What is IAM, Identity and Access Management?

Publié :

12/2022

| Mis à jour le

-
Articles
>
Les brèves
Can everyone connect to the company's information system? And does each user have the right to do everything? No! Let's see how to control and regulate these accesses.

Summary

We are going to talk about IT IAM or an IAM solution. The acronym IAM stands for Identity and Access Management.

IAM is the control of identities and access; it says who is a user in the company and what they are authorized to do for each application.

Identity and Access Management encompasses control over users, accounts, and applications within the IS.

Users are physical persons within the company. Users should not be confused with accounts. The HRIS is therefore the source of truth at the user level.

Accounts are all the access rights created for users to access applications or software. Each user has multiple accounts. These accounts must be listed and known to everyone, otherwise they fall into the shadow IT category.

Applications must also be identified and listed in the company's IS.

What is the purpose of Identity and Access Management?

After being identified, a user does not have all rights. This allows the company to control its internal security. Accounts that do not have the same levels of rights are not all as sensitive in the event of a cyberattack.

Thus, a user who does not have the correct rights and access will be immediately identified in a good IAM system and can be quickly and easily corrected.

With the modification of uses, teleworking and face-to-face, cloud and on-premise, the management of rights and access has become a real challenge for the IT department, which is why identity and access management is useful. It helps to frame and supervise all these sensitive points.

We distinguish between technical IAM and governance IAM.

One will manage the technical part with authentication, the other, the user lifecycle and account management.

Can Identity and Access Management be self-managed?

Yes, of course, in the same way that you can also install all the electrical circuits in your house yourself. However, it requires skills, tools, a comprehensive understanding, and a clean, reliable, and fast technique.

If you carry out the electrical installation, but your cables are poorly connected, the fuses blow randomly, or you separate and are no longer able to manage the installation, this 'homemade' will be rather harmful.

In IAM it's the same, it's difficult and cumbersome to maintain, it's preferable to delegate this to experts because the solution will be more elaborate, less expensive and less cumbersome than a proprietary solution.

Besoin d'évaluer le coût d'un projet d'IAM ?

Téléchargez ce livre blanc sur le coût de l'inaction dans l'IAM :

Nous n'avons pas pu confirmer votre demande.
Votre demande de livre blanc est bien prise en compte.

Recommended Articles