Attestations, or certifications, are a fundamental IAM process for verifying that users have appropriate access rights within an organization. They are crucial because they represent a key touchpoint between the IAM system and users, including business leaders, shaping their perception of IAM. The primary drivers for attestations are enhancing security by preventing unauthorized access, ensuring compliance with regulations like NIST, SOX, and HIPAA, and mitigating insider threats. They also support data integrity, operational efficiency, and auditability. Common types include user access reviews, role certifications, and privileged access reviews, with practices varying across industries such as finance, healthcare, and government due to different regulatory and data sensitivity requirements. However, implementing attestations faces challenges like managing large volumes of data, complex access rights, user fatigue leading to superficial approvals, and integration difficulties. Tools for attestation are usually embedded within comprehensive IAM platforms rather than being standalone products.
Hello everyone and welcome to another episode of the Identity Navigated. Today we will talk about certifications or also known as attestations in IAM. This according to me is one of the most, if not the most important IAM process. This is because this is where the IAM systems interact most with the users. The only other things could be login. But when something goes wrong with the login, normally they remind users of a help test. But any time a certification campaign is launched, an email reminder is sent or any other notification to remind them that certification needs to be carried out, remind the users of identity and access management. This is where executives outside of your own hierarchy knows of IAM systems. The leaders across companies, the business leaders, the business interacts first hand with the IAM system, see what level of communication is being sent out, see what their experience is like and based upon that they create an impression of the IAM team. Now this is where this is most important because this is where we have maximum interaction with the users in the way in this channel of certification. So throughout my career, I've been lucky to have implemented various innovative certifications program and by virtue of being in an audit firm for some time, I've also looked into regulatory requirements and what do regulators look at in terms of certifications. But before that, a bit of a personal update for the last couple of weeks, I was actually traveling for some time, I was overseas last week, visiting my extended family, the weather is getting absolutely depressing in New Jersey, especially after the last daylight saving last weekend. But a good thing is that I am speaking at a user conference on 16th about running an effective IAM program and looking forward to that. So let's dive into attestations. So ELI 5, it's plain like I am 5, what is attestation. Now imagine you have a big box of toys, but not all toys are for everyone. Some toys are for older kids, some are for younger ones. Now in your house, there are rules about who can play with which toys. This is kind of like identity and access management in the computer world. These rules. Now let's talk about attestation. So imagine your mom or your dad checks every now and then to make sure that everyone is playing with their right toys for their age. They might ask questions like are you supposed to play with this toy or is this toy safe for you? This is like attestation. It's a way of checking and making sure that people in a company only have access to the computer stuff that they should have access to and nothing more. So attestation in a nutshell attestation in IAM is or are critical processes for verifying user access rights within our organization. Now IAM more than any other team in the organization knows the importance of less is more. Less is more. So why do organizations need attestation? Obviously the direct answer would be enhancing security. Attestations help ensure that only authorized individuals have access to specific systems, data, resources. So this is key in preventing unauthorized access which can lead to data breaches, leak of sensitive information or any other security incidents. Apart from security obviously compliance with the regulations is possibly the number one reason why multiple organizations carry out certifications. And unfortunately this is the reason this is possibly the reason that this is carried out badly because what we are only trying to do is make sure that we are in compliance with the regulatory needs and not really thinking about how can we enhance certifications to be a true tool in our defense and depth approach. But in terms of compliance with regulations, right? So the NIST CSF PRAC4 which I have written down here, this states that access permissions are managed incorporating the principle of least privilege and separation of duties. So your segregation of duties and your least privilege. So this least privilege part especially quickly translates into your attestation processes that you carry out. And then with regards to multiple industries you have other regulatory requirements that we need to comply with. So attestation helps in demonstrating compliance with these regulations by regularly reviewing and validating access rights. What else are the reasons for us to need attestations? We have spoken about security, we have spoken about regulatory requirements inside the threats. So somebody is changing jobs, we do not want them to keep previous access, somebody was on a temporary assignment that needed a dedicated access. So these things like these increases the risk of insider threats. So attestations help in minimizing this risk by regularly checking and adjusting access rights. It could also be directly related to data integrity. If right people have right access to the data, we would be more confident in saying that the data integrity is intact or there would be less chances of data corruption or laws because only the right people have access to data. So a bit of a stretch here if I could say but this is the one. Operational efficiency. Now certifications are not usually thought about without bringing operational efficiency. But by regularly reviewing and updating access rights, organizations can remove unnecessary access privileges which can simplify management and improve system performances. Audit trail and accountability, this is definitely needed. Audit trails also are needed for compliance purposes but attestation provides the records of who had or has access to what which is important for audit trail. So this audit trail is not only used for regulatory purposes but also is crucial for investigating security incidents or breaches. And then responding to changes. So all of us are working in a dynamic organization right now. Employees are changing roles, leaving or new ones joining. So attestations help in properly updating access rights in response to these changes, ensuring that access privileges always align with current role and responsibilities. So these are some of the reasons that attestations are required. The most important of ones would be like security, insider thread, compliance and audit trails and accountability. Everything else I think would be bit of a stretch. Now let's deep dive into type of attestations. And so every time I've asked this question in an interview I've always got great answers. Like you know there is a user certification, there is an application certification, there is a role membership certification and what not. But essentially what we need to look at is there is an object involved in the certification. So the certification could be about make of an object. So it could be about an object like role. So it could be role certification or a user certification which is like an identity cube and sale point or a user object or a recall. Or it could be about data associated with an object. It could be like the assignment criteria associated with the role or it could be like access to an object. So how many users have got access to this application or how many users have got access to this entitlement. So think of certification not just putting it into specific buckets, but think of it as either it could be about make of an object data associated with an object or access to an object. This you can absolutely define this object. But normally we look at user access reviews which are carried out mostly by users manager. We look at role certifications which are of two flavors. Membership that is role membership certification who has got access to the role and the contents of the role which entitlements or other roles constitutes this role is the role contents certification is also.
