Technology

How to Manage Identity Sprawl Using an Identity Fabric

The enterprise operates on SaaS, from HR to IT to manufacturing to finance. Yet, the fast adoption of SaaS services has resulted in a two-pronged danger of identity theft and hijacking of vital technologies used to manage the digital organisation. SaaS-generated identity sprawl has become a serious challenge with modern work relying on SaaS-delivered solutions.

How to Manage Identity Sprawl Using an Identity Fabric

How to Manage Identity Sprawl Using an Identity Fabric

Share

The enterprise operates on SaaS, from HR to IT to manufacturing to finance. Yet, the fast adoption of SaaS services has resulted in a two-pronged danger of identity theft and hijacking of vital technologies used to manage the digital organisation.

Advertisement

SaaS-generated identity sprawl has become a serious challenge with modern work relying on SaaS-delivered solutions. Similarly, integrating identity and access management (IAM) systems has always been difficult, from the first directory service to today’s SaaS-delivered IAM solutions. As identities become the final remaining enforcement point, functionality deficiencies frequently lead to security flaws. Yet, identities spread, replicate, and connect significantly more than traditional perimeter defences such as firewalls.

Consider distributing thousands such firewalls and leaving them open for third-party programmes to consume and be devoured by, with nothing more than a sign-up form to establish the arrangement. Does that appear to be safe? That is exactly what happened when the corporation handed over operations to SaaS—services that operate completely outside of IT and security constraints but house thousands of corporate identities.

Why An Identity Control Fabric?

Because digital organisations’ surroundings are constantly evolving, security controls and protection frequently fall behind. This tendency has only been intensified by modern work across the world. Identity, in particular, has escaped technological boundaries and is now the crucial point of management as a permanent corporate asset tied to cloud and SaaS services.

The dispersed identity perimeter continues to be the greatest source of shadow entrance, but on the plus side, it is also the most lasting and sustainable bearer of security at scale, as well as the most adaptable to emerging hazards. The distributed identity boundary may apply the proper restrictions when apps and services consume identities by integrating security into the identity, such as using an identity control fabric.

Identity and context are now the last control points for distributed environments that allow access from anywhere and at any time. These are the global fabric’s threads: identity and context.

Advertisement

What Exactly Is An Identity Fabric?


The identity fabric is a support layer that abstracts identity domains and different SaaS services, apps, relationships, and contexts. It is the result of a collection of services for managing IAM across numerous data silos, clouds, and SaaS applications.

The identity fabric is a critical component of a cybersecurity mesh architecture aimed at enabling composable security for the composable digital organisation. A Gartner Inc. study states: “Cybersecurity mesh architecture is a composable and scalable approach to extending security controls, even to widely distributed assets. … CSMA enables a more composable, flexible and resilient security ecosystem. Rather than every security tool running in a silo, a cybersecurity mesh enables tools to interoperate through several supportive layers, such as consolidated policy management, security intelligence and identity fabric.”

An identity control fabric is a novel solution to addressing the fundamental security difficulties of identity security, specifically the increase of the identity attack surface and the continual attack against that developing identity fabric.

Developing An Identity Control Fabric

To begin the process of creating an identity control fabric, companies must investigate four essential aspects of how identities use and are consumed by SaaS services:

1. Visibility. Identities are spread across various silos and systems in the typical enterprise. It is essential for security teams to gain line of sight into all identity touchpoints (from Active Directory to CASB) to identity providers and IAM. Gaining a baseline of how identities are expressed and where they are used can give you a consistent picture of the identity attack surface.

2. Simplify. Most identity security comes from multiple dashboards and is a general expectation when getting started. However, simplifying products, policies and playbooks into a single identity fabric can remove the need for niche skills and disciplines operating with multiple silos. By unifying the visibility and simplifying control and policy, organizations can begin to secure the identity fabric at scale, as when a single access control policy is propagated to all places when identities perform an authentication event.

3. Continuity. Safeguarding identities through an identity control fabric demands continuity across all forms of identity governance such as regular assessments, user access reviews, newly discovered authentications and grants for extending access to third-party applications.

4. Response. Security teams must craft a plan to secure identities in the wake of SaaS compromise, phishing campaigns or risky SaaS services or functions entering the environment. This process of universalizing identity security can project control into the enterprise SaaS layer—past, present and future.

Conclusion

Increasing complexity necessitates security and risk teams sifting through a plethora of tools and technologies, but these teams must ensure they are addressing the two-pronged issue of identity and SaaS theft. Because the identity is safe independent of the SaaS in use, security programmes may stay adaptive and flexible to SaaS changes by protecting identities first.

Reporting for Business Tech Africa on the funding, tools and strategy shaping the continent's founders and SMEs.

Was this useful?0 reactions
Huawei apostará por el internet de las cosas para sus dispositivos
Read nextTechnology

Huawei Considers 4,000MWh Battery Storage Project in Egypt

Roy Mulenga · readContinue reading