IDPros / bok

This is a public comment environment for the IDPro body of knowledge.
70 stars 26 forks source link

User provisioning article update suggestions #123

Open meneer opened 1 year ago

meneer commented 1 year ago

The article is still valid and complete. Some suggestions for small updates to the article:

Introduction ‘the bedrock of any IAM system’ There are many IAM no-provisioning systems. Please use IGA instead of IAM. IGA could be introduced (including synonyms like IAG - it is mentionwd in the What is... part)

What is...: ‘User provisioning is setting up the entitlements for users to the resources’

´User provisioning is setting up the accounts and entitlements for users to the resources' (the term user points to persons, so adding 'accounts' would be logical)

De-provisioning deserves a little more attention in the article (just one mention and a small paragraph about leavers. And almost everywhere we see issues in this department...

Business drivers: Data quality should be added: The SoR-owner is accountable for identity and therefore account data. Data quality issues because of manual administration are big, resulting in lots of inefficiency remediation tasks.

User Provisioning: Entitlement catalog: Lacking the concept of roles. Roles are mentioned only in the policy part.

Certification, or re-certification or attestation deserves a little more attention. 'Soll - Ist' could be used.