{"id":46809,"date":"2021-10-29T16:23:00","date_gmt":"2021-10-29T10:53:00","guid":{"rendered":"https:\/\/arcon.xyz\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/"},"modified":"2026-03-12T12:15:07","modified_gmt":"2026-03-12T06:45:07","slug":"identity-governance-how-to-keep-the-house-in-order","status":"publish","type":"risk-to-watch","link":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/","title":{"rendered":"Identity Governance: How to keep the House in Order?"},"content":{"rendered":"<p>Probably the most convoluted IT practices of all, the Identity Management and Governance is always vulnerable to a security gap. After all, controlling a vast expanse that extends beyond the traditional realm of a datacenter demands careful planning.<\/p>\n<p>While spiraling cost issues and inadequate resources often undermine the identity governance approach, the inherent shortcomings are too many. And how to overcome those shortcomings invariably will depend on whether an organization clings to the basic principles.<\/p>\n<p>Broadly, the identity governance practice can be split up in three stages.<\/p>\n<p>If we move down in descending order, then the stage one is where identity lifecycle management is at the core. Automation and risk-based scores for identities among many other tools enable to on-board, discover, including grant\/revoke access rights to identities. The whole idea here is to uncover the <a href=\"https:\/\/arconnet.com\/risks-to-watch\/privileged-access-detecting-the-blind-spots\/\"><u><span style=\"color: #e6333a;\">security blind spots<\/span><\/u><\/a>\u00a0through automation.<\/p>\n<p>The second stage is where the manual IT rules and processes complement the automation. Here the Information Security professionals will lay down an unambiguous set of rules as to password policy, authorization among other controls. The objective here is to avoid those mistakes that can prove costly due to the lack of <span style=\"color: #e6333a;\"><a style=\"color: #e6333a;\" href=\"https:\/\/arconnet.com\/risks-to-watch\/pam-people-and-processes\/\"><u>policies and processes<\/u><\/a><\/span>.<\/p>\n<p>The stage three requires doing the basics right. It forms the foundation for robust identity management and governance practice. Here the IT security staff will use the data to the fullest to understand the patterns behind it. Based on the data, an organization can enhance the security by employing the basic tenants in Information Security, especially the identity management and governance.<\/p>\n<h2><strong><b>The Basics in Identity Management and Governance <\/b><\/strong><\/h2>\n<p><strong><b>Segregation of Duties <\/b><\/strong><\/p>\n<p>Every time the end-user logs in and conducts IT tasks, the data is collected and managed in the Identity Governance platform. The metadata collected enables the IT security staff to understand the usage of IT resources including the access patterns. This in turn helps them to draw a clear outline on varied access requirements, including mapping of a workflow matrix. Roles and duties are thus defined.<\/p>\n<p><strong><b>Entitlements based on \u201cneed-to-know\u201d and \u201cneed-to-do\u201d principle <\/b><\/strong><\/p>\n<p>Once the segregation of duties is defined, the next task to ensure access is granted only on \u201cneed-to-know&#8221;, and the \u201cneed-to-do\u201d principle becomes easy. The access entitlements are clearly defined because now the admin knows who ought to access what and how frequently. It mitigates the risk of granting more than required access entitlements.<\/p>\n<h2><strong><b>The bottom-line <\/b><\/strong><\/h2>\n<p>To keep the identity management house in order, organizations implement several practices that include just-in-time privileges and granular controls. Implementing the basic identity governance practices, complements the other best practices in access management.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Probably the most convoluted IT practices of all, the Identity Management and Governance is always vulnerable to a security gap. After all, controlling a vast expanse that extends beyond the traditional realm of a datacenter demands careful planning. While spiraling cost issues and inadequate resources often undermine the identity governance approach, the inherent shortcomings are [&hellip;]<\/p>\n","protected":false},"author":40,"featured_media":47413,"parent":0,"menu_order":0,"template":"","meta":{"_acf_changed":false,"footnotes":""},"risk-categories":[],"class_list":["post-46809","risk-to-watch","type-risk-to-watch","status-publish","has-post-thumbnail","hentry"],"acf":{"blog_inner_page_contents":[{"acf_fc_layout":"hero_section","image":47413,"news_logo":"","publish_date":"","reading_time":"","heading":"","para":"","cta_text":"","cta_url":"","is_featured_post":false},{"acf_fc_layout":"page_contents","social_media_items":null,"sidebar_item_desktop":[{"id":"Overview","item_name":"Overview"},{"id":"The Basics in Identity Management and Governance","item_name":"The Basics in Identity Management and Governance"},{"id":"Entitlements based on \u201cneed-to-know\u201d and \u201cneed-to-do\u201d principle","item_name":"Entitlements based on \u201cneed-to-know\u201d and \u201cneed-to-do\u201d principle"},{"id":"The bottom-line","item_name":"The bottom-line"}],"contents":[{"id":"Overview","title":"Overview","content":"Probably the most convoluted IT practices of all, the Identity Management and Governance is always vulnerable to a security gap. After all, controlling a vast expanse that extends beyond the traditional realm of a datacenter demands careful planning.