Research Project
Access link
https://docs.google.com/presentation/d/1bt6IBOPjy1X4iQdoZ-wMD7Qk4z9GFvP_DSE-rkWsFGA/edit?usp=sharing
Title
Automation of access controls (IAM) is essential in improving the security and productivity while reducing the cost of security management in a scaling organization
Abstract
In today's quick paced I.T environment, there is a dire need in organizations for automation in administering access control effectively. Access control can be automated with the use of digital profiles through Identity and Access Management (IAM). IAM is the lifecycle management of an employee’s digital identity that encompasses the provisioning and de-provisioning of a personnel’s access to resources within an organization. With the use of automation over manual intervention in IAM, organisations will increase productivity, minimize human error and reduce overhead costs while maintaining an efficient and secure environment.
Introduction
Access control is the foundation of information security within an organisation :
· “80% of security breaches involve privileged credentials.” - Forresters Research’s 2017
Automation of IAM will ensure the efficient management of personnel in an organisation while maintaining proper segregation of duties and the principle of least privilege. With little to no manual intervention, automation will reduce the risks associated with access creep in an organisation.
· “66% of organizations still rely on manual methods to manage privileged accounts” - Thyotic’s 2016 State of PAM report.
Materials
1. Various IAM software suites such as [IBM ISIM/ISAM, Sailpoint, Oracle etc.]
2. Software cost per person (if no prior AD)
3. Software cost per year (if AD already installed)
4. Average cost of Security profession
5. Average number of security professionals needed in an organization in automated versus manual
6. Calculations of salary with inflations.
Methodology
· Cost of an Automated IAM and Manual IAM
· Annual cost of automated IAM = cost of IAM Software + annual salary of IAM staff to manage an automated system.
· Cost of IAM Software: total employees in an organisation per month * cost of IAM software per individual * 12 months
· Annual cost manual IAM = (average % of security professionals required to manually manage the total number of employees in the organization * number of employees in the organization) * average salary of a security professional
Results – The calculations and charts should indicate a strong move towards automation of most IAM with little manual intervention. It will also indicate the savings as the organization scales.
Discussion – Interpret the finding of the study
The result of this study will take into consideration statistics from over 10 year period as more and more organizations are adopting the automated model of IAM.
Summary – Summarize the findings
References:
Edwards, Jeff. “By The Numbers: Privileged Access Management.” Top Identity & Access Management Software, Vendors, Products, Solutions, & Services, Top Identity & Access Management Software, Vendors, Products, Solutions, & Services, 20 July 2018, solutionsreview.com/identity-management/privileged-account-management-by-the-numbers/.