Introduction: The Framework of Trust

In Lessons 6.1 through 6.4, we established the foundations of Identity and Access Management (IAM), explored authentication mechanisms, analyzed authorization and access control models, and examined Privileged Access Management (PAM). We examined the core IAM concepts, the identity lifecycle, authentication factors, MFA, biometrics, certificates, RBAC, ABAC, DAC, MAC, and PAM. Each of these components contributes to managing digital identities and controlling access to resources.

However, effective IAM requires more than just technology and controls. It requires a comprehensive framework of governance, oversight, and administration. This is the domain of Identity Governance and Administration (IGA) .

Identity Governance and Administration (IGA) is the practice of managing the lifecycle of digital identities, governing access rights, and ensuring compliance with policies and regulations. It encompasses the processes, tools, and controls used to manage identities, entitlements, access certifications, and compliance reporting.

In financial institutions, IGA is of paramount importance because it:

  • Ensures Compliance: Meeting regulatory requirements for access control (GLBA, SOX, GDPR, NYDFS, PCI DSS).

  • Manages Risk: Identifying and mitigating access-related risks.

  • Enforces Policy: Ensuring that access policies are consistently enforced.

  • Provides Visibility: Providing visibility into who has access to what resources.

  • Enables Auditing: Supporting internal and external audits.

This lesson provides a comprehensive analysis of Identity Governance and Administration for financial institutions. We begin by examining the IGA Components: Identity Lifecycle Management, Access Certification, Policy Management, and Compliance Reporting. We derive the IGA Maturity ScoreI_GM = L_ifeycle * C_ertification * P_olicy * C_ompliance.

We then examine Identity Lifecycle Management, including identity creation, maintenance, and deprovisioning. We derive the Identity Lifecycle Management ScoreI_LM = C_reation * M_aintenance * D_eprovisioning.

We also examine Access Certification, including user access reviews, role certifications, and entitlement certifications. We derive the Access Certification ScoreA_CS = C_overage * A_ccuracy * T_imeliness.

We also examine Policy Management for IGA, including policy definition, enforcement, and monitoring. We derive the Policy Management ScoreP_MS = D_efinition * E_nforcement * M_onitoring.

Finally, we examine Compliance Reporting for IGA, including regulatory compliance, audit reporting, and executive reporting. We derive the Compliance Reporting ScoreC_RS = R_egulatory * A_udit * E_xecutive.

By the end, you will have a complete understanding of Identity Governance and Administration, and be able to design and implement IGA programs for financial institutions.


Learning Objectives

Upon completion of this lesson, you will be able to:

  1. Analyze the IGA Components: Identity Lifecycle Management, Access Certification, Policy Management, and Compliance Reporting.

  2. Derive the IGA Maturity ScoreI_GM = L_ifeycle * C_ertification * P_olicy * C_ompliance.

  3. Analyze Identity Lifecycle Management: Creation, maintenance, and deprovisioning.

  4. Derive the Identity Lifecycle Management ScoreI_LM = C_reation * M_aintenance * D_eprovisioning.

  5. Analyze Access Certification: User access reviews, role certifications, and entitlement certifications.

  6. Derive the Access Certification ScoreA_CS = C_overage * A_ccuracy * T_imeliness.

  7. Analyze Policy Management: Definition, enforcement, and monitoring.

  8. Derive the Policy Management ScoreP_MS = D_efinition * E_nforcement * M_onitoring.

  9. Analyze Compliance Reporting: Regulatory, audit, and executive reporting.

  10. Derive the Compliance Reporting ScoreC_RS = R_egulatory * A_udit * E_xecutive.


Part 1: IGA Components

1.1 The IGA Definition

Identity Governance and Administration (IGA) is the practice of managing the lifecycle of digital identities, governing access rights, and ensuring compliance.

text
IGA = {Lifecycle Management, Access Certification, Policy Management, Compliance Reporting}

1.2 The Four IGA Pillars

 
 
Pillar Description Key Activities
Identity Lifecycle Management Managing identity lifecycle Creation, maintenance, deprovisioning
Access Certification Certifying access rights User access reviews, role certifications
Policy Management Managing access policies Policy definition, enforcement, monitoring
Compliance Reporting Reporting on compliance Regulatory, audit, executive reporting

1.3 The IGA Maturity Score

The IGA Maturity Score quantifies the maturity of IGA:

text
I_GM = L_ifeycle * C_ertification * P_olicy * C_ompliance

Where:

  • L_ifeycle is the Lifecycle Score (0-1)

  • C_ertification is the Certification Score (0-1)

  • P_olicy is the Policy Score (0-1)

  • C_ompliance is the Compliance Score (0-1)

 
 