application. The same thing membership entitlements who has access to this applications it could also go into little more detail about what is the type of access to they have and also about entitlements as to which are the entitlements that are associated with this applications. One of the most important certification is the privileged access certification so which are the privileged user accounts in the system or privileged accounts in the system who has got access to it. They could be both human and non-human accounts so there could be a privileged account associated with a user and we want the manager to certify it or there could be a generic privileged account with an owner defined and we need to make sure that the owner is correct is active user in the company is still the rightful owner and also you know if it is a shared account how is that permission being given if that is given by an AD account membership is that AD account membership correct up to date and things like this. So privileged access certifications do have some flavors as well and I think these are the most important certifications for an audit perspective and then entitlements again you can have who has access to these entitlements like for a specific entitlement you can carry that out or is this entitlement associated to a particular application so it could be of any type to be honest depending on your specific organizational needs. So when I've looked at attestations or certifications at different companies it is not a one-size-fit-all solution so their application varies across different industries so just at a high level if you think about finance sector where I work right now so it has got high security and compliance needs so we deal with highly sensitive financial data subject to thankfully stringent regulations like socks, serbane socks law or act GTPR and YDFS and others. So attestations in this sector are critical for ensuring that only authorized personnel have access to financial systems and data. In financial sector we need regular reviews and obviously privileged access certifications which I halved on so much is because of microintessor association with finance sector. Health care now health care really focuses on patient data privacy so it is actually governed by strict privacy laws like HIPAA which stands for Health Insurance Portability and Accountability Act. I think my CSP training or CISSP training is paying dividends so and I lost my train of thought so yeah HIPAA is required for a health care sector for making sure that there is a focus on patient data privacy and this ensures that health care professionals have access only to the patient data necessary for their rule. Varied access level is another important type of attestation in in health care sector you know there are doctors and nurses and administrative staff and they require different access levels and then emergency access certifications so in health care more than any other field emergency situations can associate quick access to patient data and attestation in the sector must balance security with the need for rapid access and critical solutions so this is another type of check and balance in terms of how do health care sector take care of patient's privacy and then government sector there are obviously nothing more sensitive or classified than than the data in government sector so attestations are crucial for it because we need to make sure that only authorized personnel have access to certain level of information and then there are wide range of information types like public records to confidential records to national security information and then attestation needs to be tailored to ensure appropriate access based on security clearance and job functions and then public accountability government agencies need to ensure transparent and compliant attestation process to maintain public trust and adhere to legal standards however this should be applicable to all sectors but but not anymore than then government sector so I could keep going on and on about telecom sector which I was part of in my previous jobs so depending on the type of industry that you are in there would definitely be some different regulatory requirements or different challenges that would be present yourself presenting to you when you carry out these certifications so in terms of differences among each sectors the regulatory framework like Finder for finance, HIPAA for health care they basically present a different set of challenges or opportunities and then types of data protected and then frequency and rigor of when the certification and how often would be carried out now we spoke about the different sectors we also spoke about different type of certifications remember object the make of an object the data associated with an object and access to the object now let's look a little bit into what are the different methodologies in attestation so the one which is most common to all of us is the periodic review so scheduled regular reviews of user access right is something that we are all familiar with it could also be event driven so it could be triggered by specific events such as roll changes departures new regulatory requirements so these reviews ensure that the access right remains aligned with the current needs the most common use case that I have seen is in terms of movers so either you or somebody moves to a different department or exterminated you know the certification set triggered so that we can we can make sure that data is up to date a role-based attestation you know reviews access based on predefined rules and showing that individuals only have access right that their rule requires all of them could fall into the category of automated or manual attestations depending on whether you are utilizing software tools or are you using the excel files and share points there could also be add how attestation right so unplanned checks that could be initiated in response to security concerns or incidents to verify access right immediately could also be another flavor of attestation it could be user centric it could be entitlement setric one of the entitlement or one of the certification that is very less frequently used is the peer review which involves users peers in the attestation process to help verify whether