Website Chat from Envolve

July 31, 2010

Into the Breach – Audio Series – Chapter 12 (Final Thoughts: Courage to Act)

itb-audioseries-150px

Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today’s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]

Role- and Rule-Basing Part 5: Implementation and Cleanup

The final step in this month’s activity is to implement the roles and clean up any extraneous access that’s left behind. As in the previous segment, the distinction between enterprise and IT roles doesn’t matter, so I will generalize. The reason for this is that what you implement depends on your strategy – as defined [...]

Role- and Rule-Basing Part 4: Documentation and Approval

Once all of the roles are defined, it’s time to document them and obtain approval for their use. We’re now past the point where the distinction between enterprise and IT roles matters, so in this segment I go back to the generic term, “role.” Documentation and approval Once testing is complete, the final roles should [...]

Role- and Rule-Basing Part 3: Designing and Testing IT Roles

Now that enterprise roles have been identified and prioritized, it’s time to tackle IT roles, and figuring out IT roles is where the rubber meets the road. Chances are, neither the department heads nor the HR team can help on this one. It’s up to the identity management team and business “power users” to determine [...]

A Difference of Perspective

I recently participated in a briefing with Cisco where Cisco’s David Bump explained to me the idea behind the Cisco Learning System. The Cisco Learning System works to fill the IT talent gap by partnering with both public and private partners to help increase the supply of qualified professionals. David caught my attention when he [...]

Boost Your Security Career

In my experience, the more we explore the tradecraft of our profession, the more we position ourselves for career success. For me, this means a lifelong study of communication – verbal and written – blended with human ecology and the fundamentals of security. It’s an odd mix, but with my focus on Awareness that Works™, [...]

Role- and Rule-Basing Part 2: Identifying & Prioritizing Enterprise Roles

The first step in role- and rule-basing is identifying and prioritizing the enterprise roles. This sets the direction for the entire effort, which – make no mistake – will be time consuming. Doing some thoughtful planning up-front is therefore imperative to ensuring that you don’t start out off-track. Identifying the roles in the organization is [...]

Role- and Rule-Basing Part 1: Introduction

At this point in the identity management process it is time to consider what access the company’s job functions should have to begin creating roles and rules. This is the first step in automating provisioning and de-provisioning. Even without automation, creating and managing the roles and rules will make manual provisioning (and auditing!) quite a [...]

Into the Breach – Audio Series – Chapter 11 (Outsource with Security and Success)

itb-audioseries-150px

Welcome to the continuation of the Into the Breach: Protect Your Business by Managing People, Information and Risk audio series. (Click this link) to learn more about this how this book solves today’s challenges and pick up a complete copy. This series, underwritten by Configuresoft, now part of EMC, is the full and unabridged audio [...]

Guest Post: Why and How to Invest in Yourself

This is a guest post from Jill Van Zelfden  - a friend of our practice and a passionate professional. Initially connected through twitter, our conversations have demonstrated her zeal for our field, as well as her insights. When I offered the Catalyst Career Compass – Jill jumped at the opportunity and captured this post as [...]