Introduction: The Framework of Trust
In Lessons 6.1 through 6.4, we established the foundations of Identity and Access Management (IAM), explored authentication mechanisms, analyzed authorization and access control models, and examined Privileged Access Management (PAM). We examined the core IAM concepts, the identity lifecycle, authentication factors, MFA, biometrics, certificates, RBAC, ABAC, DAC, MAC, and PAM. Each of these components contributes to managing digital identities and controlling access to resources.
However, effective IAM requires more than just technology and controls. It requires a comprehensive framework of governance, oversight, and administration. This is the domain of Identity Governance and Administration (IGA) .
Identity Governance and Administration (IGA) is the practice of managing the lifecycle of digital identities, governing access rights, and ensuring compliance with policies and regulations. It encompasses the processes, tools, and controls used to manage identities, entitlements, access certifications, and compliance reporting.
In financial institutions, IGA is of paramount importance because it:
-
Ensures Compliance: Meeting regulatory requirements for access control (GLBA, SOX, GDPR, NYDFS, PCI DSS).
-
Manages Risk: Identifying and mitigating access-related risks.
-
Enforces Policy: Ensuring that access policies are consistently enforced.
-
Provides Visibility: Providing visibility into who has access to what resources.
-
Enables Auditing: Supporting internal and external audits.
This lesson provides a comprehensive analysis of Identity Governance and Administration for financial institutions. We begin by examining the IGA Components: Identity Lifecycle Management, Access Certification, Policy Management, and Compliance Reporting. We derive the IGA Maturity Score: I_GM = L_ifeycle * C_ertification * P_olicy * C_ompliance.
We then examine Identity Lifecycle Management, including identity creation, maintenance, and deprovisioning. We derive the Identity Lifecycle Management Score: I_LM = C_reation * M_aintenance * D_eprovisioning.
We also examine Access Certification, including user access reviews, role certifications, and entitlement certifications. We derive the Access Certification Score: A_CS = C_overage * A_ccuracy * T_imeliness.
We also examine Policy Management for IGA, including policy definition, enforcement, and monitoring. We derive the Policy Management Score: P_MS = D_efinition * E_nforcement * M_onitoring.
Finally, we examine Compliance Reporting for IGA, including regulatory compliance, audit reporting, and executive reporting. We derive the Compliance Reporting Score: C_RS = R_egulatory * A_udit * E_xecutive.
By the end, you will have a complete understanding of Identity Governance and Administration, and be able to design and implement IGA programs for financial institutions.
Learning Objectives
Upon completion of this lesson, you will be able to:
-
Analyze the IGA Components: Identity Lifecycle Management, Access Certification, Policy Management, and Compliance Reporting.
-
Derive the IGA Maturity Score:
I_GM = L_ifeycle * C_ertification * P_olicy * C_ompliance. -
Analyze Identity Lifecycle Management: Creation, maintenance, and deprovisioning.
-
Derive the Identity Lifecycle Management Score:
I_LM = C_reation * M_aintenance * D_eprovisioning. -
Analyze Access Certification: User access reviews, role certifications, and entitlement certifications.
-
Derive the Access Certification Score:
A_CS = C_overage * A_ccuracy * T_imeliness. -
Analyze Policy Management: Definition, enforcement, and monitoring.
-
Derive the Policy Management Score:
P_MS = D_efinition * E_nforcement * M_onitoring. -
Analyze Compliance Reporting: Regulatory, audit, and executive reporting.
-
Derive the Compliance Reporting Score:
C_RS = R_egulatory * A_udit * E_xecutive.
Part 1: IGA Components
1.1 The IGA Definition
Identity Governance and Administration (IGA) is the practice of managing the lifecycle of digital identities, governing access rights, and ensuring compliance.
