Best IAM practices to strengthen enterprise security
As part of Cybermoi/s 2024, we are sharing best IAM practices with you to strengthen corporate security.
Memority offers a powerful role model definition to manage delegated administration into Memority portal but also applications accesses, equipment and any other link between an identity and a resource.
This blog series will allow you to understand how we handled this fundamental part of right management.
As named, Identity and Access Management (IAM) allows to manage inside an organization identities that need to access resources. In the past, authorizations were given with more or less control, with more or less known processes and with more or less painful rights omissions (to add or to remove). To control and simplify authorizations management, it is necessary to define a role model which will allow to set publication rules, access conditions and most important, role removal at the right point!
The role assigns to a user one or more rights about a resource. It allows to define a first level of abstraction and automatism against a technical right and to control that two users with the same roles will have the same rights. But when we need to manage thousands of resources with different types, it becomes necessary to organize and design rights into a role model to manage them as one and allow anyone to request roles easily: the user in self-service, its manager, an application manager and more.
Memority’s role model is highly dynamic and allows to manage administration rights in Memority, applications accesses, equipment, business roles, contracts and more. In a word, we can represents anything as a resource assigned to a user. To do that, we use several concepts:
Thanks to these 4 concepts, we can easily design several types of resources and roles to set a dedicated data model, with their own attributes.
For example, we can set resource types “Application” and “Equipment”, and role types “Application role”, “Administration role”, “Business role” and “Supplies” with their own publication and assignment rules (another article about publication and assignment is coming too 😉). These roles can be displayed separately according to their types, and managed by dedicated administrators.
We set our Memority role model, now we can dig deeper:
But you have to wait for our next articles of our role model series!
-> To find out more about the benefits of the Memority platform: click here