Critical Analysis needed. Please follow the instructions on the paper. Thank you

profileJohn_matt
case_study_1.docx

Defending Against Insider Threats

Identity and privilege management are two very fundamental features that are essential to defending an organization against possible monetary and data losses resulting from an insider threat.  Insider attacks can occur anywhere at any time.  It is important to foster a healthy working environment ensuring that employees feel their efforts are valued and that they are entrusted to competently fulfill their operational responsibilities.  Unfortunately, this alone will not mitigate the potential threat of malicious intent posed by internal users in trusted positions and privileges.  Mathias defines Identity Management as “what users can do on the network with specific devices and under what circumstances”, (2013).  Roles need to be structured providing the lowest level of access required for empowered users in key positions to function.  Separation of duties is another fundamental aspect of privilege management as it will provide checks and balances preventing one individual from making significant changes to technical infrastructure assets or disseminating confidential data.  It is essential for organizations to employ a framework for establishing, tracking, modifying, managing and revoking access privileges for the internal network users and network assets.  A collaborative effort between internal policies and utilization of an identity and privilege management software platform will provide your company with a proactive defense from insider threats.

             The ideal identity and privilege management platform for your company is Oracle Identity Governance (OIG).  OIG is comprised of three subcomponents: Oracle Identity Manager (OIM), Oracle Identity Analytics (OIA) and Oracle Privileged Account Manager (OPAM).  Access privileges are created and managed within the OIM application.  User roles are created and managed within the OIA application.  OIA also facilitates separation of duty assignments and certification updates confirming the ongoing need for all users with privileged access roles.  “Oracle Identity Analytics provides comprehensive dashboards and reporting capabilities based on user identity, access and audit data offering quick review of compliance and operational status in context of roles, segregation of duty polies, and other controls,” (Oracle, 2008).  OPAM oversees the management of privileged user accounts and essential network assets such as servers or databases.  The OIG protection platform can be deployed on a server with a Windows, Linux or Unix based operating system.  Developmental opportunities for this product is the overall pricing may appear high compared to many of its competitors and its limited focus on innovation to remain in the forefront with the top industry competitors for this product, (Gaehtgens, F., Iverson, B. & Perkins, E., 2013).  Oracle remains an industry leader for identity and privilege management software and continues to provide intuitive defense against the dangers of insider attacks

            Your company will benefit from OIA’s ability to identity how, when and on what device individual privileged users utilized their privileged access and also providing historic details of confirmed and potential violations of its use, (Oracle, 2008).  This will assist in posturing your organization for taking an intuitive approach to improper usage of elevated access, which can also facilitate policy improvement and raise overall awareness.  Oracle provides a fluently adaptable platform to most business infrastructure environments.  “The OIM application is designed to manage user access privileges across all of a firm’s resources throughout the entire identity management lifecycle without requiring changes to existing infrastructure, polies or procedures, effectively minimizing costs by avoiding the need for customizations,” (Oracle, 2016).  The utilization of assigned roles is not set in stone as the OIA application must provide an approval to confirm the business needs of requesting changes to ensure they are in line with the current organizational objectives.  This product is constantly learning from policy updates and will effectively provide system wide monitoring and management for privileged access.

References

Gaehtgens, F., Iverson, B. & Perkins, E. (2013, December 30). Magic quadrant for identity

governance and administration. Retrieved from http://innetworktech.com/wp-content/

uploads/2014/01/Magic-Quadrant-for-Identity-Governance-and-Administration.pdf

Mathias, C. (2013, October). Identity management (ID management). Retrieved from

http://searchsecurity.techtarget.com/definition/identity-management-ID-management

Oracle. (2008). Feature overview: Oracle Identity Analytics. Retrieved from

http://oracle.com/technetwork/testcontent/fov-identity-analytics-088634.html

Oracle. (2016). Oracle Identity Governance. Retrieved from http://oracle.com/us/products/

            middleware/identity-management/governance/features/index.html

Oracle. (2016). Oracle Identity Management. Retrieved from http://oracle.com/technetwork/

Middleware/id-mgmt/overview/index-098451.html