Component Description Scoring Factors
Lifecycle (L) Quality of identity lifecycle management Creation, maintenance, deprovisioning
Certification (C) Quality of access certification Coverage, accuracy, timeliness
Policy (P) Quality of policy management Definition, enforcement, monitoring
Compliance (C) Quality of compliance reporting Regulatory, audit, executive
text
IGA Components (Visual):
┌─────────────────────────────────────────────────────────────────────────┐
|                                                                         |
|  ╔═══════════════════════════════════════════════════════════════════╗  |
|  ║  Identity Lifecycle Management                                 ║  |
|  ╠═══════════════════════════════════════════════════════════════════╣  |
|  ║  • Identity Creation                                            ║  |
|  ║  • Identity Maintenance                                          ║  |
|  ║  • Identity Deprovisioning                                       ║  |
|  ║  • Key Activities: Provisioning, updates, revocation            ║  |
|  ╚═══════════════════════════════════════════════════════════════════╝  |
|                                                                         |
|  ╔═══════════════════════════════════════════════════════════════════╗  |
|  ║  Access Certification                                           ║  |
|  ╠═══════════════════════════════════════════════════════════════════╣  |
|  ║  • User Access Reviews                                          ║  |
|  ║  • Role Certifications                                          ║  |
|  ║  • Entitlement Certifications                                   ║  |
|  ║  • Key Activities: Review, certify, remediate                  ║  |
|  ╚═══════════════════════════════════════════════════════════════════╝  |
|                                                                         |
|  ╔═══════════════════════════════════════════════════════════════════╗  |
|  ║  Policy Management                                              ║  |
|  ╠═══════════════════════════════════════════════════════════════════╣  |
|  ║  • Policy Definition                                            ║  |
|  ║  • Policy Enforcement                                           ║  |
|  ║  • Policy Monitoring                                            ║  |
|  ║  • Key Activities: Create, enforce, monitor                    ║  |
|  ╚═══════════════════════════════════════════════════════════════════╝  |
|                                                                         |
|  ╔═══════════════════════════════════════════════════════════════════╗  |
|  ║  Compliance Reporting                                           ║  |
|  ╠═══════════════════════════════════════════════════════════════════╣  |
|  ║  • Regulatory Reporting                                         ║  |
|  ║  • Audit Reporting                                              ║  |
|  ║  • Executive Reporting                                          ║  |
|  ║  • Key Activities: Generate, review, submit                    ║  |
|  ╚═══════════════════════════════════════════════════════════════════╝  |
|                                                                         |
|  Formula: I_GM = L_ifeycle * C_ertification * P_olicy * C_ompliance   │
└─────────────────────────────────────────────────────────────────────────┘

Part 2: Identity Lifecycle Management

2.1 The Lifecycle Definition

Identity lifecycle management is the process of managing identities from creation to deprovisioning.

text
Identity Lifecycle = {Creation, Maintenance, Deprovisioning}

2.2 Identity Creation

Definition: Identity creation is the process of creating a new digital identity.

text
Identity Creation = {Identity Generation, Attribute Assignment, Account Provisioning}

Creation Activities:

 
 
Activity Description Security Considerations
Identity Generation Creating the identity Unique identifiers, generation process
Attribute Assignment Assigning attributes Accuracy, completeness
Account Provisioning Creating accounts Account creation, access assignment

2.3 Identity Maintenance

Definition: Identity maintenance is the ongoing management of identities and access.

text
Identity Maintenance = {Attribute Updates, Access Updates, Monitoring}

Maintenance Activities:

 
 
Activity Description Frequency
Attribute Updates Updating identity attributes As needed
Access Updates Updating access rights As needed
Role Changes Changing roles and permissions As needed
Password Management Password changes, resets Ongoing
Monitoring Monitoring for anomalies Continuous

2.4 Identity Deprovisioning

Definition: Identity deprovisioning is the process of revoking access and removing identities.

text
Identity Deprovisioning = {Access Revocation, Account Deletion, Data Destruction}

Deprovisioning Activities:

 
 
Activity Description Security Considerations
Access Revocation Revoking all access Timely revocation
Account Deletion Deleting accounts Complete deletion
Data Destruction Destroying identity data Secure destruction
Verification Verifying deprovisioning is complete Audit trail

2.5 The Identity Lifecycle Management Score

The Identity Lifecycle Management Score quantifies the effectiveness of identity lifecycle management:

text
I_LM = C_reation * M_aintenance * D_eprovisioning

Where:

  • C_reation is the Creation Score (0-1)

  • M_aintenance is the Maintenance Score (0-1)

  • D_eprovisioning is the Deprovisioning Score (0-1)

 
 
