So many organizations struggle with policy exceptions. While exceptions are a reality, the prevalence of them leads one to believe that risk management is not quite working.
While organizations try to pivot from risk to compliance focal points to enforce adherance to security / privacy best practices, the reality is that most entities are not agile, and they also lack the resources to migrate from legacy workdlows to secure processes and systems.
While the cloud and ITO / BPO of the past have promised more agility, many orgs leverage traditional internal models due to cost constraints.
GRC, risk management, and IT audit professionals have a legit argument to focus on policies, standards, and guidelines; however, for orgs to be and remain secure these days, an offensive, proactive model is more of a necessity.
Showing posts with label BPO. Show all posts
Showing posts with label BPO. Show all posts
Tuesday, August 8, 2017
Wednesday, August 31, 2016
Consolidate Internal Identity Stores BEFORE Focusing on Cloud-based SSO / IAM
There is a tendency to focus on the shiny objects, and many orgs have a cloud-first mentality, but there is no reason to ignore the multitude of internal identity stores that exist in most large enterprises.
SSO, SAML, etc. are great, but what about LDAP, AD, etc.? How about de / provisioning, especially with your vendors (e.g., SOC / MSSP, NOC / MSP, ITO, BPO)?
SSO, SAML, etc. are great, but what about LDAP, AD, etc.? How about de / provisioning, especially with your vendors (e.g., SOC / MSSP, NOC / MSP, ITO, BPO)?
Subscribe to:
Posts (Atom)