Knowledge Article

Identity Security Program Milestones

Author

  • ryan_cutter

    SailPoint

HORIZON 1

Fragmented identity experience across organization

Organizations in Horizon 1 are at the initial stage of their identity security journey. They typically have fragmented and siloed identity management processes, often with no centralized IAM function. Identity governance is rudimentary, and there is little to no automation. Compliance is achieved manually, and responses to security incidents are largely ad hoc and reactive.

To advance to Horizon 2:

  • Establish a centralized IAM function.
  • Begin consolidating identity management processes.
  • Introduce basic automation and governance tools.
Executive Sponsor (1).png

Executive sponsor

Obtain executive support and resources, and ensure alignment with organizational goals.

View guidelines →

Charter (1).png

Program charter

Define the scope, objectives, stakeholders, and governance structure of your identity security program.

View guidelines →

Connectivity@2x.png

Steering committee

Guide the direction and prioritize efforts of the identity security program, involving key stakeholders.

View guidelines →

Event-Driven Orchestration@2x.png

Program roadmap

Outline your plan and milestones for your program.

View guidelines →

SailPoint Identity Security Cloud 1.png

Identity foundation

Onboard your authoritative sources and data.

View guidelines →

Analytics 1.png

Advanced analytics

Verify your data is correct, accurate, and expected.

View guidelines →

HORIZON 2

Started on identity management but mostly manual

Organizations in Horizon 2 rely heavily on manual identity management processes, with low adoption of identity tools and reactive, tactical responses to external pressures such as compliance or security breaches. The centralized IAM function is basic, mainly focused on fulfilling service tickets, with limited organizational buy-in.

To advance to Horizon 3:

  • Increase identity security tool adoption.
  • Begin introducing more strategic automation of manual identity processes.
Personalized Insights@2x.png

Access insights

Capture access history and identify risky outliers

View guidelines →

Compliance Management.png

Targeted certifications

Perform targeted access reviews of business-critical access.

View guidelines →

Lifecycle Management (1).png

Lifecycle management

Manage the lifecycle of identities, from onboarding to offboarding.

View guidelines →

Access Request.png

Access requests

Automate and streamline the process for users to request and gain access.

View guidelines →

Separation of Duties.png

Policy modeling

Define and enforce policies that govern identity and access management.

View guidelines →

Password Management.png

Password management

Enable secure and efficient password handling, including resets and changes.

View guidelines →

HORIZON 3

Digitalized at-scale identity management

Organizations in Horizon 3 have a more mature identity management approach, with moderate adoption of IAM tools and automated processes. The centralized IAM function is evolving, with a focus on improving efficiency and reducing risk. Compliance and security measures are more proactive, but there is still room for improvement in terms of organizational buy-in and strategic alignment.

To advance to Horizon 4+:

  • Fully integrate IAM with broader business processes.
  • Expand automation and governance capabilities to additional identity types and infrastructure.
Frame 1 (2).png

Dedicated identity team

Establish a team solely focused on managing and securing digital identities within the organization.

View guidelines →

Access Modeling.png

Access modeling

Develop and manage access roles and policies to ensure appropriate access levels.

View guidelines →

Non-Employee Risk Mangement.png

Cloud infrastructure entitlement management

Govern and manage access across multi-cloud infrastructures.

View guidelines →

Access Risk Management.png

Access risk management

Streamline GRC controls across SAP.

View guidelines →