English   Deutsch

Martin Kuppinger: No Information Security Without Identity

No Information Security Without Identity
by Martin Kuppinger
mk@kuppingercole.com
So what is the poor IT guy to do? One way is to use "soft" sales arguments, and that's why compliance has become so popular recently. It helps, of course, that regulatory compliance actually is a big issue nowadays. However, most compliance demands tend to be rather fuzzy, and besides, IT people aren't lawyers so they tend to lack hard answers when asked by business managers to provide particulars about certain items of compliance legislation. And even if they do, the other side usually fires back something like "SOX doesn't concern us anyway!"; conveniently overlooking the fact that there is much more to compliance than SOX - or to put it another way, compliance starts way before SOX.

There are such things as data protection laws, for instance. And the public has a nagging habit of asking who actually has access to which sets of data and how in tarnation did they just get leaked again! Auditors are also prone to ask unpleasant questions about compliance issues concerning both external and internal regulations. The word "compliance", after all, means following the rules.

Data protection is actually a good example since it shows what IAM is really all about. Identity and Access Management, after all, isn't just an end in itself. Neither is it some purely theoretical problem. Instead, it's the result of a relatively simple demand that has been around since the early days of IT, namely: „Make sure our information is safe!"

Part of IAM's job is protecting data, either directly or by protecting the systems that use and store data. That is also the backdrop against which compliance regulation, both internal and external, must be viewed. That also means that it is much easier to talk with business people about "access" rather than about "identity". The big question is how do we control and monitor access to information and systems? To do that, we need to know who is allowed to do what - and who isn't. The only way to achieve that goal is through true digital Identity Management. Anyone who thinks he can do it by granting rights and approvals based on IP addresses or MAC numbers is seriously kidding himself.

Good IAM is the fundament on which to build information security - nor else not. Individual measures such as banning or monitoring things like USB sticks can help, but only if they are part of an overall system. Companies today need an "access strategy" which determines who is allowed to do what in my system. That cannot be done by a trying to apply and enforce a bundle of unconnected ad-hoc measures.

So selling IAM is actually quite easy, if you think about it. All you have to do is put it in the context of information security and risk management. The danger of losing intellectual property, of being caught ignoring the law or of corporate systems being compromised should be strong enough arguments for even the most hard-headed boss. At least they are stronger than trying to sell IAM as a technology and as yet another part of the company's IT plumbing. Yes, IAM is an essential infrastructure component, but it is also much more than that - namely the basis for a comprehensive security concept and a good investment in more IT security.

Created: 01.12.09, modified: 14.12.09

top
KuppingerCole Select
Register now for KuppingerCole Select and get your free 30-day access to a great selection of KuppingerCole research materials and to live trainings.
Register now
Research
KuppingerCole CIO GPS
The KuppingerCole CIO GPS shows the nine areas CIOs should focus on for IT Spend Optimization, Business IT/Alignment, and Strategic Procurement, when looking at GRC (Governance, Risk Management, Compliance) and Information Security. GPS stands for Governance, Privacy and Data Protection, and Security.
KuppingerCole BII: The Business Impact Indicator
The KuppingerCole BII is a Business Impact Indicator for Information Technology. It shows the business value a particular technology or initiative can deliver, in a single and clearly laid out graphic. It complements other KuppingerCole research methodology that shows which technologies are best for achieving the targets in IT Spend Optimization, Business/IT Alignment, and Strategic Procurement.
Services
KuppingerCole Analyst Services
In the networked economy of the 21st century, digital identities play a key role in establishing trust, achieving security, lowering costs and making business processes more efficient. Things like Identity and Access Management (IAM) or...
KuppingerCole Vendor Services
The market for Identity and Access Management (IAM), governance, risk management, and compliance (GRC) and cloud computing is expanding by leaps and bounds. In fact, no other segment of the IT market can boast such dynamic growth rates. At the...
KuppingerCole Briefings
KuppingerCole welcomes the opportunity to hear from IT companies when they launch a new product or service or have other interesting progress to announce. Please fill in the request form , and we will contact you shortly. 
Links
 KuppingerCole News

 KuppingerCole on Facebook

 KuppingerCole on Twitter

 KuppingerCole on Google+

 KuppingerCole at LinkedIn

 Our group at LinkedIn

 Our group at Xing

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2013 KuppingerCole