Monday, August 23, 2010
A flying start with Role Based Access Control (RBAC)
RBAC is one of the possible ways to solve this problem. RBAC consists of a matrix of roles, functions and specific access rights. For example, if a new employee joins the organization, utilizing the RBAC matrix determines what the new employee will be allowed to do in the network. That's the theory. In practice it appears the population of such a matrix brings many problems. Because people often feel their needs are one of a kind, this often leads to as many roles as there are employees. Ultimately, that results in an infinite and unworkable matrix. Companies are therefore afraid to implement RBAC within their organization. However, there are organizations that get started and strive to get 100 percent of the employees in the RBAC matrix. I think this is improbable and may takes years of both management’s and the Security Officer’s time to implement.
Want a quick start with RBAC? It is quite feasible if you do not target 100 percent in the first instance. Based on information from the HR system, it is possible to explore the 50 most common combinations of departments and functions within the organization. This allows the completion of up to 80 percent of the RBAC matrix immediately - . all within a few days! Then, a workflow application can be used to fill using the remaining 20 percent - manually entered by the manager of an employee.
It may be years before the RBAC matrix is completed 100 percent, but by incorporating existing systems and sources - such as the HR system - and the focus of the manager - the population of the RBAC matrix is a manageable process with direct result. The result is a positive ROI with respect to the feasibility of RBAC and the amount of effort required to enforce positive IT auditing standards. An indirect benefit is often a reduction of licensing costs, storage requirements and security incidents.
How to deal with Role Based Access Control (RBAC) in relation to Identity Management
Monday, June 1, 2009
Second of a series
A 6,500 employee company that provides professional services and technology solutions in energy and climate change to government and commercial clients had a problem. The scripts that they relied on to manage accounts in Active Directory, based on twice daily PeopleSoft dumps, were becoming tedious to maintain and with the imminent departure of the head programmer, an off the shelf solution became imperative.
The details of the requirements were quickly relayed and a proof of concept was established in the client’s environment. Basically the information from PeopleSoft was utilized to implement account lifecycle management for employees while web forms were created to manage contractors. Employees needed an Active Directory account, Exchange 2007 mailbox, a base set of group memberships, and the proper OU container, were to be based on location codes. Approximately 10 attributes including office address and phone number need to be set as well.
As information in the file changes, such as location or specific attributes, the AD account needed to be updated and if necessary, re-provisioned with new groups and moved to a different OU. If the terminate date field was set in PeopleSoft, the account needed to be disabled, hidden form the GAL and moved to a specific OU. Every time an account is created, modified or disabled, an export file is generated by User Management to feed back relevant data to PeopleSoft.
While the automated process easily handled the direct employees, the company also had a large population of contractors that were never entered into PeopleSoft. To address this, web forms were created and deployed to hiring managers. The form contained the fields necessary to create an AD and, if required, Exchange mailbox. All contractor accounts are set to expire after 90 days and the hiring manager is notified 2 weeks before account expiration. A second form is available to allow the manager to easily extend the timeframe. If no action is taken, the account is disabled automatically and the hiring manager is again notified.
All told, the implementation of both the automated process and the web forms required about 3-4 days of work by a Tools4ever consultant. After through testing, the product was tolled out company wide. As an added benefit, the customer was able to implement Tools4ever’s Self Service Reset Password Manager to reduce the most common call to the help desk.
Friday, May 8, 2009
Group Management and Auditing
The first situation I would like to discuss involves a medium-sized financial institution located in the northeast. When they approached us, they were in need of a web-based system for group management compliance auditing. Every 90 days, they required managers to sign off a paper report indicating the members of distribution and security groups they managed were accurate. Obviously, the shortfalls were many. When the paper was returned, IT admins need to go into Active Directory and make edits as required. Other times managers simply ignored the paper work leaving potential security breaches.
After a thorough analysis of the requirements, we presented a solution that delivered what the client was looking for and also provided suggestions on how to expand the use of the product. A decision to move ahead was made by the client and we set about delivering a proof of concept, at no risk, to prove the capabilities.
In the end, the client was satisfied with the proof of concept and purchased the solution. Basically, the end result provided the following:
For Managers
- Automated email notification to managers that a review of their groups was pending.
- A website to allow managers to view all of their groups and the members thereof.
- The ability to add / remove individuals from each group as appropriate.
- The ability to electronically sign off on the accuracy.
- Consolidated reporting on who has/ has not verified the groups
- Automatic escalation procedure when a review has not occurred within a defined timeframe. (15, 30 and 60 days)
- A portal to provide easy modification of group ownership when a manger departed.
- Ability to maintain white lists of groups that should never need verification.
- An easy method to view what groups they belong to.
- Ability to request membership in other groups (requires managerial / IT approval)