Very quickly, Matthias Reinwarth, Director of Practice IAM at KuppingerCole Analysts. Not much more to say. Thank you. Heiko Klarl, good morning everyone, CEO of Nexis, focused on authorization governance. Good morning, Jason Gzym, I work for Pathlock and I run the global pre-sales and advisory practice at Pathlock. I'm Anders, I work with developer relations at Styra, the creators of the Open Policy Agent project. And my name is Andrew Hartnett, I'm the CTO of One Identity. I come from a slightly different background, representing those from the engineering and development world.
Perfect, thank you so much. I think we let's dive right into the panel. First question I have for you is, how can compliance frameworks adapt to support real-time role-based and context-aware access without introducing new vulnerabilities? I would just like to mention to the audience as well, it will be an open floor, so if you have any questions in between, let us know and we'll deal with them.
And also, maybe you would like to give some context on why we are moving to dynamic access models. I mean, we came from static models, and why does compliance now have to adapt to that also? Who wants to start maybe? I don't know, Matthias, let's start with you. I think when it comes to dynamic authorization management, this is something that we see actually some years already right now. When it comes to creating infrastructures, volatile dynamic infrastructures in the cloud, but also in your own virtualization environments, you need to deal with these environments properly.
That means a lot of automation, a lot of adaption to what is currently your business model, and static roles just do not do the job anymore in many cases. So you need to find a mechanism to make sure that your access is proper at any time of the lifecycle of an application. And of course, regulators have realized that as well, so they ask for proper control of these access requirements at runtime, and that is why we need to deal with that. I think that's the main starting point. It's almost a truism.
It's really we're changing infrastructures much more frequently and access much more frequently than we check. And ephemeral accounts that are used in the cloud are one of the major drivers for this. And from my perspective, I see what's driving some of this dynamic change leading into the massive explosion of NHIs needing companies to be able to manage this.
Yeah, I think you heard Martin say standing privileges should be dead, right? Wait for my presentation after this.
So I mean, if the application allows for that to exist in zero standing privileges, then you're not reviewing the access that people or things have, but you're governing the policy that's allowing the runtime authorization of whatever that is giving access to the application or entity. And I think the governance of those policies for runtime access is very important. That shift from static review of access to reviewing the policy that gives the access runtime versus admin time. Absolutely. So I had a session before on NHI and a question was there.
Kind of similar to yours, are there new vulnerabilities when I switch my model? So when I do a proper maintenance of NHIs or when I do a proper maintenance of dynamic access? And basically, like in classic IGA, if you do nothing, tomorrow everything is the same as yesterday. So from a manager's perspective, the best thing will be don't do any recertification, don't do any rejections because your team can work. But from a compliance perspective and from a company risk perspective, it's completely different.
So basically, yes, for sure, there might be every now and then an error until your processes have adapted seamlessly. But there is no alternative to have kind of dynamic access control in order to have continuous recertification of policy assignment, of access assignment. The key to success is basically if something was over the edge, that you have proper processes to fix them afterwards if you have probably reduced too many rights or policies.
Yeah, I think from like the policy world where I'm from, what we have been seeing is, and I think aligning with this, is largely moving away from this idea that you can up front say like we're doing RBAC or ABAC or REBAC or all these acronyms for a model where you decide and then you try and kind of retrofit your whole authorization model or permissions model in to work with that. Where instead now you might use all of these technologies or like frameworks for working with permissions. And you don't have to pick one, but you need systems that are flexible and can do this.
And you're talking about frameworks, there's two parts of the framework. There's the policy, but then there's also the tooling, right? And I think, yes, I'll be the first on this panel to bring up those two letters, AI. AI will be a useful tool to help us to these ever-changing policies and the need for them. So having tools that can adapt to that, AI-based tools I think are definitely going to be the future. But then there's just old school. You need to have auditing in place, right? You need to be able to do these things manually when needed.
And there are plenty of tools out there that can help you out with this in the current changing environments. And to go back to his questions, how can compliance frameworks support it? I think this continuous controls management, the monitoring, that is actually the way to move forward. If it's mere pattern matching or if it's just the auditing part or if it's maybe the AI that can support there, I think the continuous part is the important part because regulations demand for that as well. Absolutely. I think you touched on a very good topic of AI and automation as well, Matthias, you earlier.
How can we maintain transparency with respect to that, with this ever-evolving rise of automation and AI-driven access decisions? So maybe you can start, Matthias. So how can we protect the AI or how do we govern the AI? How can organizations maintain transparency and accountability?
