For Security & Risk Professionals (Length: 15 pages)

September 30, 2008

Best Practices: Enterprise Role Management

by Andras Cser

with Jonathan Penn, Allison Herald


Executive Summary (This is a document excerpt)

Enterprise role management plays a central role in efficiently managing access rights and enforcing access policies such as segregation of duties (SoD). The processes and tools related to role management consist of role mining and design, recertification, and access recertification. Forrester's IT end user interviews revealed that successful organizations implement and maintain enterprise roles by: 1) establishing a closed-loop process that covers all strategy, people, process, and technology aspects of role management; 2) leveraging existing access information and repositories for role definitions; and 3) targeting simple areas that yield high return, such as where there is high employee turnover or where the workforce performs common and repetitive tasks requiring access to a limited number of applications and application features. Next practices include: 1) feeding access log information to the role management system to ensure that role definitions remain up-to-date and reflect how applications are being used; 2) using entitlement management solutions to enforce fine-grained access policies tied to enterprise roles; and 3) extending role definitions to identify federation partners.

Buy Risk-Free

Download and print PDF immediately. Price: US $499

Our Money-Back Guarantee: If you are not completely satisfied, return it for a full refund within three weeks of your online purchase.

Already a Forrester Client?
Log in to read this document.

Add to cart

TABLE OF CONTENTS

NOTES & RESOURCES

itemWhat Is Enterprise Role Management And Why Do We Need It?

itemBest Practices In Enterprise Role Management

itemBest Practice No. 1: Establish A Closed-Loop Process

itemPitfalls To Avoid

itemBest Practice No. 2: Leverage Existing Access Information And Repositories

itemPitfalls To Avoid

itemBest Practice No. 3: Target Simple Areas That Yield High Return

itemPitfalls To Avoid

itemForrester's Enterprise Role Management Next Practices

itemIdentifying Your Challenges

itemCase Study

itemSupplemental Material

In developing this report, Forrester drew from a wealth of analyst experience, insight, and research through advisory and inquiry discussions with end users, vendors, and regulators across industry sectors.

Related Research Documents

itemCase Study: North American Financial Services Company Defines An RBAC Vision And Services

August 28, 2008

itemThe Forrester Wave™: Identity And Access Management, Q1 2008

March 14, 2008

itemUser Account Provisioning For The Midmarket

August 20, 2007

Find Documents In Related Categories

This document falls under the following categories. Click on a link below to find similar documents.

Analyst: Andras Cser
Technology: Identity & Access Management, Security & Risk
Industry: Financial Services
Geography: North America

Upcoming Teleconference:
Shifts In Security Architecture
Tuesday, December 08, 2009
corner border corner
Ratings and Comments
NOT YET RATED
corner border corner