290 likes | 597 Views
IAM – GRC - SOA. 03.06.2008 Martin Kuppinger, KCP mk@kuppingercole.de. Identity Management: Vision – five years from now…. Business. Business Control Enterprise Entitlements (IAM for Business). Standardization and Services:
E N D
IAM – GRC - SOA 03.06.2008 Martin Kuppinger, KCP mk@kuppingercole.de
Identity Management:Vision – five years from now… Business Business Control Enterprise Entitlements (IAM for Business) Standardizationand Services: Services, Application Security Infrastructure, Integrated IAM (IAM forApplications) Fundamentals: Integration and (Basic) Provisioning (IAM for Administrators) Technology 2008 2009 2010 2011 2012 2013 © Kuppinger Cole + Partner 2008
Two definitions to start… © Kuppinger Cole + Partner 2008
IAM – SOA – BSMUnsolved relationships… Controlling IAM Services End-to-End Security „ERP for IT“ App Security Infrastructure GRC Services on App level © Kuppinger Cole + Partner 2008
GRC: Governance, Risk Management, Compliance © Kuppinger Cole + Partner 2008
GRC Market:Level 1 © Kuppinger Cole + Partner 2008
GRC Market:Level 2 © Kuppinger Cole + Partner 2008
Generic GRC tools:General purpose © Kuppinger Cole + Partner 2008
GRC:Business Control for IAM © Kuppinger Cole + Partner 2008
Layered approach © Kuppinger Cole + Partner 2008
Multi-layered IAM:Business Control for IAM OM ECM Enterprise Roles BPM PPM … © Kuppinger Cole + Partner 2008
GRC: The way towards an integrated system of control © Kuppinger Cole + Partner 2008
Tactical and strategical:The right tool © Kuppinger Cole + Partner 2008
Why SOA Governance is relevant © Kuppinger Cole + Partner 2008
Some issues © Kuppinger Cole + Partner 2008
Missing end-to-end security © Kuppinger Cole + Partner 2008
Missing service management on the software level © Kuppinger Cole + Partner 2008
Missing reuse © Kuppinger Cole + Partner 2008
The main reason why:Siloed IT organizations Infrastructure Software architecture and development © Kuppinger Cole + Partner 2008
The technical solution Application Application Application Application Requires organization changes first! Application Infrastructure: Application Server, Orchestration,… Application Security Infrastructure: Identity Services Layer Central Directories Auditing Services More Services Application Directories © Kuppinger Cole + Partner 2008
How to reengineer (or even create) SOA Governance © Kuppinger Cole + Partner 2008
Reorganize IT:Some ideas… © Kuppinger Cole + Partner 2008
Apply BSM principles © Kuppinger Cole + Partner 2008
Apply risk controls © Kuppinger Cole + Partner 2008
Conclusion: There has to be SOA Governance © Kuppinger Cole + Partner 2008
IAM – SOA – BSMUnsolved relationships… Controlling IAM Services End-to-End Security „ERP for IT“ App Security Infrastructure GRC Services on App level © Kuppinger Cole + Partner 2008