Entitlement Management

On-site workshop

Many enterprises recognize the issues with managing and enforcing entitlements. However, it's not always that easy to understand where to start or what can be achieved by adopting a new technology. There are usually a number of issues regarding access policies and how access control can be streamlined  in the enterprise or even in a system.

Axiomatics offers on-site workshops where, together with your team, we study your needs from both an access policy aspect, and an architecture and performance aspect. The workshop helps you to identify the problems with your existing access control solution, and to understand if and how these can be solved by introducing an XACML-based entitlement management solution.

The workshop is structured into the following tasks:

  1. Review of your needs
  2. Construction of use cases
  3. Analysis of use cases: architecture and XACML policies
  4. Identify difficult issues

The result of the workshop is delivered in a report consisting of use-cases, architecture, sequence diagrams, XACML policy outline, top issues and next steps.

 
Proof of concept

Introducing a new access control solution is a big step for most of enterprises. It will not only affect various systems and sometimes the entire IT-infrastructure, but also the administration and auditing of access policies. Therefore, enterprises need to verify their choice of access control solution in an isolated setting, before they can make a final decision.

Axiomatics offers Proof of Concept (PoC) projects in which both the XACML technology as such and the software can be tested and verified by the customer. A PoC is usually a well-defined project in which a suitable application is chosen for integration to Axiomatics products that can also be tested in a reasonable time and effort.

 
Integration and implementation

Access control is a critical and highly integrated function in a system or in an IT infrastructure. Many functions and applications are dependent on its performance. Therefore introducing a new access control model requires a good understanding and best-practices knowledge of how to integrate access control in a larger setting of functions and applications.

Together with our integration partners we replace your old access control functions with a new XACML-based access control solution.

Most enterprises have their own system architecture based on various systems and platforms and their access control mechanisms have specific requirements. We offer tailored extensions to our software package in order to satisfy  customers' needs and requirements. The usual extensions are tailored Policy Enforcement Points. 
 
Access policy modelling

XACML is a highly expressive policy language that provides administrators with a powerful tool to express access policies that satisfy the need for higher enterprise policies and compliance requirements. XACML allows you to implement access policies in many ways with different perfomance outcomes and administrative burdens.

The Axiomatics team has unparalleled knowledge and experience in  structuring, optimizing and expressing access policies to meet your different access control requirements. Axiomatics provides this service in addition to the training courses and as a support function to the enterprises policy administrators.

 
Governance framework

Access control is a security critical function in an enterprise. Hence, the access policies and the additional information required for decision making must be securely created, administered, stored and provisioned.

Axiomatics has developed a Governance framework for XACML-policies and the attributes needed to instantiate and to trigger these policies. This governance framework can be applied to identify the critical components and information that will affect the access decisions and also the management of these from a security governance perspective.