Control and Access Management for a large Telecom Holding
Summary
Project milestones:
- Define formal Labor Functions based on employee duties
- Develop a comprehensive RBAC model for the Customer environment
- Deploy the IDM solution and integrate with existing systems
- Launch and customize the Self-Service Portal for staff and external users
Problem: Dynamic business environment is hindered by the outdated and time-consuming access management processes. The Customer is looking for a solution capable of automating automate access approval and provisioning processes.
Result: The implemented solution based on One Identity Manager (IDM) allows the Customer to automate access management for IT systems. Additional benefits include a deep process control and informational log generation for analysis and review.
Plans: Further solution development focuses on update and maintenance of labor functions lifecycle, integration with new IT systems and SIEM.
Customer profile:
The Customer is a telecommunication holding that provides services associated with broadband access to Internet, telephony, digital TV, access to Wi-Fi networks, VPN, LoRaWAN, video surveillance and comprehensive solutions based on the internet of things (IoT) technology stack.
567
cities of presence
20000
employees including staff and external contractors
5000+
workstations running *nix-based operating systems
One of the largest managed optical networks in Europe
Case study overview
The Customer has implemented centralized HR processes. New user accounts are created based on the record management system events. The access to Company information resources is based on requests. The request processing may take up to 3 days based on the number of information resources and users.
The distinctive company factor is the large number of information systems that must be accessed by company employees and external contractors who service and maintain information systems data. Request-based access control management requires significant efforts to process and approve such requests. Another reason for increased timeframe for granting access to end users is the need to establish communication channels between the user and the approver on a case-by-case basis.
There’s no unified method to grant access to internal employees and to 5 specific categories of external employees and there’s no centralized permission provisioning control.
The company actively participates in reshaping telecommunication market. It unites new providers under the single brand that leads to Company restructuring and increase in the number of information systems and staff.
Rapidly changing infrastructure requires access provisioning process to be fast, transparent and capable of providing privileges in real-time.
Efficient and mature tools are needed for providing granular access for various users to Company information resources.
Implementation steps
01
Formalize employee duties into the Labor Functions description based on a set of basic operations associated with business process execution
02
Develop an RBAC model for granting, changing and revoking access based on employee labor functions
03
Integrate One Identity Manager with the existing HR and workflow management systems, using the Apache Kafka message broker. Enable IDM to collect the employee labor functions and enrich it with access privileges and rights according to the role-based model for automatic access provisioning and revocation
04
Integrate IDM with target systems: MS SQL, Oracle DB, MS Skype for Business, MS Exchange and others
05
Create a structured directory on the Self-Service portal listing available systems, resources and roles to simplify access request procedure for end users
06
Deploy reporting functions concerning user roles, access authorization states, target systems’ owners, internal IDM processes, access-related risks for multiple departments and Company as a whole.
Results
One Identity Manager is the access control and management tool for the Customer. Access to the resources is granted automatically in about 3 minutes, based on the role model and labor functions.
Any HR event leads to employee labor functions change and therefore employee privileges and rights also change. One Identity Manager allows to promptly block access to information resources in case of employee dismissal or reassignment to another position.
IDM-based access management allows granular privilege control for every user and every information resource.
One Identity Manager provides security team with vital analytical information that can later be used for IT and security incident investigation.
Apart from the access that was granted automatically, any user can request access to required information resources via the unified self-service portal. The self-service portal allows resource managers to approve and provide access to the Company and contractor employees on-the-fly and eliminates the need for additional workflow management.
Further plans
Further development of IDM-based access management processes includes labor functions lifecycle support and role-model improvement.
One Identity Manager supports implementing new business processes essential for Company development using built-in graphical editor.
IDM can be integrated with new target systems such as general or specialized IT resources. Integration with security incident management systems is also available in order to increase the company’s IT security posture.