Talk to us Risks to Watch

The Five Key Components to Build an Identity Fabric

Overview: Evolving IAM functional needs and the importance of identity fabric

The requirements for having a holistic Identity and Access Management (IAM) approach have increased significantly in the recent past. Decentralized IT setups with distinct human and non-human digital identities, zero trust adoption, and the proliferation of SaaS applications and multi-cloud environments as well as complex identity-based functional use cases that can lead to insider and third-party threats, have all led to the construction of robust perimeter security around each digital identity. 

Every IT infrastructure, such as on-prem, hybrid, private/public clouds, and multi-clouds, are continuously accessed by numerous and distinct identities during different hours for different purposes. Therefore, improving IAM infrastructure is no longer an option but is mandatory to ensure adequate control of identities, i.e.  every digital identity accessing business and infrastructure assets at the right time for the right purpose. Because different identities constantly interact with critical applications, secrets, and information of critical importance, including the network and infrastructure devices, a holistic IAM practice is a must to thwart identity misuse and abuse related threats. 

In this context, building an identity fabric goes a long way towards providing the framework for secure and seamless IAM practice. A well-architected identity fabric provides complete visibility into the identity system and provides adequate safeguards against IT threats like account takeover, insider attacks, and third-party risks.

Let us find out what are the 5 key components to build an identity fabric

  • Centralized engine to manage multiple and distinct digital Identities

In a typical IT setup, organizations must control and manage numerous kinds of digital identities. There are:

  •  Human Identities (Named and shared identities)
  •  Non-human identities (for software bots, workloads on cloud and various automated services)
  • Cloud identities (DevOps toolchains, SaaS applications)

It becomes a herculean task for IT administrators to administer and govern hundreds of identities in a distributed and complex IT environment.  Adding to woes, the fragmented IAM approach, i.e., standalone IAM, PAM, IGA solutions to administer access management use cases results in decentralized controls and decentralized polices. 

Therefore, the first requirement, to build a holistic IAM approach, and construct identity fabric is to have a centralized mechanism in place that can administer all kinds of digital identities. So, it is important for IAM pros to move towards the converged IAM approach.  Convergence of Identities builds a comprehensive and centralized approach towards the major functional areas of Identity Access Management (IAM) space. It nullifies the necessity of multiple solutions to manage distinct identities available in an IT setup and combines all the different dimensions and requirements of identity and access management in one platform. It includes identity access policy framework, identity governance, and even seamless monitoring.

  • Policy Enforcement

The “who, what, where, when, how, or why” parameters build the base of a secure policy in an IT environment. Before enforcing a policy in the IT setup, it is important to define the policy, explain it to the users, apply it to the respective users and build a secure IT environment. A standard identity fabric is built by enforcing a standard and desirable IT policy for every digital identity available in the IT environment. Occasionally, IT policies that are applied to a group of identities, are categorized automatically as per roles and access limitations of the users.

Identity access control policy includes the below parameters:

  • Creation of identities (auto onboarding of digital identities from source of truth such as HR application, active directory, Azure AD, AWS EC2 instance, GCP) 
  • Categorization of identities
  • Monitoring the identities
  • Interaction with the identities
  • Execution of rules with the identities

Policy enforcement of digital identities may also address specific technical interactions or requirements such as which protocols to accept, which ports to use, or details about connection timeouts.

  • Entitlement Management

Entitlement management of digital identities is a mechanism that administers, allows, enforces, and revokes digital identity access permissions. In a standard identity fabric, the privilege authorizations, access rights, and permissions are the prerequisites of identity entitlement management.

The purpose of entitlement management is to execute the predefined IT access policies for the structured/unstructured data, devices and servers. This can help eliminate potential human errors, especially while ensuring the right users have right access to the right systems, networks, applications, and devices. At the same time, it manages what the users should be barred from.