the access is appropriate based on their understanding of job functions and requirements so when we talk about user access reviews we normally go about you know the manager should be reviewing the access but there are also flavors to like self-review in which you review your access yourself there is also the concept of peer review and then obviously the manager review right so work with your auditors if you can take some work away from the plate of the poor managers who have to identify and rubber stamp or stamp everybody's access and put it on user's plate that is definitely an advantage we already spoke about managerial review in this flavor and then risk-based attestation you know prioritization reviews based on a level of risk associated with certain access rights could also be one of the methodologies of certifications now let's talk about the challenges that we face in certifications obviously volume of data we have such a large amount of data we have so many users they have varied access rights it's many too many relationships between system access and users so reviewing all of these could be overwhelming and resource-intensive complexity of access rights I don't have to tell you all you all are here because you are interested in identity and access management or trying to fall asleep in either of those cases I do not have to talk more about complexity of access rights that environments are pretty dynamic especially with cloud coming in and most of the companies have partial presence on premise and in cloud and in the SAS ecosystem this is a pretty complex environment to wrap your head around or hands around there are obviously manual processes still which is definitely a challenge lack of clarity
So most of the stuff that is associated with attestation process is non-IT stuff and they need to have absolute clarity on why this is important because otherwise what happens is the user fatigue sets in right and this leads to robust stamping or automatic approval without prior reviews. And I tell you, I am a information security practitioner and I am guilty of carrying out these robust stamping sometimes myself because it was just the last day and I had to review excess to 100 people because they were reporting to me and I did not want them to go to my boss and this is just I'm not very proud of but robust stamping is a real thing. The user fatigue is a real thing that is happening out there. Integration issues, we need to get the data in and then after the certification is carried out, we need to either move the excess, we also need to have the audit trail, the complete and its completeness and accuracy checks. So the inadequate tools are just the amount of work that goes in to create this end to and work flow in an automated manner is pretty intensive. Policies and procedures gap, we will talk more about it in a bit but when organizations lack formal policies or procedures for attestations, this leads to inconsistent applications and enforcement. Audit trails, so maintaining comprehensive audit trails for attestations can be challenging. So how do you ensure that the data that you are presenting to your auditors goes through compliance or completeness and accuracy checks? So think about that, I'll give you a hint in a word blockchain. So in sufficient training, we already spoke about this and then balancing security and usability. So you have to find the right balance between strict access controls and allowing employees to perform their job effectively can be challenging. So double stamping, complex access rights, insufficient documentation, sometimes lack of clear ownership, poor communication which is root cause of most of these issues, lack of training, one size fit, all approach failure to update that attestation process, one time to get it done by next week, not understanding the complexity of it, just trying to have it as a check box for your auditors are some of the major challenges that then an I am practitioner faces when implementing a comprehensive or a holistic certification program. In terms of tools, I have not seen and I could absolutely be wrong, but I have not seen too many one off tools that provide only certification capabilities. Most of the tools that I have seen are actually inbuilt. So like your sale point identities, IQs or your RSA or your cyber art privilege access security, IBM security identity governance and intelligence, one identity, I can keep going on and on. But mostly I have seen that certification is a module in the existing tools rather than this being a tool in itself. This is because you have to carry out so many integrations with this certification system if you want to implement certification as a service. So I am not saying that is not possible, I have seen some crappy implementations of it out there, but nothing that has really caught my eye. But if I do something or if I find something, I would definitely let you know. And if I make a tool out of it, I will ask you to buy it as well. On the topics of buying stuff, I actually got educated myself last week. So I was told that, so I was approached by this gentleman who wanted me to sell his products nothing wrong with that. And I was told that if I do it at the start or at the end of the podcast, this would cost me like this would cost them like $X dollars. And if I do it in between the podcast, it would be like $2X dollars because that is where the users are consumed with the content and whatnot. So anything that is advertised within the podcast or between now in the middle of the podcast is actually costlier than anything that is then at the start or at the end. So I found that pretty fascinating. And it almost felt like common sense to me after I knew of it. But when I heard of it for the first time, it definitely was new knowledge. So that's that. This is a bit of a useless piece of information that I knew that I had to share with you all as well. But let's talk about future of attestations and identity and access management. It won't be a surprise. But obviously increased automation with AI and machine learning technologies, we can expect more automated attestation process. But there are many of these things that could be done today. And how do you think about them is something that I am a big advocate of. So if you don't take anything