May 10, 2020 9:32:47 AM EDT | Blog Entitlement Review Blackout

Learn how to overcome the challenge of end users not responding to entitlement reviews in IAM systems. Find out how SPHEREboard can help improve data quality and streamline workflows. Contact us for more information.

A simple yet critical issue exists in the realm of Identity and Access Management (IAM): end users do not respond to their entitlement reviews.
 

IT Security and Infrastructure teams deploy sophisticated IAM systems like SailPoint and invest in aging homegrown solutions to confirm identity. Despite these investments, IT managers continue to struggle to get their end-users to engage with these systems and complete the necessary surveys.

The irony lies in the fact that upper management knows people can’t or won’t make decisions about who should have access to the systems. It is entirely up to the lines of business to make these calls. Yet, no matter how logical the explanation is, the business always pushes back. Why is that?

There are many great solutions in the IAM ecosystem designed to handle the workflows IT organizations require for certifying access, including scheduled entitlement reviews and on-the-fly account recertifications. These solutions come with all the features an administrator could need—pretty email templates, escalation processes, automated provisioning, and role concepts, to name a few.

However, despite all this functionality, there is one major problem these IAM systems can’t overcome: Bad Data In = Bad Data Out. An application is only as good as the data it receives.

These applications work as designed when supplied with clean, pristine, and refreshed raw data. But ingesting quality data is a significant challenge for any complex system and those who manage them. Unfortunately, data quality is mostly out of their control.

Most IAM tools pull user data from Active Directory, which may be managed by another group. Permissions, ownership, and data structure are complicated, come from many disparate sources, and aren’t provided in a pre-configured package that is easily uploaded and displayed to business users.

The Reality

To be effective, there needs to be a solution wedged between the source systems and the desired end-state IAM workflows.

SPHEREboard collects data from the source systems first; this is what we call our IAM Views solution.

There are Three Ways of Retrieving the Data:

  1. Directly from the Source System: For example, if you want group drives included in your entitlement reviews, we will use our NetApp connector to grab entitlements and any other relevant metadata.
  2. Using an Existing Solution: For example, if you want local admin accounts included in your access certification processes, use our Tanium connector that’s already collecting that data.
  3. Uploading the Files: For example, if you want your SOX apps reviewed quarterly, use our File Listener and File Ingestor to configure it to wait for your apps to drop files to a certain location (we set that up too!) and upload them into the system.

Getting the data from the sources is just the start, as referential and contextual data are extremely important to any recertification or entitlement project. IAM workflows always require accurate ownership. The owners are the business people who will have to certify access. The reality is most companies have incomplete ownership catalogs and, very often, conflicting information.

Where We Provide Value

We perform common-sense checks first. Is the listed owner still at the company? Additionally, when an owner cannot be found, we leverage a host of proprietary methodologies and algorithms behind the scenes to fill in the gaps automatically.

Finally, data needs to be normalized, and the presentation layer must be addressed. For example, if you want group drives certified by the data owner, including every folder and file in the review is impractical. It’s too much data to consume rationally.

Instead, we devised the concept of Collections. Our approach groups folders based on usage, naming standards, permissions, etc. This helps quantify the number of people who need to be contacted to validate ownership effectively. We identify just the folder paths that are meaningful to the data owners and provide metrics on the entire data set. Equally important, the same normalization must occur for any other asset in the environment. This step should not be underestimated.

Packaging the Data

The final product from us is our IAM views. All the information and analysis SPHEREboard conducts with entitlements, ownership, and any additional data is placed into pre-defined tables that the IAM workflow system consumes.

These tables are regularly refreshed, ensuring data quality is up-to-date. Now, business users see entitlement data that makes sense and can provide relevant feedback to the business as intended.

Contact us for more information about how we can help you with your entitlement reviews 

Rita Gurevich

Written By: Rita Gurevich

Rita Gurevich is the CEO and founder of SPHERE, a leading identity hygiene company redefining how organizations achieve access controls across their environment. Rita began her career at Lehman Brothers where she oversaw the distribution of technology assets after the organization’s bankruptcy in 2008. From this, Rita gained a deep understanding of analyzing identities, data platforms, and the overall application and system landscape distributed across buying entities. The enhanced regulatory environment aimed at protecting data from misuse concurrently forced large enterprises to more proactively manage and control access across their on-premises and cloud environments. With this knowledge, Gurevich founded SPHERE, an organization that provides critical governance, security, and compliance solutions centered around the expanding access control issues plaguing organizations. The company has developed a repeatable and effective approach to assessing, remediating, and managing access controls across any scope. Rita has driven the growth of SPHERE through its evolution to a cutting-edge software company that also provides services to clients with the only end-to-end access management solution available today. Gurevich is the recipient of multiple honors and awards including recognition from Ernst & Young for her entrepreneurial skills, SmartCEO, 40 Under 40, and many more.