Use Case - IdM Gap Analysis with the SAM Role Modeler

Situation
In order to exploit SAM Jupiter’s a provisioning and identity management functions to the full extent, organizations should first should perform an in depth analysis of the current privileges structures and, on the basis of flaws discovered through such an analysis, identify its own needs and justify the SAM Jupiter. Having a productive IdM system in place also requires periodic check-ups so as to keep the initially defined quality level. 

Complications
More often than not, there are large discrepancies between the rules and roles based on organizational data and the actual access rights. In the context of an Identity Management project, the organisation needs to know where these discrepancies occur, to be able to consistently operate an integrated IdM solution such as SAM Jupiter. When the applied accounts are redundant or privileges are not equally granted in respect to the various target systems used, not only is the organisation impeded in achieving its goals but also is the security of its operations endangered. For an IdM solution to work properly, it is essential for these imperfections to be detected.

Solution
Beta Systems’ SAM Role Modeler works on the principle of a gap analysis: it tells the organisation where it stands in terms of IdM and helps it take the optimal path to follow through the implementation and operation of a solution. It assists the organisation thereby in overcoming difficulties and avoiding potential roadblocks. In addition, SAM Role Modeler reports provide the customer with facts and statistics which build a strong justification for the purchase of an IdM solution.

A typical 5-day gap analysis reports on users, groups and privileges, on several target systems and several levels of granularity. It evaluates the mismatches such as out-of-pattern privileges and incorrectly assigned or redundant roles and groups. For a modest investment, SAM Role Modeler enables the organisation to prepare for IdM deployment in a way that fits its organisational culture and the existing privileges structure. In a running IdM solution, the detected weaknesses can in a subsequent step be used to define corrective actions with regard to administration and role life-cycle management.