|
15:00 -16:00 CET, 9am Eastern |
Keynote
The Three Elements of Access Governance: Recertification/Attestation – Access Control – Privileged Access Management
Access Governance is commonly associated with “recertification” or “attestation” as approaches for a recurring review of existing access controls by the responsible managers in IT and business. But knowing the problems isn’t sufficient – enforcing changes and implementing continuous processes for access controls is a key element. And, beyond that, many approaches mainly focus on standard access and not on the security sensitive privileged accounts. This session explains the elements for a consistent approach – across all areas of access governance and all levels of controls, from system to business.
MORE INFORMATION
SPEAKERS
WATCH NOW
|
|
|
16:00 - 17:00 CET, 10am Eastern |
Presentation + Discussion
Getting the Big Picture: How Access Governance fits into IT Governance and Risk Management
Access Governance is a key element in every strategy for information and system security as well as IT Governance. However, there are many different approaches from system-level access control management tools for ERP systems with some SoD support up to “Enterprise GRC” solutions which focus on the risk management and governance approaches from a high-level business perspective, sometimes without the interface to IT systems. And access-related controls are only part of that – 4 of 210 controls within COBIT, for example. For sure they are highly relevant, but they are only part of a bigger story. The link from business controls to IT controls and the role and relevance of the access-related IT controls covered by access governance with respect to complete IT Governance frameworks like COBIT is explained in this session. The different elements and approaches to governance are put into context and associated with the GRC roadmap of Kuppinger Cole.
MORE INFORMATION
SPEAKERS
WATCH NOW
|
|
|
17:00-18:00 CET, 11am Eastern |
Presentation + Discussion
5 Golden Rules for Efficiently Implementing Access Governance
How to do Access Governance right? Which are the key success factors you have to focus on for as well quick-wins as long-term success? This session explains how to solve the access governance needs best.
MORE INFORMATION
SPEAKERS
WATCH NOW
|
|
|
16:00 - 17:00 CET, 10am Eastern |
Panel Discussion
XACML: The Holy Grail of Access Governance?
In this panel, the role XACML will and can play for access governance is discussed. Is XACML the solution? What is missing? How to manage policies and how to analyze these dynamic constructs? And how to avoid vendor lock-in? The strengths, shortcomings and needed improvements are discussed by different vendors and Kuppinger Cole analysts.
MORE INFORMATION
SPEAKERS
WATCH NOW
| Partners: |
|
|
|
|
|
17:00-18:00 CET, 11am Eastern |
Panel Discussion
How to Efficiently Implement SoD Controls: Which Level Works?
SoD controls (Segregation of Duties) are a cornerstone of access governance. But how to efficiently implement them? Should they be based on roles, on activities, on granular entitlements? There are many different approaches to solve the problem. In this panel, different vendors and Kuppinger Cole analysts will discuss different approaches for SoD controls, with focus on their manageability and the required granularity.
MORE INFORMATION
SPEAKERS
WATCH NOW
| Partners: |
|
|
|
|
|
18:00 - 19:00 CET, 12am Eastern |
Panel Discussion
How to Start: Recertification or Active Access Controls First?
What is the best approach to do access governance? Should you start with attestation to understand where the problems are? Or should you first have a management infrastructure in place which allows to control access across different systems and use access governance approaches then to improve the state of your information security? Or is recertification sufficient? Kuppinger Cole analysts and different vendors discuss the strengths and weaknesses of different approaches?
MORE INFORMATION
SPEAKERS
WATCH NOW
|
|