Component Description Scoring Factors
Creation (C) Quality of identity creation Accuracy, completeness, security
Maintenance (M) Quality of identity maintenance Timeliness, accuracy, monitoring
Deprovisioning (D) Quality of deprovisioning Timeliness, completeness, security
text
Identity Lifecycle Management (Visual):
┌─────────────────────────────────────────────────────────────────────────┐
|                                                                         |
|  Identity Creation                                                    │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Identity Generation                                        │  │
|  │  • Attribute Assignment                                        │  │
|  │  • Account Provisioning                                        │  │
|  │  • Security: Unique identifiers, accurate attributes          │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Identity Maintenance                                                │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Attribute Updates                                            │  │
|  │  • Access Updates                                               │  │
|  │  • Role Changes                                                 │  │
|  │  • Password Management                                          │  │
|  │  • Monitoring                                                   │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Identity Deprovisioning                                             │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Access Revocation                                           │  │
|  │  • Account Deletion                                            │  │
|  │  • Data Destruction                                            │  │
|  │  • Verification                                                 │  │
|  │  • Security: Timely revocation, complete deletion              │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Formula: I_LM = C_reation * M_aintenance * D_eprovisioning         │
└─────────────────────────────────────────────────────────────────────────┘

Part 3: Access Certification

3.1 The Access Certification Definition

Access certification is the process of reviewing and certifying access rights.

text
Access Certification = {User Access Reviews, Role Certifications, Entitlement Certifications}

3.2 Access Certification Types

 
 
Type Description Frequency
User Access Reviews Reviewing user access rights Quarterly/Annually
Role Certifications Certifying role assignments Annually
Entitlement Certifications Certifying entitlements Annually
Privileged Access Reviews Reviewing privileged access Quarterly

3.3 Access Certification Process

 
 
Step Description Key Activities
1. Planning Plan the certification Define scope, schedule
2. Data Collection Collect access data Data gathering, preparation
3. Review Review access rights Reviewer review, investigation
4. Certification Certify access Certify, revoke, modify
5. Remediation Remediate issues Remove access, modify permissions
6. Reporting Generate reports Certification reports, audit trails

3.4 The Access Certification Score

The Access Certification Score quantifies the effectiveness of access certification:

text
A_CS = C_overage * A_ccuracy * T_imeliness

Where:

  • C_overage is the Coverage Score (0-1)

  • A_ccuracy is the Accuracy Score (0-1)

  • T_imeliness is the Timeliness Score (0-1)

 
 
Component Description Scoring Factors
Coverage (C) Coverage of access certification Users, roles, entitlements
Accuracy (A) Accuracy of certification Correctness, completeness
Timeliness (T) Timeliness of certification Frequency, deadlines
text
Access Certification Process (Visual):
┌─────────────────────────────────────────────────────────────────────────┐
|                                                                         |
|  Step 1: Planning                                                     │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Define scope                                                │  │
|  │  • Schedule certification                                       │  │
|  │  • Identify reviewers                                           │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Step 2: Data Collection                                             │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Gather access data                                           │  │
|  │  • Prepare data for review                                      │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Step 3: Review                                                      │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Review access rights                                         │  │
|  │  • Investigate exceptions                                       │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Step 4: Certification                                              │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Certify access                                               │  │
|  │  • Revoke or modify access                                      │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Step 5: Remediation                                                 │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Remove unauthorized access                                   │  │
|  │  • Modify permissions                                            │  │
|  └────────────────────────┬────────────────────────────────────────┘  │
|                           │                                           |
|                           ▼                                           |
|  Step 6: Reporting                                                   │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Generate reports                                             │  │
|  │  • Audit trails                                                 │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Formula: A_CS = C_overage * A_ccuracy * T_imeliness                 │
└─────────────────────────────────────────────────────────────────────────┘

Part 4: Policy Management

4.1 The Policy Management Definition

Policy management is the process of defining, enforcing, and monitoring access policies.

text
Policy Management = {Definition, Enforcement, Monitoring}

4.2 Policy Types

 
 
Policy Type Description Examples
Access Policies Policies governing access Least privilege, separation of duties
Identity Policies Policies governing identity Identity verification, authentication
Compliance Policies Policies governing compliance Regulatory compliance, audit
Security Policies Policies governing security Password policies, MFA

4.3 Policy Definition

Definition: Policy definition is the process of creating and documenting policies.

text
Policy Definition = {Policy Creation, Policy Documentation, Policy Approval}

4.4 Policy Enforcement

Definition: Policy enforcement is the process of ensuring policies are followed.

text
Policy Enforcement = {Policy Implementation, Policy Monitoring, Policy Compliance}

4.5 Policy Monitoring

Definition: Policy monitoring is the process of monitoring policy compliance.

text
Policy Monitoring = {Policy Compliance Monitoring, Policy Exception Management, Policy Reporting}

