copyright © sailpoint technologies holdings, inc. 2019 ...€¦ · governance based approach to...

33
1 Copyright © SailPoint Technologies Holdings, Inc. 2019. All rights reserved.

Upload: others

Post on 18-Jul-2020

7 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

1Copyright © SailPoint Technologies Holdings, Inc. 2019. All rights reserved.

Page 2: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Identity @ Center of a Zero Trust Network

Darran RollsCTO & x-CISO

Page 3: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance
Page 4: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Free Solo Zero Trust

Page 5: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance
Page 6: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance
Page 7: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Zero Trust

Page 8: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Assume the Network is

Compromised

Page 9: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Zero Trust is an approach

Page 10: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Taking a Zero Trust Approach

• Assume the network is hostile…

Make Identity & Access Management a core competency

• Catalog your people and devices…

• Build solid application-level boundaries…

• Manage fine-grained access and entitlement…

• It’s a way of thinking…

Page 11: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Identity Governance

DrivingZero Trust

Page 12: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Identity Governance

Least Privilege

Model-based Lifecycle

PredictiveControls

Zero Trust Approach

Page 13: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Self-Service &Delegation

Inventory &Visibility

Least Privilege for Zero Trust

Least Access

Page 14: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

give out less by default!

Page 15: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Identity Governance

Zero Trust Approach

Least Privilege

Model-based Lifecycle

PredictiveControls

Page 16: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Model-based Lifecycle

GovernanceModels

- RBAC lifecycle management…

- Ownership & approval…

- Triggers & change control…

- Requestable units…

Governance Based Approach to Identity

Page 17: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Model-based Lifecycle

Attributes DriveAccess

Embedded Controls

GovernanceModels

Page 18: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

an access policy decision based on identity data…

Page 19: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

HR System

Attribute = Job_Code

RoleDefinition

AssignmentRule

Accounting Role

If Job_Code = “A101”

Page 20: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

IdentityProvider

Attribute = Manager

IAMPolicy

AccessCondition

S3 Access Policy

If Manager = “True”

Page 21: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Outlook Profile

Attribute = Location

ProtectedResource

DynamicGroup

OneDrive Folder

If Location = “Austin”

Page 22: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

ProvisioningControls

Governance?

Page 23: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Attribute Providence?

Page 24: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Policy & Rule Lifecycle Management?

Page 25: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

The providence and assurance of identity attributes

& runtime access policies becomes a key governance control

Page 26: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Identity Governance

Zero Trust Approach

Least Privilege

Model-based Lifecycle

PredictiveControls

Page 27: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Big Data - Machine Learning - AI

Anticipate user access needs

Spot risky user behaviors

Enhance governance models

Reduce administration costs

Enhance user experience

Page 28: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Predictive Controls

SmarterGovernance

Baselines& Norms

Dynamic Approvals & Recommendations

Page 29: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

LeastPrivilege?

Page 30: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Dissolving Entitlement?

Page 31: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Attribute integrity

Identity context

Access history

Automatic approval

Dynamic provisioning

Embedded control

Page 32: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

CHANGETHE FUTURE OF

ZERO TRUST

SailPointPredictiveIdentity™

Page 33: Copyright © SailPoint Technologies Holdings, Inc. 2019 ...€¦ · Governance Based Approach to Identity . Model-based Lifecycle Attributes Drive Access Embedded Controls Governance

Thank You