SlideShare une entreprise Scribd logo
1  sur  34
Télécharger pour lire hors ligne
Courtesy of InfraMatix 
http://www.IDMChecklist.com 
The 4 Web Access Management Problems that Lead to Regulatory Fines
The legislation reads, in part, that a company must verify 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
“…company transactions are properly authorized, recorded, and reported according 
to GAAP, and that assets 
are safeguarded from unauthorized use.” 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
The optimal word here is “authorized” 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Web access management tools, like Oracle Access Manager or CA Single Sign-On, check two items: 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Credentials 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Credentials are the user ID 
and password 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Authorization 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Authorization is the process 
of checking the user for 
proper authority to access 
the application 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
In identity management (IDM) systems, this authorization 
is usually driven by “roles” 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Roles are an abstraction 
that sets the attributes, groups, and DN (Distinguished Name) of the user in LDAP (Lightweight Directory Access Protocol) 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
or Active Directory 
(e.g., title=VP; cn=banking; ou=operations, dc=company, dc=com) 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Web Access Management Mistakes 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
There are two general areas where a single sign-on, 
web access system can 
go wrong with regards 
to granting access: 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
(1)problems in the access management tool itself 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
(2) problems with user provisioning 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Replication and Sync Issues 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
In a high-availability environment, the web access manager load balances between LDAP or Active Directory user stores 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
These can have latency issues with replication 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
A change made in one server might not make it to another server for several hours 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Offboarding 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Any technical or procedural problems with the IDM system will leave people with access they should not have 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Lack of a Common Approach 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
When the web access manager is responsible for authorization, 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
risks can be prevented unless the policies in the access manager are driven by roles granted by an IDM system 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Proprietary Provisioning 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
If the web access manager handles authorization for those, then these ERP systems need 
to replicate the roles in those systems to the common 
user store 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Bottom Line 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
The take away message here 
is that a web access management system should 
be coupled with some kind of IDM system in order to reduce 
the kinds of errors listed above 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
and, ultimately, regulatory fines 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
This gives one system control over the data used as the source for web access management 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
What is yourexperience 
with web access 
management products? 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Please share yourthought 
in the Comments box below. 
Sponsored by http://www.IDMChecklist.com 
Veera Sandiparthi Founder of InfraMatix
Copyright © InfraMatix 
Is Your Company Adequately Protected from Security Risks? 
Download the Free 8 Point Identity Management Checklist Now at http://www.IDMChecklist.com

Contenu connexe

Dernier

DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxLoriGlavin3
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionDilum Bandara
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024Stephanie Beckett
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfPrecisely
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxBkGupta21
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024Lonnie McRorey
 

Dernier (20)

DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptxThe Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
The Fit for Passkeys for Employee and Consumer Sign-ins: FIDO Paris Seminar.pptx
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Advanced Computer Architecture – An Introduction
Advanced Computer Architecture – An IntroductionAdvanced Computer Architecture – An Introduction
Advanced Computer Architecture – An Introduction
 
What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024What's New in Teams Calling, Meetings and Devices March 2024
What's New in Teams Calling, Meetings and Devices March 2024
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdfHyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
Hyperautomation and AI/ML: A Strategy for Digital Transformation Success.pdf
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
unit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptxunit 4 immunoblotting technique complete.pptx
unit 4 immunoblotting technique complete.pptx
 
How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024TeamStation AI System Report LATAM IT Salaries 2024
TeamStation AI System Report LATAM IT Salaries 2024
 

En vedette

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by HubspotMarius Sescu
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 

En vedette (20)

2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot2024 State of Marketing Report – by Hubspot
2024 State of Marketing Report – by Hubspot
 
Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 

The 4 Web Access Management Problems that Lead to Regulatory Fines (SlideShare)

  • 1. Courtesy of InfraMatix http://www.IDMChecklist.com The 4 Web Access Management Problems that Lead to Regulatory Fines
  • 2. The legislation reads, in part, that a company must verify Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 3. “…company transactions are properly authorized, recorded, and reported according to GAAP, and that assets are safeguarded from unauthorized use.” Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 4. The optimal word here is “authorized” Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 5. Web access management tools, like Oracle Access Manager or CA Single Sign-On, check two items: Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 6. Credentials Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 7. Credentials are the user ID and password Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 8. Authorization Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 9. Authorization is the process of checking the user for proper authority to access the application Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 10. In identity management (IDM) systems, this authorization is usually driven by “roles” Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 11. Roles are an abstraction that sets the attributes, groups, and DN (Distinguished Name) of the user in LDAP (Lightweight Directory Access Protocol) Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 12. or Active Directory (e.g., title=VP; cn=banking; ou=operations, dc=company, dc=com) Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 13. Web Access Management Mistakes Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 14. There are two general areas where a single sign-on, web access system can go wrong with regards to granting access: Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 15. (1)problems in the access management tool itself Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 16. (2) problems with user provisioning Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 17. Replication and Sync Issues Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 18. In a high-availability environment, the web access manager load balances between LDAP or Active Directory user stores Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 19. These can have latency issues with replication Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 20. A change made in one server might not make it to another server for several hours Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 21. Offboarding Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 22. Any technical or procedural problems with the IDM system will leave people with access they should not have Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 23. Lack of a Common Approach Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 24. When the web access manager is responsible for authorization, Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 25. risks can be prevented unless the policies in the access manager are driven by roles granted by an IDM system Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 26. Proprietary Provisioning Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 27. If the web access manager handles authorization for those, then these ERP systems need to replicate the roles in those systems to the common user store Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 28. Bottom Line Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 29. The take away message here is that a web access management system should be coupled with some kind of IDM system in order to reduce the kinds of errors listed above Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 30. and, ultimately, regulatory fines Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 31. This gives one system control over the data used as the source for web access management Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 32. What is yourexperience with web access management products? Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 33. Please share yourthought in the Comments box below. Sponsored by http://www.IDMChecklist.com Veera Sandiparthi Founder of InfraMatix
  • 34. Copyright © InfraMatix Is Your Company Adequately Protected from Security Risks? Download the Free 8 Point Identity Management Checklist Now at http://www.IDMChecklist.com