Monday, September 28, 2009

Common problems with ID&AM projects

Following list mentions most commonly seen issues with IAM related projects –
1)Foggy technology road map
Envision is key of good technology road map to provide a smooth ride to IT services. IT architects of a company need to realize relevance of ID&AM services into overall enterprise architecture. ID&AM is not just about buying an identity and access management tool to provision accounts to few systems. It is important to define one authentication and authorization layer and one Identity management services layers and more important is to publish a direction in where most of the application use services provided by ID&AM components. I have seen company buying costly IDM suit but not leveraging full potential of it.
2) More focus towards technology
An Identity playing a specific role in an organization has access to specific resources and is authorize to do defined business operations. ID&AM is more about defining a process based on the business requirement which controls the link between Identity, Access and authorization. On contrary ID&AM team is more focused towards technology than business and process aspect of the IAM. It might result in failure of the project as it does not meet business requirements.
3) Incorrect tool selection
It is very important to select a right identity and access management solution which suits both functional and technology needs of an enterprise. On functional part ID&AM solution controls life cycle of business entities (like provisioning of accounts/access, grant/restrict access based on profile, de-provisioning etc.), access governance based on business policies, roles and entitlements. On technology part, in order to manage identity and access of all the entities in an organization, ID&AM components need to integrate with desperate end system. So evaluation of a ID&AM solution becomes very important to make it can meet business needs and integrates with most of proprietary systems in an organization.
4) Identity Islands
In a traditional enterprise design every application maintain a separate identity store for the users of the application. It result into creation of duplicate identity information and increase the access point for the availability of user sensitive information. By introducing the ID&AM architecture it should target to reduce the identity stores across enterprise and provide centralized access and policy management platform. It usually require very strong selling to provide a strategic solution to remove authentication layer from legacy applications and introducing common access management layer.
5) Leadership support
For success of any ID&AM project it is very important to buy confidence of higher leadership in the organization.

No comments:

Post a Comment