Solved

access governane

Posted on 2014-04-02
2
280 Views
Last Modified: 2014-04-11
Can anyone recommend any books publications on how to implement best practice access governance and management   across an organasation regardless of what format and where the data is stored
0
Comment
Question by:pma111
2 Comments
 
LVL 26

Accepted Solution

by:
Leon Fester earned 250 total points
ID: 39974451
Access governance and management is best implemented through the introduction of Role Based Access Control (RBAC).

I would refer to the SANS websites for information about governance and best practices.

http://www.sans.edu/research/security-laboratory/article/311
http://www.sans.org/reading-room/whitepapers/bestprac

I found a presentation that might help you see RBAC being introduced into a complex environment.
http://www.id-conf.com/files/kruit_abnamro.pdf

Also have a look at Identity and Access Management article information for better understanding of what's options you have available for governance and access management.
0
 
LVL 63

Assisted Solution

by:btan
btan earned 250 total points
ID: 39974881
I will say delve into identity access management as a whole which covers the full identity lifecycle from its creation, usage, removal and oversight. A good kickstart is the GRC ecosystem which ISACA has established couple of article and publication too. maybe check this out for a start which include references that helps the understanding and planning to implementation an IAM program

http://www.isaca.org/Journal/Past-Issues/2011/Volume-5/Pages/The-Impact-of-Governance-on-Identity-Management-Programs.aspx 

Also we can tap on Gartner as well since they are also watching this space with even recommended reading (need registration)

https://www.gartner.com/doc/1698615/best-practices-identity-access-management

Sometimes, I may also look at MNC in this space actively pushing the practical side to deploy and operationalise the strategy. We should stay practical and map solution to just purely paper talk, and bonus is how it comply with standard and regulation e.g. PCI, SOX, etc

http://www.oracle.com/us/products/middleware/identity-management/061145.pdf
0

Featured Post

Free Tool: Postgres Monitoring System

A PHP and Perl based system to collect and display usage statistics from PostgreSQL databases.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

OnPage: Incident management and secure messaging on your smartphone
No single Antivirus application (despite claims by manufacturers) will catch or protect you from all Virus / Malware or Spyware threats. That doesn't stop you from further protecting yourself however - and this article is to show you how.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question