Thank you very much and a heartwarming welcome to the last day here of EIC and yeah, welcome to my talk here. It's about something that moves me around for now, yeah, a few years I would say, because like Federation, although we are talking already here about decentralized identities in a way beyond, yeah, about what is moving companies around, there's still a topic that now comes with various technologies into the play and therefore might need a closer view.
So the thing is, if you are already there utilizing decentralized identities in your company and so on, so you might get another view, but maybe you are at the beginning of this journey and I hope I give you some insights what you should think about and maybe also what to address to your management to get some budget, some time to take care about. So I want to start with a quick question here. Who has ever worked in an external Microsoft 365 tenant as a guest, yeah? Who is it like for Teams collaboration, joining a team, whatever, yeah? So I see a few hands raising.
Please keep your hands up because now comes the next question, yeah? And then there are two opportunity or two possibilities how this goes, but I'm prepared for both. So let's see. Who was aware about the responsibilities regarding this access? For example, the information security policies that apply, the IAM policies that apply, the obligations you have when you are entering this foreign domain.
Yeah, still a bit, yeah, but I also see a bit, a few of the hands falling. It's usually like this, the people who should listen to this are not there. So this is what I usually tell in the lectures, right?
So, and this is the core problem, what I would say. We are not aware what comes here, but why is this a problem?
And there, I want to show you a picture that one of you might recognize. It's the Tower of Babel, yeah? Where you have the people wanted to show their power and started to build a tower towards God.
And God, it's from the Bible, and God created a speak or language confusion, yeah? And therefore led to stopping this project. And this is how IAM sometimes feels. And even when you are crossing boundaries, we are talking somehow a similar language, but meaning different things. And when we are talking about federation, this becomes a crucial thing, yeah? But before we get really to the core of the topic, I want to start or to give you a view on why are we doing this? Why are we federating? So there are, of course, different drivers for it.
I want to have a closer look at this one because it becomes more and more relevant. The thing is, using federation, at least from my experience or what I have seen, a lot of companies are employing this particular concept because they want to fill the accuracy gap, yeah, of the data you have about your partners. So imagine you have, like, for a project, a contractor joining your company. You know these forms they are filling in service now or whatever, sending to your IAM team and manual typing.
Then this person joins within the partner company, a different department, leaves the company, and sometimes the access remains active, yeah? So why don't we get the data from there where the source lays, where the information is? Because obviously in the sending organization, they are aware about these changes.
So this, as I said, that's the reason, one of the reasons we are federating identities. Having said this, this should somehow be, yeah, aligned when you are shaking hands. And why did I choose this picture? Because you might know this, yeah, situation, it happens sometimes. You know someone, somehow it could be like in your business relationship, and then you are approaching someone, not sure if you shake hands or hug, and then this awkward situation is created, right, where you are not, like, knowing what to do. And this is somehow what you have also then with identity federation.
Not sure how the other one is treating identities, what they are doing, but sometimes you better do not ask, right? So if I close my eyes, maybe the problem, if I don't see the problem, the problem might also not see me. A little hint, the regulators see it differently. A hard learning for me.
So this is the situation we have, and with modern technologies, modern tools like Microsoft 365, Entry ID, you have tools and you have usually very, yeah, your administrators in the cloud environment are usually very, yeah, like to test, to play around and enable features and so on, sometimes not knowing so much about the impact. So, and this is then, could happen here, could happen, yeah, just to draw the worst picture, also have seen, integrating these tools, yeah, enabling federation between the tenants, but not having thought about the processes and the policies behind.
And then there, this void is created that causes risk, monetary risk, security risk, but also, of course, compliance risk. With the next years, with NIST 2, this becomes also another problem or, and also a solution, yeah, so the federation is a problem and a solution at the same time, because NIST 2 requires you to do, to implement robust cybersecurity supply chain measures. To implement these measures, federation can help you, but only if you do it under certain, under a certain framework, you establish trust through the framework you're establishing here.
You need to have the structured information that if the auditor comes and wants to see what you are doing there, you need to have the proof. And to get this proof, of course, you have to align how you can get this proof. Because when we are enabling federation, in a lot of cases, we have the issue that we are just talking about the top of the iceberg, yeah, about the nice and fancy business enabler.
We are saving costs, we are onboarding, faster onboarding, yeah, you know, maybe in the one or other organization, it takes like one or two weeks to onboard an external or whatever, and then the federation seems to be the nice tool that you have to make this all very easy and very fast, but you are neglecting parts of it that you have to do from a risk perspective, from a governance perspective.
And this is what you see then in the water, yeah, the auditing, nobody really cares about, in these cases, how you're doing the auditing or the recertification, yeah, under which circumstances is this done? Who is doing the recertification? If you have the person from the external company but not maintained someone who is observing this person, yeah, sponsor information, so-called manager information, whatever. So this all is a bit ignored, I would say, or at least neglected in some organizations.
This problem now occurs because this is how you see usually, traditionally, IM, yeah, you have a defined interface of this, for example, manual administration, where you kind of have defined via the forms that you have how the person gets into your system, you inform, yeah, if you change a department and so on, you inform if you're leaving the project, it's up to manager to do this, but you have clear interfaces. With moving towards the federation, this is starting to overlap, yeah, I know, nice animation, I hope at least. I was really impressed that this is now possible with PowerPoint.