Due to the continuously changing workflow, the user access rights and requirements keep on altering. While it is essential for the users to have access to the systems and applications for uninterrupted IT operations, at the same time security cannot be ignored to prevent any unauthorized access. In fact, with a standard identity fabric, organizations can manage identity access of both insiders and outsiders. Entitlement management systems in identity fabric can:

  • Define user roles
  • Manage end-user hierarchies and workflow management 
  • Define and manage permissions of users (granular controls, just-in-time access)
  • Allow and revoke user privileges based on requirements
  • Manage complexities of allowing and denying access control mechanisms
  • Implement different access control paradigms, e.g., data-driven approaches, role-based approaches etc.
  • Multi-factor Authentication (MFA)

Authenticating users before allowing the desired access is one of the basic IT security steps followed by the IT administrators in a distributed IT environment. To protect confidential data assets and critical servers from unauthorized and suspicious access, authentication mechanism plays a pivotal role. Every category of identity in an IT setup requires some kind of authentication to remain ‘authorized’ before any desired access. This authentication mechanism could be categorized based on the criticality of the identity. For example, 

  • A general non-privilege user can have two-factor authentication
  • A privileged user with a privileged identity can have multi-factor authentication (MFA)
  • A cloud identity with access to highly confidential cloud resources require adaptive authentication mechanism to predict and prevent sophisticated attacks

To be precise, Multi-factor Authentication (MFA) provides additional and adequate layers of protection to the critical systems and applications. It verifies the authenticity of the identity in multiple layers before allowing access to the desired server, application, or target device.

AI-based adaptive authentication mechanism, on the other hand, is based out of the experience of past user behaviour which mostly happens through geo location, IP address and typing speed. These aspects determine whether the user activity has happened through an authentic environment. This is more beneficial for the organizations that follow hybrid work models where too many users remotely access critical systems and applications for seamless IT operations.

  • Identity Governance and Administration (IGA)

Poor governance of identities is one of the reasons behind the increase of identity-based threats in the recent past. Every identity in the IT infrastructure has its individual role and thus governing them continuously can build a comprehensive IT security infrastructure. A standard identity fabric with the help of identity goveranance can ensure the right user access to the right resource at the right time for the right purpose. Thereby, it maintains a secure access control framework in every layer of IT setup and protects the confidential IT assets from breaches and unauthorized access. 

          IGA ensures provisioning and deprovisioning of identities: For example: 

  • Running on-demand and detecting all digital identities
  • Corelating with existing on-boarded users
  • Classifying accounts into local domain/ privileged/ non-privileged
  • Deprovisioning dormant accounts
  • Handling transfer use cases

Conclusion

The IAM functional needs are evolving continuously. As a result, the necessity for a holistice IAM approach is gradually increasing. These five key components discussed above build an identity fabric that not just ensures complete control of the identities but also enables seamless administration.

Large Scale Layoffs, Identity-based threats, and Converged IAM approach

Overview: The Layoffs and Underlying Risks

The first quarter of 2023 witnessed large scale layoffs in the technology domain across the globe. More than three hundred thousand people were handed over pink slips. And there can be few more numbers that may be unaccounted for as such massive layoffs lead to “domino” effect.

Such incidents lead to mental stress and uncertainties among the employees and their family members. For few it results in frustration and for another few it results in a revengeful attitude. Employees may feel left out, unrecognized and turn their frustration into vengeance.

But the bigger risk is Identity-based threats

While the objective of layoffs is cost reduction and increased profitability, it could turn out to be counterproductive exercise for an organization if the Identity Access Management (IAM) mechanism is fragile.

Let’s consider some scenario-based risks due to poor IAM implementation

  • Think of the risks and uncertainties that linger around the enormous number of digital identities that are no longer active in the IAM systems. Daily hundreds of identities interact with hundreds of cloud applications, including legacy applications. If those identities are not deprovisioned on time, that could result in account take over, social engineering and other forms of insider threats. 
  • On the other hand, if this enormous number of identities are deprovisioned manually, there could be chances of human errors and it could be time-consuming, eventually leading to utter chaos.
  • Risks multiply if there are dormant accounts or any orphaned account that remain undetected for longer period and any disgruntled insider out of vengeance misuses the accounts. Unless the provisioned accounts are not deprovisioned on time, malicious insiders, suspicious third-parties or even hacktivists can misuse them for compromising IT assets.
  • Adding to the woes, if any of these identities are privileged identities, then the outcome can be catastrophic. There are many privileged entitlements on cloud, for example, administrative access to cloud consoles, critical applications, DevOps tool chains among other cloud resources. In addition, in on-prem IT set-up, there are many administrative privileged identities that have to access to network devices, databases and servers. Any sort of misuse or abuse of such identities can bring the entire IT operations to a standstill.
  • Lastly, it’s not just data loss or financial loss. The organization could face non-compliance financial penalties from the global IT standards and regulatory compliance bodies that demand secure and authorized logins to every critical account. 