out of this podcast, this is the only thing that I want you to take back. We always think of certifications as, okay, we are doing user access reviews. We are doing privileged user access certifications. We are doing application attestations and whatnot. So we are thinking in terms of what do we as security team wants to do or what do we as the control solution implemented for auditors want to provide to them. Think of it again from the user's perspective. Right. So if you are sending to Bob, I choose a registered certification tomorrow. You are sending him a privileged certification day after tomorrow since because he is a data owner for an application. You are sending him an application certification. That is not a good experience for Bob because carrying out your certifications is not his job. Right. We are implementing certifications in silos, depending on what they are there for. I am asking you to implement the certifications by putting user in the center and you can absolutely do it. A amount of work on the IM team would be more if you do not do it in silo, but the amount of work on Bob would be significantly less. And this is what I want you to think about. Another thing is I want you to work with your auditors. So why do you have to certify birthright rules? You shouldn't. Why do you have to certify rules which are auto-provisant to users based upon an assignment criteria. Can't somebody just look at assignment criteria and say okay, if user profile or job profile is equal to IT analyst and location is equal to New York City, this is a birthright rule given to the user. Now you can just verify this assignment criteria rather than identifying every user associated with IT analyst New York City. So push back, sit down and discuss with your auditors what is really needed. Sit down with your lawyers or legal team and based upon all the regulatory requirements ask them of what can you do so that you are meeting those requirements. And at the same time, not just throwing everything out at the user because right now the problem with the industry is that we are expecting user to do it because they have to. And this would lead to the birth stamping and this definitely leads to the birth stamping. So how do you minimize the amount of clicks that the user has to do and how do you make your certifications, user centric are the two things that I want you to take them out. So if you if they have to carry out user access certification, they only need to carry out user access reviews for those access that was requested by the user and not provisioned to them automatically. And also based upon everything that was requested, what was the high risk that was assigned. So if they requested for let's say wish your license, that is not a security issue, it could be a licensing issue. But only thing that the requested which is in high risk which was out of band and is not an alignment with all of their colleagues is something that the manager should should attest and nothing else and nothing more. So real time attestation is another thing. We need to start performing real time on near real time attestations provide continuous assurance of appropriate access. We can definitely integrate with other security measures like behavior analytics, anomaly detection and
to provide a holistic security posture. I already spoke about blockchain for a testation. So to create a mutable record of a testation, enhancing the audibility and trustworthiness of the that of the a testation process, think about blockchain. We have already spoken about risk based and enhanced user experience, but this would continue to be focused. There's I'm sorry to repeat myself, but certifications have to be user focused. The regulatory technology I think has a lot of scope and developments in red tech may provide advanced solutions for a testations that help organizations stay compliant with changing regulations more efficiently. So I'm not I would not be surprised if another certification as a service tool is introduced in the market by a big four auditing firm. It could be packaged as a red tech beer and this provides all of these features like real-time attestations, continuous monitoring, behavioral analytics and depending on what you feed into the system that what the requirements are that company should comply to the regulatory requirements, it would carry out die type of certification. User behavior profiling, context of error, detective analysis, you know, obviously there are obviously tools out in the market like sale point has something in their identity cloud. It does give you or the manager a thumbs up or a thumbs down saying that you're okay to certify it and you are not okay to certify it. So we have to mature our tools to the capability where the prediction they are making does not need to be weighted by a human. We should trust their predictions and this is where we truly want to or be and where their prediction or are crushed in their prediction ends only those things needs to be certified by the manager. Another thing is if you are creating a business case because I'm pretty sure that most of the companies today are doing certification. So you do not have a green field implementation of certification in most cases. So this is just an advice is if you are going to create a use case or a business case for enhancing certifications, don't just keep it focused on security and you would you would hear me saying this all the time that business cases created only on based only based on security should not be multi-year. So if you have an initiative that that you know with need multi-year financing do not solely focused on the security concerns that is addressing because what would happen is in next year funding exercise you would be fighting against some new initiatives you would be fighting against some new things that needs to be sponsored and you would as you mature in your initiative you will continue to fall down the priority ladder. So if you are creating this certification business case, plug it in with your zero trust model, plug it in with anything else or the user experience. So tie it back to initiatives like this and that would help you get multi-year financing or funding and do not just focus solely on the security part of it because security as soon as bare minimum