So about this part, it is important to start or to be aware that you, on the one hand, are not like closing your eyes and saying, I hope the other one does it, better not to ask, but on the other hand, wherever you have redundancy, you have to manage it. The thing is, redundancy and processes can be intended, you know, like your redundancy is intended redundancy, so it's not always something bad, but here to say you have to manage it, you have to be aware about the responsibilities that one, that the partner organization has, but also what your obligations are in these terms.
And this, how do you achieve it? You have to kind of shape your organization like a puzzle, I would say. You have to leave not only interfaces in a technical manner, but also in the organizational manner. You have to start to really build your organization in a way that they have a part where they can connect and there with you leave the gaps that your partner can fill and then also has the opportunity or the responsibility assigned here. So what is the way to get someone aware about their responsibilities?
You have to also talk to your procurement, your legal department, because all the regulations that then apply to you, you have to also reflect and the contracts, you have to detail when you have to get like reports, what insights you are able to get, for example, how the joiner mover lever process is done and so on, how identities are verified, identity assurance level, authentication assurance level, the thing you might know already from the NIST policies that are there, the NIST documentations, the frameworks that are there, you have to really build and determine what is delegated, what is your partner responsible for, but also what is done if non-compliance exists.
We also, we all want just to talk when it is nice and see it as a business enabler, but what happens if something goes wrong, if you have a security incident, that this is not like also neglected and but also has a contractual foundation so that you are ensuring that you are not compromising your overall security. I have a practical view now on how it could be done.
Of course, in this talk that we have here, it is not that easy to like show a detailed view on how these things are done and what you could do. Of course, there are a lot of things out there how you could do it, but I want to give you here a starting point to have an overview how you could start with such an assessment, how you could, in which direction you could go here.
Of course, it starts all with the requirements. You have to get your stakeholders on board and like a usual IAM project, I'm not telling anything new here, of course, but of course, you have to involve your legal department, your contract management and talk to them what is coming, for example, from the contractual perspective in terms of your partners, what you can put into the contract as an obligation for them and also, on the other hand, what you are providing that these obligations can be fulfilled. On the other hand, it is like I already said, be aware what of course applies to you.
Is it NIST 2, for example, is it DORA? The compliance and risk management, of course, also defines how you have to treat this particular topic and then you have to assess, get an overview about the things that you want to delegate.
You are taking your process framework and see like, of course, I can only or can here again recommend here the identity fabric, the IAM reference architecture we are providing to see what of this architecture, of this framework I want to delegate and what not and then to define the standards here, to define what am I doing and to get an understanding also within your organization what is better. Better is always good, but what is below the internal standards, so that you have an understanding when you have to say no or to say under these and that circumstances we can all also implement this.
The IAM process framework should also consider the data quality behind it. Also, when you are talking about the processes, you have to talk about the process quality as well to understand how the partner organization is doing their business, doing their processes. One example is here for the synchronization, how fast are emergency levers treated, how fast are levers treated once the information is entered. Also to take this into consideration when assessing your partner organization.
And then at the end, you will get an overview of the partner organization, where you understand how they are doing IAM. Also to identify potential risks, you can define also mitigation measures, for example, or say under which circumstances you would be willing to profit from it. Because again, not the only driver is not governance and so on. It should be thought of. But of course, you could be saving money through licenses and so on. And this should be then harmonized or at least aligned with the risks that you have. And of course, at the end, it is a documentation for your audits.
When something is happening, then you always have to prove that you have done it, that you had an overview about how it went. And therefore, it is of course very important to have it documented. And as we know, this is often forgotten and not neglected. So it's a very easy graphic, but I think I just was thinking, how can I transmit the message that it is? Define non-negotiable standards for your organization. In terms of IAM, when starting the federation, you have to define where is the minimum what we require, and it should also be correlated to the data that it is accessed.
Of course, if you are just like, you know, the usual example of the cantina plan, yeah, that might be not needed to be that secured. But if you are accessing, if the provider accesses internal or confidential information, you have different requirements in terms of the processes. And that should be also reflected then within your assessment. Another thing is, of course, we are talking a lot about trust, yeah, and you're also like the circle closes. Trust is here the thing, but don't assume it. Validate it through sample validation. And there the topic of auditing comes into play.
You are as the receiving organization of the identities there and integrating, you are then also in a situation that you need to validate it through circles, yeah, and to perform audits. Also, this is something that then comes into play, and you have to request the information, for example, for the samples. And therefore, what I want to say here, the federation is not something that we just do because we want to save money. It's something that needs to be earned. It's a proof of close partnership and integration of two partners, and therefore, you need to see it that way.
It's not the standard you have to earn it. And then, again, this red line, protect your organization. Don't waste or send the efforts you have conducted with the pricey efforts in terms of IM by now just getting bad information, bad data, bad identities into your system, but ensure that also your standards are followed.
So, this is how we close, and this is what has guided me. Yeah, trust must be built, not assumed.
Yeah, so we are assuming a lot in our lives. We are assuming a lot in relationships.
Yeah, have the handshake in mind. Yeah, we're assuming a lot.
So, when we're doing federation just under the existence of governance, of contracts, of verification, ensure if the partner is not ready, don't start the federation. Do the structural work, the structural clarity before you start the integration. Don't start with the tool integration again, but start up front.
And then, of course, integrate with the existing governance frameworks in your organizations that you have established already, like to build another IAM silo will, of course, not help. Integrate it with the risk management you have, with the other governance you have in the organization.
And yeah, as you see, federation is earned through maturity. So, mature organizations can cooperate here with mature organizations and not to compromise your level of IAM maturity that you have. That's it. Thank you very much.