How to Mitigate the Risks?

Automation is the key to mitigate the security threats from orphaned accounts, and deprovisioned accounts. This is the age of automation and organizations are continuously transforming their IT infrastructure to hybrid models or/ and adopting SaaS (Software as a Service) models. As a result, provisioning of user accounts for multiple applications happens regularly to enhance productivity and operational efficiency.

However, too many user accounts create complexities in managing large and distinct identities. It requires utmost attention when it comes to ever-increasing number of SaaS applications because of its vulnerabilities and most of the time unmanaged identities become the intrusion doors for anomalies. Similarly, while laying off employees, especially those working remotely, organizations tend to take unlimited time in deprovisioning their identities. It increases the numbers of dormant/orphan accounts and the chances of compromising those accounts.

Modern enterprises seek an automated solution that can provision and deprovision all types of identities including human identities, machine identities, and privileged identities without human intervention.

Converged Identity Approach

Not just privileged identities, modern IAM infrastructure equally demands utmost security of any named identity, shared identity, machine identity, bot identity, API identity, and cloud identity. Converged Identity platform offers comprehensive visibility over all sorts of identities and is believed to be the future of Identity Access Management (IAM) initiatives.

So, considering the above scenarios, what today’s IAM pros need is a single glass pane that shows the status of every identity in real-time. ARCON’s Converged Identity platform helps to give an overview of how many different identities are there in an IT setup at any point of time. The IT administrator can have a clear overview of:

  • Total number of digital identities (both human and non-human)
  • Total number of active identities
  • Number of privileged identities
  • How many dormant identities
  • Total number of disabled users & suspended users
  • Number of departments and user groups
  • Total number of business assets & infrastructure assets
  • Overall login records
  • Day & month-wise login records
  • Most accessed resource/ application

In short, CI (Converged Identity) offers comprehensive mapping of all sorts of identities. 

In the current mass scale lay off scenario, as discussed above, most of the organizations seek a holistic and comprehensive IAM security approach in the most easy-to-use and secure manner. The future of IT security stands tall with ARCON’s Converged Identity approach because the solution: 

  • Manages every identity from a centralized location to detect and prevent unauthorized access
  • Provisions/ Deprovisions both business assets (e.g. Web applications), infrastructure assets (e.g. OS or network devices) and the users
  • Ensures role-based access only and thereby eliminates the chances of unnecessary privilege access
  • Possesses the ability to integrate multiple solutions under one roof and improves operational efficiency
  • Eliminates the requirement of manual intervention due to automated approach
  • Maintains lifecycle of every identity starting with creation of identities, modifying their access rights, and even disabling/removing their access rights
  • Authorizes end-users with access certifications, entitlement management and makes proper segregation of duties to prevent unauthorized activities
  • Helps to meet regular audit and standard compliance requirements

Conclusion

Converged Identity approach is the new age mantra for Identity Access Management (IAM) initiatives that administers overall access management and comprehensively helps to manage the lifecycle of distinct digital identities.

Identity Fabric: The Foundation of Secure Digital Transformation

Overview: Identity Fabric 

Digital transformation is ubiquitous. Fundamentally, it has changed the IT paradigm.  In terms of security as well. Digital transformation demands carefully architected identity management practice, which is composed of people, policies and procedures. Indeed, these identities have taken the center stage of this transformation. Identities constantly interact with applications, secrets, information of critical importance and network and infrastructure devices. So, if organizations lack the ability to manage and control the way these identities make access to critical applications, the digitalization initiatives might fail. 