Yeah, first of all, this is not an IAM topic. It's really providing proper model governance. So really taking care of your AI, giving guardrails, understanding what it does, define expected behavior, identify drift and act upon that. I think that is one important starting point. This is not an IAM topic, but this is the thing that does the work. So we need to take care of that in the first place. One of the areas that this is moving into is, they call it XAI or explainable AI, which is, okay, tell me how you made that decision, right? And then again, audit it.
In the AI world, they call it training, right? But constantly going back, double-checking, human interaction, I think the combination of those things have to be there. And basically picking AI or different approaches in the right way. So if you just want to count numbers, count numbers. Don't use Chen AI, so why? If you want to do things that can be done in an excellent way by machine learning, go ahead. Then you save a lot of infrastructure power and you can reduce your costs and you have a more discrete outcome. So explainable AI, because it reproduces exactly.
And if there is a use case that fits 100% to Chen AI, go for Chen AI. For example, when it comes to explaining what's behind an authorization cost, that's often the difficult part for business owners. What's basically in the bucket? So it has a nice name and I expect it could be, but sometimes it's a game of guessing. So when I get an explanation based on documentation and concepts from the application owners, I can really help business users to understand, okay, I'm giving this person an assignment to a policy, to a role, whatsoever. And it's exactly doing this and this in the system.
And this helps enormously from a customer satisfaction or end user satisfaction point of view, but also from a business owner point of view. You bring up a good point and that's about with AI being this faceless thing, how do you build trust? And you build trust by constantly verifying. And I think that's the human interaction, developing those deep audit trails. And so that you can, over time, just really have a good understanding that, yes, this is actually doing exactly what I want it to do.
Yeah, thank you. Now let's move to the regulatory frameworks, since we covered AI. How do the evolving frameworks like Dura, Nis2, you name it, how do they influence the design of access governance programs?
Yeah, so your most financially critical applications, your ERPs, where you're doing payment processing, vendor management, these regulations really tie into your most crown jewel applications, right? Your SAPs, Oracles, et cetera. And looking for the ability for humans and even non-humans to have toxic combinations of access that would allow for internal fraud to occur. That's what these regulations are for, right? To prevent that. So you want to have business processes in place that are looking for that, but not just static, dynamic access.
If you look at data protection within these applications, it's very important to have a policy that says an admin should be able to see PII of EU citizens, but not American citizens or vice versa. So the regulatory frameworks as they evolve, we all have to evolve with them and look at the business process to protect those crown jewels, right? And do it in a dynamic manner because less resources, AI, et cetera, continuous controls monitoring. So you have to evolve with the regulations themselves as they evolve.
Yeah, I'd say kind of related to that, this idea of the role of a super admin that can do anything. It's basically dead by now, or it should be. There's no such thing that would be allowed by any of these frameworks. And another thing I think as far as influencing design would of course be that I think this idea that access control or permissions is something that you can do as a last step of your application or your systems. It's like that's also not going to work. That needs to be there from the start. And that needs to be an integral part of the whole system design. Absolutely.
And so what I like with all this kind of regulatory requirements, whether it was GDPR in the past or now NIS2 and DORA, it gives us the chance to clean the kitchen or to clean the house. So IT tends to get dirty sooner or later. So if there is an external influence to force us to keep the things continuously in a clean way, that's basically good. It might be for sure annoying if you have to clean up your systems, if you have to document, if you have to manage risk. But it's the same way annoying as to clean your kitchen after a cooking session. Let me give you one example.
DORA, for a financial institution, it's required to have an authorization concept. So describing for each and every application what are the critical entitlements, SOD constraints, what the application is actually doing. When you are a large organization with 1,500 applications, it's probably not the nicest work to do so, especially if you go for Word and Excel spreadsheets and kind of a continuous outdated status of the documents.
If you solve it in a programmatic way, because kind of end-to-end integrated, you fetch out the data from the connected IGA systems, probably use Chen AI to support kind of description and summarize documentation. You can turn it around from a kind of burden that you have documented, that you have to document it, into a business enabler that helps you with application onboarding. So instead of firing an email out to your Microsoft Entra ID administrator, in the sense, if this kind of person still exists, I want to have to have five entitlements. Or better give me ten, then I'm on the safe side.
And then you are using just three in the wild. So basically, if you have specification first, and then a provisioning via IGA capabilities of the target system, that's the way to go. That's a funny coincidence. I published yesterday an article on LinkedIn about this kind of stuff, so it might be interesting for some of you as well.
Yeah, but if you look at what actually Dora and NIST, too, have as common denominators, it's A, coverage of third parties. This is something that people often did not care of. And continuous risk management, and really trying to identify changing risk and reacting upon that while you walk. And I think that is something that many organizations have not yet embraced completely, to understand that they need to understand what's going on, that they need to act upon that, and maybe even do some notification to involved parties.
