IBM software eases role-based security operations

By Ellen Messmer, Network World |  Security, IBM Add a new comment

IBM this week announced an identity-management analytics tool that eases what can be a tedious job for information-technology managers -- defining roles for employees in order to establish policy-based access to a network and application resources.

More on IBM: IBM wins most patents for 19th straight year

The software called "Security Role and Policy Modeler" has been added to the IBM Security Identity Manager suite, IBM's flagship product for policy-based access management and governance.

The tool is able to actively poll a wide range of databases and directories, such as Microsoft Active Directory, Oracle, Siebel and SAP, that are used to store information about employees, their jobs and current access privileges, says Marc van Zadelhoff, vice president of strategy and product management at IBM Security Systems,.

The IBM tool can then analyze collected information in order to define a set of roles and their recommended access rights so users can be grouped for security purposes. That makes it possible to provision or de-provision users based on role. "This automates the setup of role-based permissions," he says.

The modeling tool alleviates the need for more extensive manual reviews by managers to make decisions about organizational roles, which can be a time-consuming process in larger businesses with tens of thousands of people.

IBM is not the only technology firm to offer a modeling tool intended for this purpose, but IBM hopes its tool, developed at IBM Research, will be distinguished by its analytics, such as flagging unusual behavior or inconsistencies in role access and expired user access.

There will always be some employees who will not neatly fall into roles and will have to be regarded as exceptions, but IBM says the modeling tool makes it simpler to establish role-based arrangements for provisioning. There are early adopters of the tool, including Bharti Airtel, a telecommunications provider in India, and IT service company Cognizant. Cognizant's director of security, Barry Miracle, says he expected it would make compliance reporting more efficient.

IBM isn't breaking out the cost for the Security Role and Policy Modeler tool, but notes that deploying identity management in a large organization can run into the hundreds of thousands of dollars.

Read more about wide area network in Network World's Wide Area Network section.


Originally published on Network World |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question