IGA = {Lifecycle Management, Access Certification, Policy Management, Compliance Reporting}
1.2 The Four IGA Pillars
| Pillar | Description | Key Activities |
|---|---|---|
| Identity Lifecycle Management | Managing identity lifecycle | Creation, maintenance, deprovisioning |
| Access Certification | Certifying access rights | User access reviews, role certifications |
| Policy Management | Managing access policies | Policy definition, enforcement, monitoring |
| Compliance Reporting | Reporting on compliance | Regulatory, audit, executive reporting |
1.3 The IGA Maturity Score
The IGA Maturity Score quantifies the maturity of IGA:
I_GM = L_ifeycle * C_ertification * P_olicy * C_ompliance
Where:
-
L_ifeycleis the Lifecycle Score (0-1) -
C_ertificationis the Certification Score (0-1) -
P_olicyis the Policy Score (0-1) -
C_omplianceis the Compliance Score (0-1)
| Component | Description | Scoring Factors |
|---|---|---|
| Lifecycle (L) | Quality of identity lifecycle management | Creation, maintenance, deprovisioning |
| Certification (C) | Quality of access certification | Coverage, accuracy, timeliness |
| Policy (P) | Quality of policy management | Definition, enforcement, monitoring |
| Compliance (C) | Quality of compliance reporting | Regulatory, audit, executive |
IGA Components (Visual): ┌─────────────────────────────────────────────────────────────────────────┐ | | | ╔═══════════════════════════════════════════════════════════════════╗ | | ║ Identity Lifecycle Management ║ | | ╠═══════════════════════════════════════════════════════════════════╣ | | ║ • Identity Creation ║ | | ║ • Identity Maintenance ║ | | ║ • Identity Deprovisioning ║ | | ║ • Key Activities: Provisioning, updates, revocation ║ | | ╚═══════════════════════════════════════════════════════════════════╝ | | | | ╔═══════════════════════════════════════════════════════════════════╗ | | ║ Access Certification ║ | | ╠═══════════════════════════════════════════════════════════════════╣ | | ║ • User Access Reviews ║ | | ║ • Role Certifications ║ | | ║ • Entitlement Certifications ║ | | ║ • Key Activities: Review, certify, remediate ║ | | ╚═══════════════════════════════════════════════════════════════════╝ | | | | ╔═══════════════════════════════════════════════════════════════════╗ | | ║ Policy Management ║ | | ╠═══════════════════════════════════════════════════════════════════╣ | | ║ • Policy Definition ║ | | ║ • Policy Enforcement ║ | | ║ • Policy Monitoring ║ | | ║ • Key Activities: Create, enforce, monitor ║ | | ╚═══════════════════════════════════════════════════════════════════╝ | | | | ╔═══════════════════════════════════════════════════════════════════╗ | | ║ Compliance Reporting ║ | | ╠═══════════════════════════════════════════════════════════════════╣ | | ║ • Regulatory Reporting ║ | | ║ • Audit Reporting ║ | | ║ • Executive Reporting ║ | | ║ • Key Activities: Generate, review, submit ║ | | ╚═══════════════════════════════════════════════════════════════════╝ | | | | Formula: I_GM = L_ifeycle * C_ertification * P_olicy * C_ompliance │ └─────────────────────────────────────────────────────────────────────────┘
Part 2: Identity Lifecycle Management
2.1 The Lifecycle Definition
Identity lifecycle management is the process of managing identities from creation to deprovisioning.
Identity Lifecycle = {Creation, Maintenance, Deprovisioning}
2.2 Identity Creation
Definition: Identity creation is the process of creating a new digital identity.
Identity Creation = {Identity Generation, Attribute Assignment, Account Provisioning}
Creation Activities:
| Activity | Description | Security Considerations |
|---|---|---|
| Identity Generation | Creating the identity | Unique identifiers, generation process |
| Attribute Assignment | Assigning attributes | Accuracy, completeness |
| Account Provisioning | Creating accounts | Account creation, access assignment |
2.3 Identity Maintenance
Definition: Identity maintenance is the ongoing management of identities and access.
Identity Maintenance = {Attribute Updates, Access Updates, Monitoring}
Maintenance Activities:
| Activity | Description | Frequency |
|---|---|---|
| Attribute Updates | Updating identity attributes | As needed |
| Access Updates | Updating access rights | As needed |
| Role Changes | Changing roles and permissions | As needed |
| Password Management | Password changes, resets | Ongoing |
| Monitoring | Monitoring for anomalies | Continuous |
2.4 Identity Deprovisioning
Definition: Identity deprovisioning is the process of revoking access and removing identities.
