Monday, November 10, 2008

IAM Architectures

Organization strategy for IAM

  1. Make it a part of Enterprise Architecture (EA)
  2. Establish Security Architecture Governance function
  3. Oversight and Review
  4. Subcommittee of EA team
  5. Consider tactical security architecture team
  6. Corporate and Business User staff
  7. Drives development and implementation of information security architecture (ISA) into the business and IT
  8. Focus on relationship building
  9. Integrate with development lifecycle
  10. AuthZ, AuthN protocols are adhered to
  11. Unify CAS, Security, Identity, roles, and priv access
Also identify 'weak' spots in existing EA and call them out, bolster by modeling IAM specific artifacts. Trace back EA/IAM to business requirements

Consider Gartner's IAM Maturity Curve - self assessment or externally lead.

No comments: