Solved

access governane

Posted on 2014-04-02
2
278 Views
Last Modified: 2014-04-11
Can anyone recommend any books publications on how to implement best practice access governance and management   across an organasation regardless of what format and where the data is stored
0
Comment
Question by:pma111
2 Comments
 
LVL 26

Accepted Solution

by:
Leon Fester earned 250 total points
ID: 39974451
Access governance and management is best implemented through the introduction of Role Based Access Control (RBAC).

I would refer to the SANS websites for information about governance and best practices.

http://www.sans.edu/research/security-laboratory/article/311
http://www.sans.org/reading-room/whitepapers/bestprac

I found a presentation that might help you see RBAC being introduced into a complex environment.
http://www.id-conf.com/files/kruit_abnamro.pdf

Also have a look at Identity and Access Management article information for better understanding of what's options you have available for governance and access management.
0
 
LVL 62

Assisted Solution

by:btan
btan earned 250 total points
ID: 39974881
I will say delve into identity access management as a whole which covers the full identity lifecycle from its creation, usage, removal and oversight. A good kickstart is the GRC ecosystem which ISACA has established couple of article and publication too. maybe check this out for a start which include references that helps the understanding and planning to implementation an IAM program

http://www.isaca.org/Journal/Past-Issues/2011/Volume-5/Pages/The-Impact-of-Governance-on-Identity-Management-Programs.aspx 

Also we can tap on Gartner as well since they are also watching this space with even recommended reading (need registration)

https://www.gartner.com/doc/1698615/best-practices-identity-access-management

Sometimes, I may also look at MNC in this space actively pushing the practical side to deploy and operationalise the strategy. We should stay practical and map solution to just purely paper talk, and bonus is how it comply with standard and regulation e.g. PCI, SOX, etc

http://www.oracle.com/us/products/middleware/identity-management/061145.pdf
0

Featured Post

Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The 21st century solution to antiquated pagers.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question