4.6 The Policy Management Score

The Policy Management Score quantifies the effectiveness of policy management:

text
P_MS = D_efinition * E_nforcement * M_onitoring

Where:

  • D_efinition is the Definition Score (0-1)

  • E_nforcement is the Enforcement Score (0-1)

  • M_onitoring is the Monitoring Score (0-1)

 
 
Component Description Scoring Factors
Definition (D) Quality of policy definition Clarity, completeness, approval
Enforcement (E) Quality of policy enforcement Implementation, monitoring
Monitoring (M) Quality of policy monitoring Compliance, exceptions, reporting
text
Policy Management (Visual):
┌─────────────────────────────────────────────────────────────────────────┐
|                                                                         |
|  Policy Definition                                                    │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Policy Creation                                             │  │
|  │  • Policy Documentation                                         │  │
|  │  • Policy Approval                                              │  │
|  │  • Types: Access, Identity, Compliance, Security               │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Policy Enforcement                                                   │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Policy Implementation                                        │  │
|  │  • Policy Monitoring                                            │  │
|  │  • Policy Compliance                                             │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Policy Monitoring                                                    │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Compliance Monitoring                                        │  │
|  │  • Exception Management                                         │  │
|  │  • Policy Reporting                                             │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Formula: P_MS = D_efinition * E_nforcement * M_onitoring            │
└─────────────────────────────────────────────────────────────────────────┘

Part 5: Compliance Reporting

5.1 The Compliance Reporting Definition

Compliance reporting is the process of generating reports to demonstrate compliance with policies and regulations.

text
Compliance Reporting = {Regulatory, Audit, Executive}

5.2 Reporting Types

 
 
Type Description Audience
Regulatory Reporting Reports for regulators Regulators
Audit Reporting Reports for auditors Auditors
Executive Reporting Reports for executives Executives

5.3 The Compliance Reporting Score

The Compliance Reporting Score quantifies the effectiveness of compliance reporting:

text
C_RS = R_egulatory * A_udit * E_xecutive

Where:

  • R_egulatory is the Regulatory Score (0-1)

  • A_udit is the Audit Score (0-1)

  • E_xecutive is the Executive Score (0-1)

 
 
Component Description Scoring Factors
Regulatory (R) Quality of regulatory reporting Completeness, accuracy, timeliness
Audit (A) Quality of audit reporting Completeness, accuracy, timeliness
Executive (E) Quality of executive reporting Clarity, relevance, timeliness
text
Compliance Reporting (Visual):
┌─────────────────────────────────────────────────────────────────────────┐
|                                                                         |
|  Regulatory Reporting                                                 │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • GLBA Compliance Reports                                     │  │
|  │  • SOX Compliance Reports                                       │  │
|  │  • GDPR Compliance Reports                                      │  │
|  │  • NYDFS Compliance Reports                                     │  │
|  │  • PCI DSS Compliance Reports                                   │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Audit Reporting                                                      │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Internal Audit Reports                                      │  │
|  │  • External Audit Reports                                      │  │
|  │  • Compliance Audit Reports                                    │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Executive Reporting                                                  │
|  ┌─────────────────────────────────────────────────────────────────┐  │
|  │  • Executive Summaries                                         │  │
|  │  • Board Reports                                               │  │
|  │  • Status Reports                                              │  │
|  └─────────────────────────────────────────────────────────────────┘  │
|                                                                         |
|  Formula: C_RS = R_egulatory * A_udit * E_xecutive                  │
└─────────────────────────────────────────────────────────────────────────┘

Summary and Bridge to Lesson 6.6

We have now completed the comprehensive analysis of Identity Governance and Administration. You have learned:

  1. IGA Components: Identity Lifecycle Management, Access Certification, Policy Management, and Compliance Reporting.

  2. IGA Maturity Score: I_GM = L_ifeycle * C_ertification * P_olicy * C_ompliance.

  3. Identity Lifecycle Management: Creation, maintenance, and deprovisioning.

  4. Identity Lifecycle Management Score: I_LM = C_reation * M_aintenance * D_eprovisioning.

  5. Access Certification: User access reviews, role certifications, and entitlement certifications.

  6. Access Certification Score: A_CS = C_overage * A_ccuracy * T_imeliness.

  7. Policy Management: Definition, enforcement, and monitoring.

  8. Policy Management Score: P_MS = D_efinition * E_nforcement * M_onitoring.

  9. Compliance Reporting: Regulatory, audit, and executive reporting.

  10. Compliance Reporting Score: C_RS = R_egulatory * A_udit * E_xecutive.

In Lesson 6.6, we will explore IAM for Cloud and Hybrid Environments in Financial Institutions, including IAM challenges and solutions for cloud and hybrid environments.