is done that is all right and next year or year after next you would have to continue to fight with other new initiatives that are out there. So just just going through a basic list of how do you implement a successful attestation process right nothing new nothing that you all folks do not already know about it is more of a deep fresh it define the scope and the objective what do you really want to do why do you want to do it how does it help the business securing up executive sponsorship develop clear policies and procedures establish roles and responsibilities training and education programs implementing technologies starting with a pilot effective communication interesting non-compliance measuring success creating an audit trail right so these are all the paths or processes in how you implement an successful implementation. So let's start looking into how do we create certification process as user centric and let's challenge our editors and our governance and risk teams to clearly define what is it that is needed I have seen so many I am teamed failing because they do not understand what is really needed of them so technology implementation implementation of certification in any IGA tool is a relatively simple process right but I am teams get so much pushback on this because they were never told what is actually required at a program level at a company level they're always given information in bits and pieces or we also need user access certification there is another thing that is coming in and we need to certify based upon that look at it at like for the entire year what are the type of certifications that you would need challenge your auditors challenge your governance and risk team to give you that data once you have that data then look at it from the user's perspective and that is where your starting point of the compliance or the certification or the station program should be right so I think this is pretty much it for this episode we are almost 36 37 minutes in thank you all for listening I really appreciate it the last episode in which we talked about toll-based access control did get some very good reviews so thank you all Yank also did suggest me that I should be doing your follow-up sessions on policy-based access controls and that would be a success controls and basically should call it back to the future as in BAC and I found that idea to be absolutely fascinating so thank you Yank I will definitely start working on it but thank you for listening I hope all of you have a good rest of your day you can always reach out to me via LinkedIn or I can always be emailed at the identity navigator at gmail.com so thank you all this is Rohit your identity navigator till next time
Podcast Summary
Key Points:
Attestations (certifications) in IAM are critical for verifying user access rights, serving as a primary interaction point between the IAM system and users, including executives.
Key reasons for attestations include enhancing security, ensuring regulatory compliance (e.g., NIST, SOX, HIPAA), mitigating insider threats, maintaining data integrity, and providing audit trails.
Common types of attestations include user access reviews, role certifications, application certifications, and privileged access certifications, which vary by industry (e.g., finance, healthcare, government).
Challenges in implementation include data volume, access complexity, user fatigue leading to rubber-stamping, integration issues, and balancing security with usability.
Attestation tools are typically integrated modules within broader IAM platforms rather than standalone solutions.
Summary:
Attestations, or certifications, are a fundamental IAM process for verifying that users have appropriate access rights within an organization. They are crucial because they represent a key touchpoint between the IAM system and users, including business leaders, shaping their perception of IAM. The primary drivers for attestations are enhancing security by preventing unauthorized access, ensuring compliance with regulations like NIST, SOX, and HIPAA, and mitigating insider threats.
They also support data integrity, operational efficiency, and auditability. Common types include user access reviews, role certifications, and privileged access reviews, with practices varying across industries such as finance, healthcare, and government due to different regulatory and data sensitivity requirements. However, implementing attestations faces challenges like managing large volumes of data, complex access rights, user fatigue leading to superficial approvals, and integration difficulties.
Tools for attestation are usually embedded within comprehensive IAM platforms rather than being standalone products.
FAQs
Attestation in IAM is a critical process for verifying user access rights within an organization, ensuring individuals only have access to the systems and data they need, similar to checking that people are using appropriate items based on rules.
Organizations need attestations primarily for security, compliance, and audit trails. They help prevent unauthorized access, meet regulatory requirements, and provide accountability by regularly reviewing and validating access rights.
Key types include user access reviews, role certifications (membership and contents), application certifications, privileged access certifications, and entitlement reviews. These focus on objects, associated data, or access to objects.
Attestations vary by regulatory frameworks and data sensitivity. For example, finance focuses on regulations like SOX, healthcare on HIPAA for patient privacy, and government on security clearances, each tailoring processes to specific needs.
Common methodologies include periodic reviews, event-driven reviews (e.g., role changes), role-based attestations, automated or manual processes, and risk-based prioritization. Peer reviews and self-reviews are also used in some cases.
Challenges include handling large data volumes, complexity of access rights, user fatigue leading to rubber-stamping, integration issues, inadequate tools, and balancing security with usability, all of which can hinder effective certification programs.
Chat with AI
Loading...
Pro features
Go deeper with this episode
Unlock creator-grade tools that turn any transcript into show notes and subtitle files.