ISIM-CXP Integration

advertisement
ILANTUS Proprietary
Enabling complete AGS features on ISIM
Compliance Express – ISIM Integration
Jaunary 20, 2014
1
Agenda
- Context
- Typical ISIM deployment Challenges
- About Compliance Express
- ISIM integration with Compliance Express
- Benefits and Demo
- ILANTUS Sales Contact details
2
Today’s focus
Access Governance
using Compliance Express for ISIM customers
3
Typical ISIM deployments
• ISIM Integrated with top few applications
• This leaves lot of applications outside the purview of access
governance
HR App
AD
SAP
Identity Manager
(ISIM)
RACF
Lotus
Notes
Applications not connected with ISIM
App1
App2
App3
App4
App5
App6
App7
App8
4
Access Governance Challenges with typical deployments
•
Access governance limited to applications that are connected
with ISIM
- Limited recertification and role-mining flexibility with ISIM
•
Single view to who has access to what application within an
enterprise is not available
- Hence recertification process is limited and not across all
applications
- Granular level recertification not possible on connected
target applications
•
CSV based integration with other applications is effort
intensive
5
Overcome the Challenges
Introducing...…
ISIM & Compliance Express integration
Features and benefits
6
About Compliance Express
Compliance Express is core Identity & Access Governance tool offered by
ILANTUS.
Access Governance Capabilities
• Access Request
• Segregation of Duties (SoD)
• Access Recertification
• Reports
Features
• Flexible
• Cost Effective
7
ISIM-Compliance Express Integration Summary
•
Integrated and complimentary to ISIM – leverages ISIM data
•
Extend ISIM’s access intelligence and certification capabilities
•
Adds SoD validation and Access Risks analysis
•
ISIM collects and syncs data, and manages user provisioning
workflows, Compliance Express delivers Access Intelligence
•
Additional
• Advanced fine grained access certifications – User, OU,
Application & Entitlements level.
• Access Risk Management
• Unique capabilities for SAP
8
How it works
• Enables Access Governance on top of your ISIM infrastructure and
data;
• Deployed and configured as an ordinary ISIM Adapter;
• API based integration;
• Native supports the various entities and object-class and has the
ability to extend to any custom object-class.
9
Adapter @ a glance
Installation & configuration
• Deployed just like any other ISIM Adapter;
• Has TDI Assembly line for the full and incremental
synchronization between ISIM and CrossIdeas.
Few hours required to configure the adapter and synchronize
the required objects and entities
10
How does this help our customers?
 Brings the “power of two” – best of breed product in each
segment brought seamlessly by Gartner recognized vendor
 Address compliance issues through a comprehensive AGS
offering built on top of industry leading identity
management platform i.e. ISIM
 Adopt flexible deployment method to cut short time to
value
 Entire solution seamless supported by ILANTUS
11
Customer Win – WhiteWave Foods (WWF)
• Entire solution being delivered in hosted mode
• IBM Products involved - IBM Identity and Access Assurance
(IBM Security Identity Manager, IBM Security Access Manger
for Enterprise Single Sign-On, IBM Security Access Manager
for Web and IBM Tivoli Federated Identity Manger)
• ILANTUS Components – ILANTUS Compliance Express,
ILANTUS Federation Express and ILANTUS Password Express
• Entire setup going live in stages – to help meet WWF strategic
initiatives (separation from Dean Foods)
12
Use-case 1 (ISIM-Compliance Express sync)
In ISIM we’d create the following objects that sync automatically to Compliance Express
•
Organizational Units (OU)
•
Roles
•
Users
All the above sync into Compliance Express
ISIM Adapter for
Compliance Express
15
Use-case 2 (Access Request Workflow)
Single interface for requesting access to any application (ISIM
integrated or Compliance Express integrated) at the enterprise level
Compliance Express
Users
IT Pros
Additional
IBM SIM
data sources
16
Use-case 3 (SoD rules for all enterprise applications)
• Define SoD rules at Enterprise level (for ISIM integrated and
Compliance Express integrated apps)
• Compliance Express manages the SoD controls and ‘mitigation’
process
SoD Policies
Risk/Security
Compliance Express
IBM SIM
IT
Additional
data sources
17
17
Use-case 4 (Attestation/Re-Certification)
• Compliance Express allows Business to easily certify access rights
• Single interface to re-certify access for all applications across the
enterprise (ISIM integrated and Compliance Express integrated)
Risk/Security
Compliance Express
IBM SIM
IT
Additional
data sources
18
ILANTUS Proprietary
Jeff Lumley, Director of Sales
jeffrey.lumley@ilantus.com
(720)233-1099
19
Download