Use Case - Rolebased Administration

Situation:
In IT security administration, a large number of questions arise in a wide variety of contexts. For example, Georgina has a new job in the customer loans department. What access rights does she need to be able to do her job? In addition, she's also a member of the "Customer Satisfaction" project group. Does she need access to additional resources because of this?

Complications:
When two different worlds meet, there are always complications. In this case, the terminology and mindset of human resources administration with its manageable number of job descriptions, projects and persons comes up against the technical world with its vast quantities of user profiles, user groups, technical resources and access rights that need to be managed and protected. To add to the complexity, access rights administration often needs to be implemented on a number of different platforms and IT systems that are managed by different teams.

Solution:
The use of a role concept makes complex interrelationships more accessible in daily processes and has proven invaluable in solving this problem. Roles are identified and defined precisely at task level. Each role is then given the aggregation of rights and privileges it calls for, if necessary, on a variety of systems. Every employee can be assigned the specific role or roles needed to complete the tasks at hand, adding transparency, speed and ease to the process of access rights administration. These roles can be just as easily taken away again when the associated rights and privileges are no longer needed. Introducing the role concept involves a lot of preliminary work. However, the effort required is far outweighed by the advantages: complex interrelationships become more accessible in daily processes, achieving advanced and professional access management. The workload on administration is dramatically reduced (there are fewer administration tasks to cope with). Access rights management takes place at the technical level, making it easier to maintain a high degree of security, and can be easily controlled across platforms from a single point of administration.

SAM Jupiter not only enables the role-based administration of access rights, it also has facilities for automating routine tasks. SAM Role Modeler simplifies the process of role identification and definition by applying sophisticated data mining technology to automatically utilize existing organization data and security information from SAM Jupiter Repository. Tried and tested, this can save your organization a lot of time and money.