\r\n\r\nWhile spiraling cost issues and inadequate resources often undermine the identity governance approach, the inherent shortcomings are too many. And how to overcome those shortcomings invariably will depend on whether an organization clings to the basic principles.\r\n\r\nBroadly, the identity governance practice can be split up in three stages.\r\n\r\nIf we move down in descending order, then the stage one is where identity lifecycle management is at the core. Automation and risk-based scores for identities among many other tools enable to on-board, discover, including grant\/revoke access rights to identities. The whole idea here is to uncover the\u00a0<a href=\"https:\/\/arconnet.com\/risks-to-watch\/privileged-access-detecting-the-blind-spots\/\"><u>security blind spots<\/u><\/a>\u00a0through automation.\r\n\r\nThe second stage is where the manual IT rules and processes complement the automation. Here the Information Security professionals will lay down an unambiguous set of rules as to password policy, authorization among other controls. The objective here is to avoid those mistakes that can prove costly due to the lack of\u00a0<a href=\"https:\/\/arconnet.com\/risks-to-watch\/pam-people-and-processes\/\"><u>policies and processes<\/u><\/a>.\r\n\r\nThe stage three requires doing the basics right. It forms the foundation for robust identity management and governance practice. Here the IT security staff will use the data to the fullest to understand the patterns behind it. Based on the data, an organization can enhance the security by employing the basic tenants in Information Security, especially the identity management and governance."},{"id":"The Basics in Identity Management and Governance","title":"The Basics in Identity Management and Governance","content":"<strong><b>Segregation of Duties<\/b><\/strong>\r\n\r\nEvery time the end-user logs in and conducts IT tasks, the data is collected and managed in the Identity Governance platform. The metadata collected enables the IT security staff to understand the usage of IT resources including the access patterns. This in turn helps them to draw a clear outline on varied access requirements, including mapping of a workflow matrix. Roles and duties are thus defined."},{"id":"Entitlements based on \u201cneed-to-know\u201d and \u201cneed-to-do\u201d principle","title":"Entitlements based on \u201cneed-to-know\u201d and \u201cneed-to-do\u201d principle","content":"Once the segregation of duties is defined, the next task to ensure access is granted only on \u201cneed-to-know\u201d, and the \u201cneed-to-do\u201d principle becomes easy. The access entitlements are clearly defined because now the admin knows who ought to access what and how frequently. It mitigates the risk of granting more than required access entitlements."},{"id":"The bottom-line","title":"The bottom-line","content":"To keep the identity management house in order, organizations implement several practices that include just-in-time privileges and granular controls. Implementing the basic identity governance practices, complements the other best practices in access management."}],"form_shortcode":"","choose_asset_type":"files","links":"","files":"","pardot_redirect_url":"","video_link":""}]},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Identity Governance: How to keep the House in Order? - ARCON<\/title>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Identity Governance: How to keep the House in Order? - ARCON\" \/>\n<meta property=\"og:description\" content=\"Probably the most convoluted IT practices of all, the Identity Management and Governance is always vulnerable to a security gap. After all, controlling a vast expanse that extends beyond the traditional realm of a datacenter demands careful planning. While spiraling cost issues and inadequate resources often undermine the identity governance approach, the inherent shortcomings are [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/\" \/>\n<meta property=\"og:site_name\" content=\"ARCON\" \/>\n<meta property=\"article:modified_time\" content=\"2026-03-12T06:45:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/arcon.xyz\/staging01\/wp-content\/uploads\/2026\/02\/Back-to-the-Basics-2-1-1024x455-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"455\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/identity-governance-how-to-keep-the-house-in-order\\\/\",\"url\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/identity-governance-how-to-keep-the-house-in-order\\\/\",\"name\":\"Identity