Identity & Access Management (IAM) is a vital function of any large organization. One which demands considerable investments in technology, operational costs and professional services. This paper discusses how, through effective access control, organizations can evolve their IAM function to gain a significant competitive advantage, while reducing IT development costs.

Requirements within IAM, however, are rapidly changing. Restricting access to data is no longer adequate, secure sharing of information, both within and across borders, is now essential for any business or governmental organization to operate effectively. Moreover, many business processes demand a more dynamic and fine-grained approach to IAM than has been previously available.

Based on this many organizations are striving to develop new strategies in their IAM vision and roadmap planning. And. while investments made need to be leveraged, organizations look for IAM capabilities that will make them more agile and responsive to change requests.

This paper discusses these changing requirements and suggests that the necessary IAM evolution can be achieved with two important new concepts that combined amount to what could be considered a small IAM revolution: the combination of Federated Identity Management and Attribute Based Access Control (ABAC).

The findings show that mature methodologies, standards and technologies are available with which IAM investments made in the past can be leveraged while new demands for simplified administration and information sharing and related fine-grained access controls can be met. These new IAM concepts even bear the promise of considerably reduced operational costs, since a number of tasks today handled in separate IAM governance processes can be embedded and delegated to existing business processes.

Some resources on this web site are available for registered users only. To access them, you need to login. If you do not have an account yet, use the registration form below.

Log in
Register

Note! Email address for activation code

or Cancel

Note! An email will be sent out. To activate your account, click the activation link in your email.
Purpose of use: see Axiomatics privacy policy.

No files or file permissions for this user

Search


The XACML Value Proposition

Cost savings may not be your primary reason to look for standards-based and fine-grained access control. It is, however, a predominant side-effect. Once you achieve secure information sharing you also enable new business opportunities. Read more...

Standards-based solutions

Cloud, mobile computing, multiple user identities, etcetera, are all factors that in the past, required an individual approach to access control. With XACML, standards-based authorization solutions can now encompass virtually any technology. Read more...

Trusted solutions provider

Axiomatics solutions can be found in use at leading global entities within finance, manufacturing, healthcare, and the public sector. Our trusted technology has been consecutively chosen for the world's largest XACML deployments. Read more...

Technology

Axiomatics is a driving force in authorization technology. The company's dedicated research hub boasts many of the world's leading experts in XACML, the standard that powers attribute based access control (ABAC), while the Axiomatics CTO is the editor of the OASIS XACML 3.0 specification. Furthermore, Axiomatics was the first organization to attest complete XACML 3.0 speciication conformance.

ABAC

Attribute-Based Access Control (ABAC) surpasses all previous authorization models. It provides easily scalable, dynamic, context-aware and risk-intelligent access control, essential for the modern enterprise.

Solutions

Axiomatics solutions deliver anywhere, any-depth access control across virtually any and every IT environment. They enable secure sharing of information across and within organization's borders and boundaries and compliance with ever-evolving regulatory mandates, while promoting new business opportunities, reducing time-to-market and cutting IT development costs.

eXtensible Authorization

Axiomatics solutions bring together the benefits of standardization, through XACML, with the proven results of externalized authorization. This is more commonly known as eXtensible Authorization.