To main content To navigation
Blog

Identity and Access Management (IAM) is not an IT matter!

Picture of Roy Dijkstra from CIMSOLUTIONS

As an IAM Cyber ​​Program Manager and consultant, I notice at many organizations that IAM is seen as something technical. It belongs to the IT department because it involves servers, passwords, and accounts. What stands out is that IAM implementations proceed with difficulty and are even halted, putting organizations at enormous risk in terms of cybersecurity.

IAM is not an IT matter but a Strategic Business issue. Especially in these times, it is one of the most important issues of the moment.

What is IAM?

With IAM, you ensure that the right people (and systems) have access to the right information, applications, and buildings at the right time. You must prevent unauthorized access.

It starts with Identification (who are you?), Authentication (are you who you are?), and then Authorization (you are granted access to information based on a number of criteria such as job title and/or department).

That seems simple, but in modern organizations where we work with cloud, partners, remote access, and AI, this is very complex.

Because with IAM:

  • We determine productivity (with good processes, we can grant access quickly)
  • We ensure that only authorized users have access. This is crucial for security and prevents reputational damage.
  • You ensure compliance (think of GDPR, NIS2, audit requirements). Auditors want to know “who has access to what and can you demonstrate that?”
  • You can support digital collaboration in SAAS (such as restricting access for external parties like partners and suppliers)

What does that mean?

If you approach IAM from a technical perspective, you miss essential elements regarding Governance and Policy within your organization to make IAM successful.

Think of:

  • IAM/Authorization policy translated into Authorization Principle and Matrix and the Role Model
  • Register where you record everything regarding Authorizations
  • Legislation (GDPR, NIS2, etc.) and compliance
  • Ownership, Decision-making, and Mandate

(Strategic) Ownership

In this blog, I focus on the most important Pillar: Strategic Owner.

The Authorization Process is a flow that runs through the entire organization. From HR/ERP via IAM to the (primary) process systems and applications. It is therefore a business-critical foundation for safe and efficient business operations and deserves the right priority and attention from senior management (C-level).

Characteristics of strategic owners are that they are accountable and mandated. They are capable of making (correct) decisions and improving the functioning of the organization. In addition, they are also functionally responsible for the operation of the governance organization, the audit cycle, and organizational behavior.

In concrete terms: As a strategic, managerial owner, you are responsible for formally approving and monitoring authorizations within your domain.

In conversations with strategic owners, I regularly see that they do not want to take on this role because they think they are also executors. You must reassure them by indicating that they are not executors but are ultimately responsible for:

  • Determining which roles may have access to which information
  • The approval process of authorization models and structures
  • Monitoring risks and compliance within their area of ​​responsibility
  • Encouraging periodic evaluation of authorizations

Conclusion

Start by appointing the strategic owner, be patient, and give it time. Once you have completed this step, the foundation stone has been laid for successfully implementing IAM. So, is IAM an IT matter? The answer is “NO”; IAM is how your organization works.

CIMSOLUTIONS has a Privacy & Security Competence Center with experienced consultants and program managers who can advise you on governance, mandate, and ownership, and are also capable of successfully rolling out and implementing IAM/IGA/PAM together with you. As a result, your business operations will be effective and efficient, and will comply with compliance and legislation.

Roy Dijkstra
Senior IAM Cyber ​​Program Manager and Consultant

Also interesting

Blog

From raw data to business value – Medallion Architecture

The Medallion Architecture, also known as the Multi-Hop Architecture, has received a lot of attention in CIMSOLUTIONS' knowledge-sharing sessions over the past year. This architecture forms the foundation of modern data platforms for a growing number of organizations.

Picture of Klim Mikhailov
Read article about From raw data to business value – Medallion Architecture
1 of 6 1 /