Removing Inappropriate Security Entitlements - Hitachi ID Access Certifier
Once certifiers have reviewed user entitlements and identified inappropriate ones, Hitachi ID Access Certifier can follow through by authorizing the deactivation of those rights and then removing them from target systems:
Authorizing Deactivation of Entitlements
By default, all requests require authorization -- but business logic may override this and auto-approve requests.
Authorizers are selected automatically and may be chosen using OrgChart data (i.e,. managers of the requester or recipient), using resource owner data or through other means, such as lookups in an external database or directory.
Each group of authorizers consists of some N>=1 authorizers. Some number M<=N of the authorizers in each group must approve a request before it will be fulfilled by Access Certifier.
A single flow-chart (state diagram) is used to authorize all requests in the Access Certifier workflow engine. The Access Certifier workflow engine supports:
- Parallel change authorization.
- Multiple groups of multiple authorizers.
- Automatic reminders to unresponsive authorizers.
- Automatic escalation, when authorizers continue to be unresponsive.
- Delegation -- for example, when authorizers take extended leaves of absence.
- Authorizers with veto power over some or all of a request.
Workflow is used in Access Certifier to approve change requests, to implement approved requests, to certify user access and more. A participant in the workflow process is a person who is being asked to complete a task, most commonly change authorization.
The Access Certifier workflow engine has built-in support for automatic reminders, escalation and delegation, so as to elicit reliable responses from individually-unreliable users:
- When participants are first chosen, their out-of-office status on their primary e-mail system may be checked, to trigger early escalation to an alternate participant.
- Non-responsive participants that have been asked to review a request receive automatic reminders. The reminder interval is configurable.
- Participants who remain non-responsive (too many reminders) are automatically replaced with alternate participants, identified using escalation business logic. Escalation is most often based on OrgChart data -- i.e., the original authorizer's direct manager is often the escalated authorizer.
- Participants can pro-actively delegate their authority, temporarily or permanently. Delegation may trigger its own approval -- asking the new participant to accept a new responsibility.
- A workflow manager can reassign participants attached to open requests, for instance when they are terminated or when a request is urgent and already-assigned participants are not available.
Removing Inappropriate Entitlements on Target Systems
Once access deactivation has been approved, Access Certifier removes excess entitlements directly on target systems. This is done using the over 110 built-in connectors, by:
- Unassigning roles (within Access Certifier).
- Disabling login accounts.
- Removing users from security groups.