|
Identity Enforcer...
Self Service User Provisioning and Policy Enforcement
With Identity Enforcer, identity customization is a fully automated down to the level of specific roles for individual users, providing a secure process that saves time and reduces the strain on critical IT resources. Users (or their managers) simply point, click and submit self-service access requests, and Identity Enforcer's dynamically generated workflow system automatically provides the business controls required by corporate policies and external regulations.
Identity Enforcer's innovative approach enables authorized staff and managers to define business relationships and implement policies with drag-and-drop ease while transparently managing all of the underlying workflow and provisioning operations. The result is a system that deploys faster, at a lower cost and evolves as the business does.
Identity Enforcer brings forth three pioneering technologies that automates workflow and eliminates the complex scripting and programming that's made user provisioning systems cumbersome, slow and expensive before today:
- Hierarchical Business Services Repository: Neatly organizes assets and applications to mirror business processes and allows end-users or managers to request what they need when they need it.
- Hybrid Roles: Supports evolutionary change by combining enterprise roles with individual assets and privileges. Hybrid roles can be modified by line of business or IT managers.
- IdentiFlow: Identity-oriented approval workflow is automatically generated for all role management and user provisioning operations from the structure of the Hierarchical Business Services Repository without the cost and delays of traditional workflow programming.
Key Features:
- Hierarchical Business Services Repository:
Hierarchical representation of available resources simplifies user
navigation and provides a visual model of approval relationships.
- Hybrid Roles: Combine enterprise roles with individual assets and privileges
in a flexible model that can be maintained by business or IT
managers as the organization evolves.
- Identiflow Approval Workflow: Identity-optimized workflow is dynamically generated (no
programming required) based on the Hierarchical Business
Service Repository and organizational structure. Workflow is
automatically updated with changes to the repository.
- Sarbanes-Oxley Separation of Duties (SoD): Applies pre-configured and user-defined conflict rules to ensure
that privileges conform to regulatory and internal standards.
Approved exceptions are captured for audit review.
- Comprehensive Logging and Reporting: All transactions are logged to provide a complete audit trail.
Real-time and scheduled reports are available to support
operations, management and auditing.
- Web-based User Interface: All Identity Enforcer administrative and end-user tasks are
performed via a simple, easy-to-navigate web UI. No programming
is required.
Key Business Benefits:
- Reduce Costs: Identity Enforcer's simplified deployment and self-service request model dramatically reduces the cost of provisioning operations.
- Increase IT Efficiency: The automated processing of provisioning tasks frees help desk, service desk and administrator resources to handle higher value assignments.
- Accelerate User Productivity: The self-service request process combined with automated workflow and provisioning delivers faster access to required IT resources and business assets.
- Achieve Compliance: By implementing approval processes to comply with internal and external standards and building an audit trail of all provisioning operations, Identity Enforcer is a key component of a comprehensive corporate compliance strategy. The SOX Separation of Duties (SOD) feature ensures that multiple stages of critical business processes are not assigned to a single employee.
- Increase Business Agility: Identity Enforcer's Hierarchical Business Services Repository, Hybrid Roles and IdentiFlow workflow all adapt to rapidly changing business demands. Instead of waiting for complex role design and workflow programming, IT and line of business managers can easily make the required changes and roll out new business processes.
Identity Enforcer also integrates seamlessly with Account Creator and Account Terminator to provide fully automated employee lifecycle provisioning and deprovisioning. As new employees are hired Account Creator automatically detects the change and creates user accounts and privileges based on enterprise roles (using job code, job title, etc.). With Identity Enforcer, the employees (or their managers) can customize their identities via selection of additional assets, privileges and roles required for their specific job assignments. Upon termination, Account Terminator will automatically remove access or delete accounts to ensure compliance with corporate policy and regulations.
|