Identity Deprovisioning = {Access Revocation, Account Deletion, Data Destruction}
Deprovisioning Activities:
| Activity | Description | Security Considerations |
|---|---|---|
| Access Revocation | Revoking all access | Timely revocation |
| Account Deletion | Deleting accounts | Complete deletion |
| Data Destruction | Destroying identity data | Secure destruction |
| Verification | Verifying deprovisioning is complete | Audit trail |
2.5 The Identity Lifecycle Management Score
The Identity Lifecycle Management Score quantifies the effectiveness of identity lifecycle management:
I_LM = C_reation * M_aintenance * D_eprovisioning
Where:
-
C_reationis the Creation Score (0-1) -
M_aintenanceis the Maintenance Score (0-1) -
D_eprovisioningis the Deprovisioning Score (0-1)
| Component | Description | Scoring Factors |
|---|---|---|
| Creation (C) | Quality of identity creation | Accuracy, completeness, security |
| Maintenance (M) | Quality of identity maintenance | Timeliness, accuracy, monitoring |
| Deprovisioning (D) | Quality of deprovisioning | Timeliness, completeness, security |
Identity Lifecycle Management (Visual): ┌─────────────────────────────────────────────────────────────────────────┐ | | | Identity Creation │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Identity Generation │ │ | │ • Attribute Assignment │ │ | │ • Account Provisioning │ │ | │ • Security: Unique identifiers, accurate attributes │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Identity Maintenance │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Attribute Updates │ │ | │ • Access Updates │ │ | │ • Role Changes │ │ | │ • Password Management │ │ | │ • Monitoring │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Identity Deprovisioning │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Access Revocation │ │ | │ • Account Deletion │ │ | │ • Data Destruction │ │ | │ • Verification │ │ | │ • Security: Timely revocation, complete deletion │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Formula: I_LM = C_reation * M_aintenance * D_eprovisioning │ └─────────────────────────────────────────────────────────────────────────┘
Part 3: Access Certification
3.1 The Access Certification Definition
Access certification is the process of reviewing and certifying access rights.
Access Certification = {User Access Reviews, Role Certifications, Entitlement Certifications}
3.2 Access Certification Types
| Type | Description | Frequency |
|---|---|---|
| User Access Reviews | Reviewing user access rights | Quarterly/Annually |
| Role Certifications | Certifying role assignments | Annually |
| Entitlement Certifications | Certifying entitlements | Annually |
| Privileged Access Reviews | Reviewing privileged access | Quarterly |
3.3 Access Certification Process
| Step | Description | Key Activities |
|---|---|---|
| 1. Planning | Plan the certification | Define scope, schedule |
| 2. Data Collection | Collect access data | Data gathering, preparation |
| 3. Review | Review access rights | Reviewer review, investigation |
| 4. Certification | Certify access | Certify, revoke, modify |
| 5. Remediation | Remediate issues | Remove access, modify permissions |
| 6. Reporting | Generate reports | Certification reports, audit trails |
3.4 The Access Certification Score
The Access Certification Score quantifies the effectiveness of access certification:
A_CS = C_overage * A_ccuracy * T_imeliness
Where:
-
C_overageis the Coverage Score (0-1) -
A_ccuracyis the Accuracy Score (0-1) -
T_imelinessis the Timeliness Score (0-1)
| Component | Description | Scoring Factors |
|---|---|---|
| Coverage (C) | Coverage of access certification | Users, roles, entitlements |
| Accuracy (A) | Accuracy of certification | Correctness, completeness |
| Timeliness (T) | Timeliness of certification | Frequency, deadlines |
Access Certification Process (Visual): ┌─────────────────────────────────────────────────────────────────────────┐ | | | Step 1: Planning │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Define scope │ │ | │ • Schedule certification │ │ | │ • Identify reviewers │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Step 2: Data Collection │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Gather access data │ │ | │ • Prepare data for review │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Step 3: Review │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Review access rights │ │ | │ • Investigate exceptions │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Step 4: Certification │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Certify access │ │ | │ • Revoke or modify access │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Step 5: Remediation │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Remove unauthorized access │ │ | │ • Modify permissions │ │ | └────────────────────────┬────────────────────────────────────────┘ │ | │ | | ▼ | | Step 6: Reporting │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Generate reports │ │ | │ • Audit trails │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Formula: A_CS = C_overage * A_ccuracy * T_imeliness │ └─────────────────────────────────────────────────────────────────────────┘
Part 4: Policy Management
4.1 The Policy Management Definition
Policy management is the process of defining, enforcing, and monitoring access policies.
Policy Management = {Definition, Enforcement, Monitoring}
4.2 Policy Types
| Policy Type | Description | Examples |
|---|---|---|
| Access Policies | Policies governing access | Least privilege, separation of duties |
| Identity Policies | Policies governing identity | Identity verification, authentication |
| Compliance Policies | Policies governing compliance | Regulatory compliance, audit |
| Security Policies | Policies governing security | Password policies, MFA |
4.3 Policy Definition
Definition: Policy definition is the process of creating and documenting policies.
Policy Definition = {Policy Creation, Policy Documentation, Policy Approval}
4.4 Policy Enforcement
Definition: Policy enforcement is the process of ensuring policies are followed.
Policy Enforcement = {Policy Implementation, Policy Monitoring, Policy Compliance}
4.5 Policy Monitoring
Definition: Policy monitoring is the process of monitoring policy compliance.
