Blog
Identity and Access Management (IAM) is not an IT matter!
IAM is not an ICT matter, but a strategic issue revolving around governance, policy, and clear ownership.
As an IAM Cyber Program Manager and consultant, I notice at many organizations that IAM is seen as something technical. It belongs to the IT department because it involves servers, passwords, and accounts. What stands out is that IAM implementations proceed with difficulty and are even halted, putting organizations at enormous risk in terms of cybersecurity.
IAM is not an IT matter but a Strategic Business issue. Especially in these times, it is one of the most important issues of the moment.
With IAM, you ensure that the right people (and systems) have access to the right information, applications, and buildings at the right time. You must prevent unauthorized access.
It starts with Identification (who are you?), Authentication (are you who you are?), and then Authorization (you are granted access to information based on a number of criteria such as job title and/or department).
That seems simple, but in modern organizations where we work with cloud, partners, remote access, and AI, this is very complex.
Because with IAM:
If you approach IAM from a technical perspective, you miss essential elements regarding Governance and Policy within your organization to make IAM successful.
Think of:
In this blog, I focus on the most important Pillar: Strategic Owner.
The Authorization Process is a flow that runs through the entire organization. From HR/ERP via IAM to the (primary) process systems and applications. It is therefore a business-critical foundation for safe and efficient business operations and deserves the right priority and attention from senior management (C-level).
Characteristics of strategic owners are that they are accountable and mandated. They are capable of making (correct) decisions and improving the functioning of the organization. In addition, they are also functionally responsible for the operation of the governance organization, the audit cycle, and organizational behavior.
In concrete terms: As a strategic, managerial owner, you are responsible for formally approving and monitoring authorizations within your domain.
In conversations with strategic owners, I regularly see that they do not want to take on this role because they think they are also executors. You must reassure them by indicating that they are not executors but are ultimately responsible for:
Start by appointing the strategic owner, be patient, and give it time. Once you have completed this step, the foundation stone has been laid for successfully implementing IAM. So, is IAM an IT matter? The answer is “NO”; IAM is how your organization works.
CIMSOLUTIONS has a Privacy & Security Competence Center with experienced consultants and program managers who can advise you on governance, mandate, and ownership, and are also capable of successfully rolling out and implementing IAM/IGA/PAM together with you. As a result, your business operations will be effective and efficient, and will comply with compliance and legislation.
Roy Dijkstra
Senior IAM Cyber Program Manager and Consultant