Governance: How to keep the House in Order? - ARCON\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/identity-governance-how-to-keep-the-house-in-order\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/identity-governance-how-to-keep-the-house-in-order\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Back-to-the-Basics-2-1-1024x455-1.png\",\"datePublished\":\"2021-10-29T10:53:00+00:00\",\"dateModified\":\"2026-03-12T06:45:07+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/identity-governance-how-to-keep-the-house-in-order\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/identity-governance-how-to-keep-the-house-in-order\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/identity-governance-how-to-keep-the-house-in-order\\\/#primaryimage\",\"url\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Back-to-the-Basics-2-1-1024x455-1.png\",\"contentUrl\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Back-to-the-Basics-2-1-1024x455-1.png\",\"width\":1024,\"height\":455},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/identity-governance-how-to-keep-the-house-in-order\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Risk To Watch\",\"item\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Identity Governance: How to keep the House in Order?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/#website\",\"url\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/\",\"name\":\"ARCON\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Identity Governance: How to keep the House in Order? - ARCON","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"Identity Governance: How to keep the House in Order? - ARCON","og_description":"Probably the most convoluted IT practices of all, the Identity Management and Governance is always vulnerable to a security gap. After all, controlling a vast expanse that extends beyond the traditional realm of a datacenter demands careful planning. While spiraling cost issues and inadequate resources often undermine the identity governance approach, the inherent shortcomings are [&hellip;]","og_url":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/","og_site_name":"ARCON","article_modified_time":"2026-03-12T06:45:07+00:00","og_image":[{"width":1024,"height":455,"url":"https:\/\/arcon.xyz\/staging01\/wp-content\/uploads\/2026\/02\/Back-to-the-Basics-2-1-1024x455-1.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/","url":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/","name":"Identity Governance: How to keep the House in Order? - ARCON","isPartOf":{"@id":"https:\/\/arcon.xyz\/staging01\/#website"},"primaryImageOfPage":{"@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/#primaryimage"},"image":{"@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/#primaryimage"},"thumbnailUrl":"https:\/\/arcon.xyz\/staging01\/wp-content\/uploads\/2026\/02\/Back-to-the-Basics-2-1-1024x455-1.png","datePublished":"2021-10-29T10:53:00+00:00","dateModified":"2026-03-12T06:45:07+00:00","breadcrumb":{"@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/#primaryimage","url":"https:\/\/arcon.xyz\/staging01\/wp-content\/uploads\/2026\/02\/Back-to-the-Basics-2-1-1024x455-1.png","contentUrl":"https:\/\/arcon.xyz\/staging01\/wp-content\/uploads\/2026\/02\/Back-to-the-Basics-2-1-1024x455-1.png","width":1024,"height":455},{"@type":"BreadcrumbList","@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/identity-governance-how-to-keep-the-house-in-order\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/arcon.xyz\/staging01\/"},{"@type":"ListItem","position":2,"name":"Risk To Watch","item":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/"},{"@type":"ListItem","position":3,"name":"Identity Governance: How to keep the House in Order?"}]},{"@type":"WebSite","@id":"https:\/\/arcon.xyz\/staging01\/#website","url":"https:\/\/arcon.xyz\/staging01\/","name":"ARCON","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/arcon.xyz\/staging01\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/risk-to-watch\/46809","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/risk-to-watch"}],"about":[{"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/types\/risk-to-watch"}],"author":[{"embeddable":true,"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/users\/40"}],"version-history":[{"count":2,"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/risk-to-watch\/46809\/revisions"}],"predecessor-version":[{"id":49394,"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/risk-to-watch\/46809\/revisions\/49394"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/media\/47413"}],"wp:attachment":[{"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/media?parent=46809"}],"wp:term":[{"taxonomy":"risk-categories","embeddable":true,"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/risk-categories?post=46809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}