Use Case - Rolebased Administration
Situation:
In IT security administration, a large number of questions arise in a wide variety of
contexts. For example, Georgina has a new job in the customer loans department. What access rights
does she need to be able to do her job? In addition, she's also a member of the "Customer
Satisfaction" project group. Does she need access to additional resources because of this?
Complications:
When two different worlds meet, there are always complications. In this case, the terminology
and mindset of human resources administration with its manageable number of job descriptions,
projects and persons comes up against the technical world with its vast quantities of user
profiles, user groups, technical resources and access rights that need to be managed and protected.
To add to the complexity, access rights administration often needs to be implemented on a number of
different platforms and IT systems that are managed by different teams.
Solution:
The use of a role concept makes complex interrelationships more accessible in daily processes
and has proven invaluable in solving this problem. Roles are identified and defined precisely at
task level. Each role is then given the aggregation of rights and privileges it calls for, if
necessary, on a variety of systems. Every employee can be assigned the specific role or roles
needed to complete the tasks at hand, adding transparency, speed and ease to the process of access
rights administration. These roles can be just as easily taken away again when the associated
rights and privileges are no longer needed. Introducing the role concept involves a lot of
preliminary work. However, the effort required is far outweighed by the advantages: complex
interrelationships become more accessible in daily processes, achieving advanced and professional
access management. The workload on administration is dramatically reduced (there are fewer
administration tasks to cope with). Access rights management takes place at the technical level,
making it easier to maintain a high degree of security, and can be easily controlled across
platforms from a single point of administration.
SAM Jupiter not only
enables the role-based administration of access rights, it also has facilities for automating
routine tasks.
SAM Role Modeler
simplifies the process of role identification and definition by applying sophisticated data mining
technology to automatically utilize existing organization data and security information from SAM
Jupiter Repository. Tried and tested, this can save your organization a lot of time and money.









