IAM Administration Choices
Identity and access management administration can follow centralized, decentralized, or hybrid approaches, balancing control, flexibility, and scalability based on organizational size, structure, and security needs.
7 slides · 4 min read · Domain 5
Information and the administration of information are key to managing an organization's access control (AC) systems. Information can be associated with both logical and physical AC systems. Whether dealing with a logical or physical access system, control over that system is maintained through discrete data, information, or both.
The management of information related to physical and logical access is generally carried out in three primary ways: centralized, decentralized, and hybrid.
within the organization's networks. This can also place substantial performance demands on the AC system.
Decentralized or distributed AC systems can provide greater levels of fault tolerance, especially for large, geographically dispersed enterprise architectures. They also can provide better response times, when compared to centralized systems, as they tend to be servicing a much smaller number of client systems (i.e., any system requesting an authentication or authorization action). It can also take quite some time, perhaps as much as 24 to 48 hours, to push AC database updates to all servers in the system. This latency can allow a window of opportunity for an attacker to attempt to use privileges that management has decided to revoke, but that not all nodes in the AC system have carried out.
Each user's account can be monitored centrally, and revoking all access for a user who leaves the organization can be accomplished efficiently. Consistent and uniform procedures and criteria are generally easier to enforce when relatively few individuals oversee the process.
Centralized AC implementations require all authentication and authorization actions to be handled by the central AC system. From one perspective, this is an advantage, in that updates to identities and privileges are immediately available for use at all nodes within the organization's networks. This can also place substantial performance demands on the AC system.
One disadvantage, however, is that there may not be consistency among creators and owners about procedures and criteria for granting user access and capabilities. Another disadvantage is that when requests are not processed centrally, it may be more difficult to form a system-wide view of all user access on the system at any given time. Different data owners may inadvertently implement combinations of access that introduce conflicts of interest or are not in the organization's best interest. It may also be difficult to ensure that access is properly terminated when an employee transfers within or leaves an organization.
Text on this slide
Centralized Administration
Decentralized Administration
Centralized administration means that a
In contrast to centralized administration, decentralized or distributed administration single function is responsible for configuring access controls so users can access data means that access to information is controlled by the owners or creators of the and perform authorized activities. As a user's information processing needs files, whoever or wherever those individuals may be.
change, their access can only be modified through central administration, typically
An advantage of decentralized after requests have been approved through an established procedure and by the administration is that appropriate authority. control is in the hands of the individuals most accountable
One advantage of centralized for the information, most administration is that strict
familiar with it, and best able
control over information is to judge who should be able to maintained because the ability do what in relation to it.
to make changes is limited to a few individuals.
Hybrid Administration
In a hybrid approach, centralized control is exercised for some information, and decentralized control is allowed for other information.
One typical arrangement is that central administration is responsible for the broadest and most basic access, and the creators and owners of files control the types of access or users' abilities for the files under their control. For example, when a new employee is hired into a department, a central administrator might provide the employee with access permissions based on the functional element they are assigned to, the job classification, and the specific task they were hired to work on. The employee might have read-only access to an organization-wide SharePoint document library and to project status report files, but the same employee might have read-and-write privileges to their department's weekly activities report. Also, if the employee leaves a project, the project manager can easily close that employee's access to that file.