To make this transformation successful, organizations must build a detailed activity map and permission policies around every identity in the backend that can perform all granted entitlements and services in the IT environment- securely. Such a map in the backend forms the “Identity Fabric” that ensures all the digital services are done in a standardized manner. It works as the first brick to build the legacy building of Identity Access Management (IAM)

If we go by the allegorical terms, an identity is the distinctive or identical qualities, beliefs, or personality traits that develop or establish a standard for a person. On the contrary, digital identities in cyber terms are information used by IT systems to represent a person, machine, application, or organization itself. And building Identity Fabric enables us to seamlessly manage user and service identities (either human or non-human) in multiple layers of IT infrastructure. 

Identity Fabric and Access Management

Digital identities are increasingly vulnerable to insider and third-party threats. And the sheer number of identities is ever greater. There are human identities, privileged identities, machine identities, API identities, and cloud identities in modern IT infrastructure. The identity fabric for every set of categories, use cases, and functions demands a distinct set of rules and policies for seamless and secure functions. If the security and governance of the identities are not as per the standards and policies, it could be connived by malicious insiders, compromised third-parties or organized hacktivists.

Therefore, a well-managed identity fabric provides visibility into the system and works as a key component to build authentication mechanisms regardless of IT infrastructure.

Policy-based access for every identity: Specified access policy is always crucial for identifying the genuineness of any digital identity. Access to any critical application, confidential database server, or the individual who has predefined roles and responsibilities in place determines the comprehensiveness of identity fabric. It is not how many accesses a particular identity must fulfill the requirements, but the genuineness and relevant access right that matters.

Hence, the access policy, once predefined, determines whether the identity is rightly used or misused. In a larger perspective, it prevents information misuse.

Authorization of Identities: The lifecycle of an identity depends on how the identity is established and used for different sets of IT tasks. And to do that, authorization of the identities plays a key role. It is the first critical step for mapping the overall identity fabric. Authorization mechanism ensures that the identity is –

  • Accessing the right application/ system at the right time for the right purpose
  • Preventing any unauthorized attempt to access any critical application
  • Maintaining confidentiality of business data
  • Seamlessly integrating the resources in a secure manner
  • Meeting regulatory compliance mandates

Components that help to choose the right Identity Fabric

An API-based approach (Application Programming Interface) is the key behind an intense architecture of identity fabric. This is because the services related to identity need to be incorporated with the digital activities of the organization consistently. Once the process is standardized, identity fabric helps to accelerate the integration of modern technologies to a smoother user experience and stronger security posture with privacy controls. It builds the compliance posture.

Here are the components that help to choose the relevant Identity Fabric:

  • Convergence: Identity Fabrics build a comprehensive approach towards the major functional areas of Identity Access Management (IAM). This niche segment of data management is integrated to ensure that the right users have the right access to the right technology resources.
  • Flexibility: This is a default trait of Identity Fabrics. Considering the advanced IT infrastructure, most organizations seek flexible deployment models, and the right identity fabric offers flexibility with a comprehensive set of APIs.
  • Supported identities and systems: The scope of an Identity Fabric lies beyond the workforce. Considering the proliferation of hybrid workforce, it covers all types of identities, remote users and third-party access. 

Role of Digital Identity Fabrics in building business strategies

The key aspects of identity fabrics in the digital age are security, privacy, compliance and user experience. Business leaders are continuously challenged by the need for technological innovations and new business models because there are frequent changes in business partnerships, and internal policies. Digital Identities take the centerstage of this transformation. Without the ability to manage and control the access of every identity to every service, businesses will face transformational challenges. To be precise, the IT challenges on businesses related to digital identities come from multiple areas including demand of –

  • Compliance standards
  • Data privacy from consumers 
  • Smart analytics of activities
  • Flexibility of the functions and access patterns
  • Ability to customize requirements as per demands

Conclusion

Digital transformation is inevitable, and the challenges related to this transformation are unavoidable. Choosing the right identity fabric helps to build the foundation of secure IT infrastructure without compromising the daily IT operational tasks and overall business continuity.