Knowledge Article

A phased approach to identity security

Author

  • ryan_cutter

    SailPoint

Successful identity programs are often broken down into manageable phases, allowing organizations to prioritize initiatives according to strategic goals, resource availability, and changing business needs.

This article provides best practice information on suggested phasing, aligned with the key Identity, Connectivity, Data, and Security Workstreams, to optimize your identity governance programs.

Data model hero@2x.png

Introduction to phased implementations

Adopting a phased implementation strategy enables organizations to:

  • Manage complexity: Break down complex initiatives into manageable segments.
  • Prioritize effectively: Allocate resources to the most critical tasks.
  • Adapt to change: Adjust objectives based on shifting organizational priorities.
  • Enhance collaboration: Foster effective communication among stakeholders.
  • Ensure continuous improvement: Assess progress at each stage and make necessary adjustments.

This approach not only enhances project management but also fosters a dynamic environment where responsiveness and adaptability are key to achieving success. Below is a suggested phasing aligned with the workstreams mentioned above.

Phase 1: Foundational governance

Focus: Establishing a solid identity foundation and initiating core governance processes.

Key activities:

  • Identity foundation:
    • Onboard employee identities:
      1. Integrate authoritative sources like Human Resources (HR) systems.
      2. Model employee identities to ensure accurate representation within SailPoint.
    • Establish core connectivity:
      1. Connect to essential systems such as directories (e.g., Active Directory).
  • Advanced analytics:
    • Verify and, if necessary, correct identity and access data within the platform.
  • Targeted certifications:
    • Leverage account and access data to conduct regular access reviews.
    • Use AI-assisted access recommendations to gain insights into access patterns.
    • Identify discrepancies or over-provisioning to enhance security posture.

Best practices:

  • Automate where possible: Utilize SailPoint's automation capabilities to streamline onboarding and access reviews.
  • Engage stakeholders early: Involve HR and IT teams to ensure accurate identity data and smooth integration.
  • Foster a culture of accountability: Promote regular access reviews to maintain vigilance and align access with business needs.

Phase 2: Expansion and lifecycle

Focus: Expanding identity coverage and establishing comprehensive lifecycle management.

Key activities:

  • Onboard additional identities:
  • Implement lifecycle management:
    • Establish processes for joiners, movers, leavers, and other scenarios.
    • Automate workflows to ensure timely updates to access rights.

Best practices:

  • Prioritize high-impact areas: Focus on systems and identities that pose the greatest risk or offer the most significant benefits.
  • Standardize processes: Develop consistent procedures for identity lifecycle events to enhance compliance and efficiency.
  • Leverage AI insights: Use data intelligence to inform decisions and refine access controls.

Phase 3: Activity and machines

Focus: Incorporating activity data and managing machine identities.

Key activities:

  1. Integrate activity information:
    • Connect high-value activity data streams to monitor account and access usage.
    • Use activity data for threat detection and response with SailPoint’s Identity Risk solution.
  2. Expand to machine identities:
    • Discover and classify machine identities, including devices, bots, and service accounts.
    • Govern machine identities within SailPoint's framework to reduce risk associated with privileged accounts.
  3. Enhance access descriptions:

Best practices:

  • Monitor continuously: Implement real-time monitoring of activities to proactively address security threats.
  • Govern machine identities rigorously: Apply the same level of governance to machine identities as to human users.
  • Use AI for efficiency: Leverage AI to automate documentation and gain deeper insights into access patterns.

Phase 4: Access modeling and requests

Focus: Developing advanced access models and implementing access request processes.

Key activities:

  1. Build access models:
    • Use SailPoint’s data intelligence to create role-based access controls (RBAC).
    • Incorporate access descriptions and metadata to understand and manage access effectively.
  2. Implement access requests:
    • Establish workflows for users to request discretionary access not covered by roles.
    • Automate approval and provisioning processes to enhance efficiency.
  3. Integrate with organizational ecosystem:
    • Connect SailPoint with service desk solutions (e.g., ServiceNow) and collaboration tools (e.g., Slack, Teams).
    • Facilitate access requests, approvals, and provisioning within the platforms where your organization operates.

Best practices:

  • Engage business units: Collaborate with various departments to define access models that reflect actual business needs.
  • Automate fulfillment: Reduce manual intervention by automating provisioning tasks where possible.
  • Enhance user experience: Simplify access request processes to improve user satisfaction and compliance.

Phase 5: Data, cloud, and privileged enrichment

Focus: Extending identity governance to cloud environments, unstructured data, and privileged access.

Key activities:

  1. Integrate Cloud Infrastructure Entitlement Manager (CIEM)
    • Use SailPoint’s Cloud Infrastructure Entitlement Manager to manage access within Cloud Service Providers (CSPs) like AWS, Azure, and GCP.
    • Gain insights into cloud resource access and enforce consistent policies.
  2. Incorporate Data Access Security (DAS):
    • Apply data governance principles to unstructured data such as files and documents.
    • Identify hidden risks and control access to sensitive information.
  3. Automate privileged access management:
    • Leverage Privileged Task Automation (PTA) to automate high-risk access without exposing credentials.
    • Integrate with Privileged Access Management (PAM) systems to monitor and control privileged sessions.

Best practices:

  • Apply uniform policies across environments: Ensure that cloud and on-premises systems adhere to the same governance standards.
  • Secure unstructured data: Extend governance to files and documents to protect against data breaches.
  • Automate high-risk processes: Use automation to manage privileged access securely and efficiently.

Phase 6: Maturity and evolution

Focus: Enhancing maturity, expanding connectivity, and refining governance practices.

Key activities:

  1. Connect to additional infrastructure:
    • Extend connectivity to on-premises systems, servers, databases, and other technologies.
    • Integrate with prior phases focusing on machine identities and privileged access.
  2. Implement advanced policies:
  3. Adapt to organizational changes:
    • Continuously assess and update identity governance strategies to reflect evolving business needs.
    • Monitor data, identities, and connectivity to maintain a robust security posture.

Best practices:

  • Maintain continuous improvement: Regularly review processes and technologies to identify areas for enhancement.
  • Foster a culture of compliance: Promote awareness and adherence to governance policies across the organization.
  • Leverage SailPoint expertise: Engage with SailPoint’s support and professional services for guidance and optimization.

In a nutshell

Implementing a phased approach to identity governance allows organizations to build a solid foundation, expand capabilities strategically, and enhance security measures effectively. By following the suggested phasing and best practices outlined above, SailPoint customers can:

  • Align efforts with business objectives: Ensure that each phase contributes to overarching goals.
  • Maximize value delivery: Focus on high-impact areas to achieve significant benefits early.
  • Maintain flexibility: Adjust phases as needed to respond to changing priorities or resource availability.
  • Enhance security and compliance: Build a comprehensive identity governance framework that adapts to evolving threats.

Final recommendations:

Embrace the phased approach as a dynamic roadmap for your identity governance program. Tailor each phase to your organization's unique needs and priorities, and leverage SailPoint's expertise to guide you through the journey. By doing so, you can achieve a mature, robust, and agile identity governance system that supports your business objectives and protects your organization's valuable assets.