Policy Monitoring = {Policy Compliance Monitoring, Policy Exception Management, Policy Reporting}
4.6 The Policy Management Score
The Policy Management Score quantifies the effectiveness of policy management:
P_MS = D_efinition * E_nforcement * M_onitoring
Where:
-
D_efinitionis the Definition Score (0-1) -
E_nforcementis the Enforcement Score (0-1) -
M_onitoringis the Monitoring Score (0-1)
| Component | Description | Scoring Factors |
|---|---|---|
| Definition (D) | Quality of policy definition | Clarity, completeness, approval |
| Enforcement (E) | Quality of policy enforcement | Implementation, monitoring |
| Monitoring (M) | Quality of policy monitoring | Compliance, exceptions, reporting |
Policy Management (Visual): ┌─────────────────────────────────────────────────────────────────────────┐ | | | Policy Definition │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Policy Creation │ │ | │ • Policy Documentation │ │ | │ • Policy Approval │ │ | │ • Types: Access, Identity, Compliance, Security │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Policy Enforcement │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Policy Implementation │ │ | │ • Policy Monitoring │ │ | │ • Policy Compliance │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Policy Monitoring │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Compliance Monitoring │ │ | │ • Exception Management │ │ | │ • Policy Reporting │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Formula: P_MS = D_efinition * E_nforcement * M_onitoring │ └─────────────────────────────────────────────────────────────────────────┘
Part 5: Compliance Reporting
5.1 The Compliance Reporting Definition
Compliance reporting is the process of generating reports to demonstrate compliance with policies and regulations.
Compliance Reporting = {Regulatory, Audit, Executive}
5.2 Reporting Types
| Type | Description | Audience |
|---|---|---|
| Regulatory Reporting | Reports for regulators | Regulators |
| Audit Reporting | Reports for auditors | Auditors |
| Executive Reporting | Reports for executives | Executives |
5.3 The Compliance Reporting Score
The Compliance Reporting Score quantifies the effectiveness of compliance reporting:
C_RS = R_egulatory * A_udit * E_xecutive
Where:
-
R_egulatoryis the Regulatory Score (0-1) -
A_uditis the Audit Score (0-1) -
E_xecutiveis the Executive Score (0-1)
| Component | Description | Scoring Factors |
|---|---|---|
| Regulatory (R) | Quality of regulatory reporting | Completeness, accuracy, timeliness |
| Audit (A) | Quality of audit reporting | Completeness, accuracy, timeliness |
| Executive (E) | Quality of executive reporting | Clarity, relevance, timeliness |
Compliance Reporting (Visual): ┌─────────────────────────────────────────────────────────────────────────┐ | | | Regulatory Reporting │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • GLBA Compliance Reports │ │ | │ • SOX Compliance Reports │ │ | │ • GDPR Compliance Reports │ │ | │ • NYDFS Compliance Reports │ │ | │ • PCI DSS Compliance Reports │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Audit Reporting │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Internal Audit Reports │ │ | │ • External Audit Reports │ │ | │ • Compliance Audit Reports │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Executive Reporting │ | ┌─────────────────────────────────────────────────────────────────┐ │ | │ • Executive Summaries │ │ | │ • Board Reports │ │ | │ • Status Reports │ │ | └─────────────────────────────────────────────────────────────────┘ │ | | | Formula: C_RS = R_egulatory * A_udit * E_xecutive │ └─────────────────────────────────────────────────────────────────────────┘
Summary and Bridge to Lesson 6.6
We have now completed the comprehensive analysis of Identity Governance and Administration. You have learned:
-
IGA Components: Identity Lifecycle Management, Access Certification, Policy Management, and Compliance Reporting.
-
IGA Maturity Score:
I_GM = L_ifeycle * C_ertification * P_olicy * C_ompliance. -
Identity Lifecycle Management: Creation, maintenance, and deprovisioning.
-
Identity Lifecycle Management Score:
I_LM = C_reation * M_aintenance * D_eprovisioning. -
Access Certification: User access reviews, role certifications, and entitlement certifications.
-
Access Certification Score:
A_CS = C_overage * A_ccuracy * T_imeliness. -
Policy Management: Definition, enforcement, and monitoring.
-
Policy Management Score:
P_MS = D_efinition * E_nforcement * M_onitoring. -
Compliance Reporting: Regulatory, audit, and executive reporting.
-
Compliance Reporting Score:
C_RS = R_egulatory * A_udit * E_xecutive.
In Lesson 6.6, we will explore IAM for Cloud and Hybrid Environments in Financial Institutions, including IAM challenges and solutions for cloud and hybrid environments.