Hitachi ID Systems, Inc.

Hitachi

Security
Hitachi ID Systems Web Feeds Follow Us on Twitter Follow us on LinkedIn
certification

Product Sites

Hitachi ID Identity Manager Security Benefits

User administration, especially in a heterogeneous environment where each user has multiple login accounts and appears in multiple directories, has many inherent security problems. In many organizations, weaknesses in change management processes are a major source of security problems.

Learn more about:


Security problem Hitachi ID Identity Manager solution
User profiles persist long after their owner has been terminated Unreliable business processes and incomplete access profiles mean that when employees or contractors are terminated, systems administrators may not be notified on time, or at all. Additionally, without a global record of every login ID on every system that belongs to a user, it is difficult or impossible to ensure that all of the login accounts associated with a user are reliably and promptly disabled after a termination. As a result, users may retain login entitlements long after they have left an organization. Identity Manager helps organizations to implement reliable and prompt termination, through automated termination, consolidated access reporting, and use of a consolidated user administration console.
Users accumulate entitlements like lint Over time, as users move around an organization, changing responsibilities, they accumulate login accounts on various systems and specific security entitlements, all required to do their jobs. Unfortunately, it is difficult or impossible to determine when their old entitlements are really no longer needed, and so should be removed. As a result, users just accumulate entitlements. This is a security problem, as it increases the risk of security violations due either to honest errors or compromised accounts. Identity Manager can be used to periodically review what login accounts and entitlements each user has, to identify suspicious entitlements, and to remove those that managers and system owners agree are truly no longer required.
It is difficult to determine what users have what access to systems and data, and how they got it. Lack of a database that connects login IDs across systems back to individual users, and that tracks security entitlements across systems, makes it difficult or impossible to determine just what access rights any given user has (globally), or conversely what set of users have a particular combination of security entitlements. Local or absent change logs make it impossible to track how users got the access rights they have. This makes it difficult to meet regulatory requirements for effective internal controls. Identity Manager can be used to report on user access rights and change history globally.
Users have non-standard login IDs and account configuration Different human security administrators create accounts in different ways, inadvertantly violating standards. Without effective standards enforcement, it is difficult to control the access rights of large user populations. Without enforcing login ID naming conventions, it is difficult to correlate security events across systems. Identity Manager creates all new users with standard login IDs by cloning pre-defined, standardized template accounts.
Users get new accounts and security changes without proper authorization Overly-restrictive change control procedures, or simply difficult to use change request forms, may lead business users to bypass the change request / routing / authorization process entirely, and demand security changes directly from systems administrators. In effect, lack of usability can defeat security. Identity Manager makes the change control process easy to use, with a built-in self-service workflow engine. Users have no incentive to bypass the system when it is fast and effective.

Identity Manager strengthens security by:

Read more: