{"id":3034,"date":"2016-12-16T21:45:20","date_gmt":"2016-12-16T21:45:20","guid":{"rendered":"https:\/\/www.wapshere.com\/missmiis\/?p=3034"},"modified":"2022-08-20T22:37:11","modified_gmt":"2022-08-20T22:37:11","slug":"iam-design-principal-handle-non-standard-in-a-standard-way","status":"publish","type":"post","link":"https:\/\/www.wapshere.com\/missmiis\/iam-design-principal-handle-non-standard-in-a-standard-way","title":{"rendered":"IAM Design Principle: Handle Non-Standard in a Standard Way"},"content":{"rendered":"<p>The &#8220;ideal&#8221; IAM solution would have a reliable flow of pre-checked data and a list of sound, proven business rules from which to provision all the accounts and access each person needs to do their job.<\/p>\n<p>This is a fantasy.<\/p>\n<p>The types of work people do, and the IT landscape they do it in, are increasingly fluid and, while we might be able to make &#8220;broad brush stroke&#8221; access rules, there is still going to be a percentage of access that must be requested, special user accounts that don&#8217;t fit the proscribed mould, and genuine emergencies. Our IAM solution must be designed with this expectation.<!--more--><\/p>\n<p>I could go into a lot of detail here about different methods such as scoping, manual overrides and integrating request-based access &#8211; but I&#8217;ll leave that for other posts and stick to the fundamental design principal here &#8211; which is this:<\/p>\n<p><strong>When designing our IAM solution we must always be considering, and including requirements for, the non-standard. The IAM solution must include configuration that allows\/ignores\/incorporates the manual stuff. <\/strong><\/p>\n<p>This will, in all likelihood, involve process changes <span style=\"text-decoration: underline;\">outside<\/span> the IAM solution. Manual changes must be separated, or tagged, in a standard way. Details will differ but there still needs to be a standard way to identify and track the non-standard. This is the only way that automation can work effectively in our dynamic IT environments.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The &#8220;ideal&#8221; IAM solution would have a reliable flow of pre-checked data and a list of sound, proven business rules from which to provision all the accounts and access each person needs to do their job. This is a fantasy. The types of work people do, and the IT landscape they do it in, are&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"footnotes":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":[]},"categories":[55],"tags":[],"class_list":["post-3034","post","type-post","status-publish","format-standard","hentry","category-best-practice"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pkp1o-MW","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts\/3034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/comments?post=3034"}],"version-history":[{"count":4,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts\/3034\/revisions"}],"predecessor-version":[{"id":3263,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts\/3034\/revisions\/3263"}],"wp:attachment":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/media?parent=3034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/categories?post=3034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/tags?post=3034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}