Future of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren RavnFuture of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren RavnIBM Danmark
 
Future of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim MortensenFuture of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim MortensenIBM Danmark
 
Future of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik RexFuture of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik RexIBM Danmark
 
Future of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim EscherichFuture of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim EscherichIBM Danmark
 
Future of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-JensenFuture of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-JensenIBM Danmark
 

Plus de IBM Danmark (20)

DevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinleyDevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinley
 
Velkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia RønhøjVelkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia Rønhøj
 
Smarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-AndersenSmarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
 
Mobile, Philip Nyborg
Mobile, Philip NyborgMobile, Philip Nyborg
Mobile, Philip Nyborg
 
IT innovation, Kim Escherich
IT innovation, Kim EscherichIT innovation, Kim Escherich
IT innovation, Kim Escherich
 
Echo.IT, Stefan K. Madsen
Echo.IT, Stefan K. MadsenEcho.IT, Stefan K. Madsen
Echo.IT, Stefan K. Madsen
 
Big Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonBig Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter Jönsson
 
Social Business, Alice Bayer
Social Business, Alice BayerSocial Business, Alice Bayer
Social Business, Alice Bayer
 
Numascale Product IBM
Numascale Product IBMNumascale Product IBM
Numascale Product IBM
 
Mellanox IBM
Mellanox IBMMellanox IBM
Mellanox IBM
 
Intel HPC Update
Intel HPC UpdateIntel HPC Update
Intel HPC Update
 
IBM general parallel file system - introduction
IBM general parallel file system - introductionIBM general parallel file system - introduction
IBM general parallel file system - introduction
 
NeXtScale HPC seminar
NeXtScale HPC seminarNeXtScale HPC seminar
NeXtScale HPC seminar
 
Future of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian NielsenFuture of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian Nielsen
 
Future of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve SibleyFuture of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve Sibley
 
Future of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren RavnFuture of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren Ravn
 
Future of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim MortensenFuture of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim Mortensen
 
Future of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik RexFuture of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik Rex
 
Future of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim EscherichFuture of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim Escherich
 
Future of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-JensenFuture of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-Jensen
 

Dernier

The Evolution of Money: Digital Transformation and CBDCs in Central Banking
The Evolution of Money: Digital Transformation and CBDCs in Central BankingThe Evolution of Money: Digital Transformation and CBDCs in Central Banking
The Evolution of Money: Digital Transformation and CBDCs in Central BankingSelcen Ozturkcan
 
Google AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAGGoogle AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAGSujit Pal
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 

Dernier (20)

The Evolution of Money: Digital Transformation and CBDCs in Central Banking
The Evolution of Money: Digital Transformation and CBDCs in Central BankingThe Evolution of Money: Digital Transformation and CBDCs in Central Banking
The Evolution of Money: Digital Transformation and CBDCs in Central Banking
 
Google AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAGGoogle AI Hackathon: LLM based Evaluator for RAG
Google AI Hackathon: LLM based Evaluator for RAG
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 