And in a reasonable time, I think three days, I'm not an auditor, but not many organizations are prepared for that. And that all means that the governance framework does not, it must not be an isolated thing, but it needs to communicate with your enterprise GRC, with those people who talk to involved parties. And that is something that involves maturity in processes and the ability to react in real time.
Yeah, I think maybe one other angle there is, years ago, speaking of auditors, the auditors really could only go after the big fish. There just weren't enough humans to go around and try and look at enforcement and have these conversations.
Nowadays, this is done with software. And so, it used to be just the enterprise companies really had to be worried about these compliance regimes, but now everybody is, down to literally the mom and pop shops, because they have now the ability to be audited via software that just wasn't available 10 years ago. So it is becoming very, very important. And the way that I look at it, coming from the engineering perspective, I build tools that help with this, but I also have to get audited myself.
So, of course, at One Identity, we drink our own champagne, we use our own tools to help us out with that. But it just becomes, to me, when I look at NAS2 or DORA, the foundation of it, I agree with totally. As a business person, yes, everything that they are bringing up makes total sense to me.
Now, you can get into the weeds with some of the things, but in general, that's the way I look at it. All right. Thanks so much.
Now, you already mentioned that it can be quite challenging to balance the regulation and staying efficient at the same time. So do you have any leading practices, or let's say best practice, any experiences, how to balance compliance and efficiency, especially in regulated organizations or industries? I think Heiko said it well, it's hard to clean your kitchen. So when you put in the effort to clean your access, wherever that is, you want to then implement continuous controls to keep it clean.
It's much easier to keep something clean than let it get dirty over and over and over in the effort to get it clean in the first place. So continuously monitoring your own controls for access to any application, whether it be cloud, using OPA, Ofsted, other types of things, or these applications that only allow for standing privileges, they don't support a dynamic authorization layer. You really want to look at best practices across your portfolio, get it clean, and then implement continuous controls to keep it clean.
And that drives efficiency because there's more resources to clean up your room once. To keep it clean should take less resources and be more efficient.
Yeah, and of course this is the idea of trying to unify access control or authorization or permissions, or policy release is of course one of the core concepts of open policy. And I think whether we clean our kitchen or not, it's like what we all want is to not have these thousands of kitchens to clean. And they all look different and they all require different tools or different cleaning equipment or what you want. So that is trying to reduce just the number of the surface area that you have to clean up or have to maintain. I think it's important whether you use OPA or not.
I think maybe even just starting from the very top level is adopting zero trust philosophies and then finding the tools that can help you with that. I think just going back to the very basics.
Yeah, the buzzword of last year's EIC was ITDR. And if you think of it as the Roomba cleaning the floor of the kitchen, I think that can support and the basics in cleaning up the tough stuff and do the heavy lifting and you can focus on what's really important and what is maybe, which needs human oversight, for example. Adding on that, speaking about ITDR, which is kind of focused on the runtime aspect, when you think of ISPM to have another approbation where you can also check the admin time.
So when it comes to kind of authorizations, to role assignment, policy assignment, however you name the child, you can check for kind of overprivileged identities about toxic combination, about SOD constraints and so on and get it up front and get rid of it up front. And when you have a clean state, you can monitor it. So when some identities have become overprivileged for whatever reason, you can act immediately as you see, okay, this is not okay.
I do now a dedicated recertification with the manager, with the business owner or so, to have this kind of continuous process, not just waiting for the winter time and the next regular recertification would have happened. Audit season. Audit season, yeah. So when you take it serious, you have the audits not just for getting the certificate or your ISO 2701 compliance or so. It should be done by heart. So basically to secure your enterprise and to manage your risks is the homework to get finally the certificate from the auditor.
And another, and this is directly in my face, very close to what you just brought up is talking about what are the other things that we have to do, right? And one of the things that is in my face right now because I just got an email talking about auditing season. In our company, we have the cybersecurity awareness training season. So training is another thing that we need to ensure as getting back to the human side of things. I have to go do my training. It's my time of year. It's actually our whole company's time of year just to ensure that that happens.
But regular cybersecurity training is part of those policies, right? True. We have just over a minute left. So I'll just quickly pause and see if anyone in the audience has any questions. All right. Maybe some summarizing thoughts, maybe, Matthias, from you.
Yeah, a good starting point is getting away from standing privileges and if you stay in the room. I think that is really an important thing. Anything that is not there that you cannot misuse is a good thing. All right. Thank you so much. Help me. Was there something?
No, no, no. Thanks a lot. Thank you.