Digital transformation is expanding organizational attack surfaces through initiatives like digital workplaces, DevOps, security automation, and IoT, creating new risks that must be assessed and managed without disrupting business operations. Identity Governance and Administration (IGA) is positioned as a core discipline for improving security posture through end-to-end identity lifecycle management, entitlement and policy workflows, role management, access certification, Segregation of Duties (SoD) analysis, reporting, and access intelligence. Weak IGA capabilities expose organizations to identity theft, unauthorized changes, access creep, role bloat, delayed fulfillment, orphaned roles/accounts, and SoD conflicts that can enable internal fraud. IGA is also framed as the convergence of Identity Provisioning (fulfillment across the lifecycle) and Access Governance (business-facing tools for workflows, certifications, reporting, and SoD checks), with access intelligence providing analytics for decision support. Privileged Access Management (PAM) is increasingly adjacent to IAM, with a possible future convergence with IGA via partnerships or built-in features, though potentially limited.
Oracle addresses governance needs with Oracle Identity Governance (OIG), available via the Oracle Cloud Infrastructure (OCI) Marketplace as part of Oracle Identity Management (IDM) 12c, using cloud-native approaches to support compliance-driven enterprise use cases and automated lifecycle governance. Key capabilities include lifecycle management, access requests and certifications, RBAC, SoD controls, and analytics reporting on access. OIG 12c streamlines application onboarding via a self-service wizard UI, optional Groovy transformations, bulk onboarding, REST APIs, and automated schema/data-type discovery, plus reconciliation, connector cloning, and scheduling. Role lifecycle management adds role discovery, role mining, and business-friendly policy authoring, including converting existing grants/requests into role-based grants. Certification features support campaign targeting and reviewer customization, while REST APIs enable web/mobile self-service. Broad connector coverage supports hybrid and SaaS targets. Security enhancements include JWT for SCIM/REST, TLS 1.2 ciphers, improved keystore management, and request header/origin controls. Deployment emphasizes Docker, Kubernetes, Terraform, CLI-driven automation, and multi-cloud support, though challenges include Oracle database dependence, RBAC without dynamic authorization, and no PAM offering.
See All Locations
See All Locations