IBM Security Identity Manager Onboards 1500 Users

  • 1. IBM Security Identity Manager at ATP Impact of On-boarding 1500 Users in a Highly Customized ISIM System
  • 2. About ATP The largest pension fund in Denmark managing public pensions schemes for 4.7 mill. persons Total assets worth of DKK 700+ billions (app USD 100+ billions) Generally regarded as one of the best performing pension funds world wide with a very high return rate and low cost. ATP has recently been appointed to take responsibility for most public welfare payments payouts (”Udbetaling Danmark”) Yearly payouts app. DKK 180 billions (app. USD 27 billions). Reducing the cost with app. 30% Onboarding app. 1500 users from the municipalities
  • 3. History/Background of the ATP ISIM Installation ATP was converting the pension system from monolithic (”Silos”) system to a SAP and WebSphere Portal based SOA Architecture ISIM (ITIM 4.5.1) was selected as the IdM Platform to automate user lifecycle management in Q2 2005 Target goal for Security Administration was to keep same number of headcounts despite additional systems The system went live 1/1 2006 supporting Windows AD, 2 SAP systems and TAM 5.1 HRFeed from SAP HR app. 1000 users
  • 4. ATP ISIM Primary Focus Automated Lifecycle Management Fully automated on/off-boarding of employees/consultants via SAP HR Identity Feed (HRFeed) Manual Master for external users and technical accounts All aspects of lifecycle and pasword management : New Hire/ contract registrered Termination Account deletion Graceperiod Changes Administration of user accounts
  • 5. ATP ISIM Primary Focus (cont.) Role Governance All ATP Business Platform Roles 100% controlled Roles modelled in top/down process to fit purpose The role model is owned and maintained by the business owners and implemented in ISIM by the Security Administration Roles are recertified regularly
  • 6. ATP Role Request Management Intranet custom tool for requests (general system covering all kinds of requests) Requests for roles are routed to the Security Administration via the Service Management tool (”Helpdesk”) Request are managed by the Security Administration via the ISIM console
  • 7. The ATP ISIM Server Setup ITDI WAS TIM application TAM Active Directory R/3 Provisioning Provisioning Provisioning Person feed HR extract SAP XI DB2 IDS Adapter for TAM HR feed Adapter for SAP Adapter for Active Directory WEMB (MQ) R/3 Multiple Systems Lotus Domino Adapter for Kerne Provisioning Adapter for Notes Provisioning NAFS Kerne Adapter for KSPCICS KSP CICS Provisioning internet
  • 8. ATP ISIM – Systems Managed In Production 16 system managed In Pilot 17 system managed Production Pilot Windows AD 1 (Windows AD 1 (non-functional system) SAP NW (ABP) 9 SAP NW (ABP) 9 Custom "Kerne" (ABP) 3 Custom "Kerne" (ABP) 3 SAP XI 2 Lotus Notes 1 Lotus Notes 1 (non-functional system) KSP CICS UDK 1 ITAM (ABP) 1 ITAM (ABP) 1 ITIM 3 ITIM 3
  • 9. Important Customizations Time Based Roles (managing roles with a start- and end-date) AD Hybrid Management Model Groups are managed ”hard” (RBAC model) if placed in specific AD OUs Groups outside these OUs are non-managed (can be managed using Accesses) Auto Create of AD groups (organization based groups) Workflow for Management of Unauthorized Accounts Accounts created outside ISIM are detected on reconciliation Workflow locks account upon detection and triggers approval flow Provisioning Policy report in CSV format (weekly via mail) Migration/Synch tool to manage business objects (Roles/Policies/Workflows etc.) between environments (Development/Pilot/Prod)
  • 10. ATP ISIM – History and Future Original platform ITIM 32 bit version 4.5.1 2005/1/1 Migrated to ITIM 32 bit 4.6 2007/Q2 Migrated to ITIM 5.1 64 bit 2011/Q4 Upgrade to ISIM 6.0 planned for 2013
  • 11. The UDK project Agreement between the goverment and municipalities in 06/2010 to : Centralize welfare payments into a new organization ”Udbetaling Danmark” (UDK) Uniform Processing Saving target DKK 300 million/year 3 Waves starting 10/2012 covering app. 1500 users ATP deliver Administrative systems support – e.g. IdM 3 new Systems (2 SAP NW + RACF/CICS via WS) Public Certificate and other govermental systems Role Governance based on organization and job role (based on ATPs role governance model) – app. 50 roles
  • 12. ATP ISIM System – Important Numbers Users : 14638 Accounts Roles : 621 Static and 86 Dynamic Roles (plus 50 UDK roles outside ISIM) 20938 Role assignements (403 Roles) Policies 15 Identity Policies 2 Password Policies 12 Adoption Policies 906 Provisioning Policies Employees 2273 Consultants 155 External 521 Technical 101
  • 13. ATP ISIM System – Process Numbers Process 2012/07 2012/08 2012/09 2012/10 2012/11 2012/12 2013/01 2013/02 2013/03 2013/04 Account Add 263 722 1460 1244 971 616 2230 2060 2478 450 Account Pwd Chg 126 125 108 160 210 72 130 202 133 145 Account Delete 385 183 267 274 374 245 474 370 605 460 Account Modify 25089 26566 24712 23825 19281 19230 19230 11990 11215 11293 Account Restore 81 141 358 792 297 460 204 1368 1953 176 Account Suspend 345 256 191 269 362 361 549 315 574 289 Check Policies 34989 38548 39333 38285 44803 45861 48413 60604 72459 68954 Person Add 44 148 304 141 2429 92 1309 4344 911 122 Person Delete 67 36 45 42 63 47 68 63 116 68 Person Modify 682 1859 3074 3338 2006 1729 2946 6689 2451 1084 Reconciliation 517 512 517 527 539 587 640 579 632 610