Cloud Cybersecurity Infrastructure & Operations Workforce Mobility

Taming Identity and Access Management

Taming Identity and Access Management

While organizations may be looking to leverage cloud, mobility, and Big Data for innovation and productivity improvements, who gets access to what data and which applications without compromising security is keeping IT leaders up at night since stakes are high! What are the current challenges related to identity and access management and what are we doing to address them?

Contributor

    • Connie Barrera, Chief Information Security Officer, Jackson Health System

Download Podcast
Apple Podcast, Google Podcast, Spotify, Pandora, iHeartRadio, SoundCloud, TuneIn, and Stitcher. Find other syndication channels here or search CIO Talk Network podcast on any other app.
Explore More

Transcript 

Sanjog Aul [00:00:56]:

Hello, and welcome to CIO Talk Radio. To learn more about the show, please visit www.ciotalkradio.com. And as always, we invite you to join the discussion on Twitter, hashtag CTR live, and look for this show as hashtag IAM and hashtag security. Today’s topic is Taming Identity and Access Management  . And our guest for today’s show is Connie Barrera, who is the chief information security officer with Jackson Health System. Hi, Connie. How are you?

Connie Barrera [00:01:26]:

Good morning. I’m doing great. Coming to you from Sunnysaw, Florida, enjoying our beautiful weather this morning.

Sanjog Aul [00:01:33]:

Very good. So I’m really already feeling jealous being in Chicago, but we are also enjoying great weather here today. So what we are trying to do, as you know, is to discuss this topic, which is a very important piece of the puzzle. We just wanted to see how is this being handled because it seems like a chronic issue when you talk to any CISO. And what we wanted to see is how complex it truly is. Is that truly a technology issue, or is it a people process or political issue? Why it is not getting solved to the degree it’s supposed to? And given the complexity that’s getting introduced in the whole ecosystem around how we are going to be using technology, how much we are going to use technology in terms of variety. Is that gonna get any better to handle this or it’s gonna get any worse? And if yes, what are you planning for that? So as the first question, what do you think in your view is the complexity that is keeping us up at night when it comes to identity and access management?

Connie Barrera [00:02:34]:

Well, identity and access management, which we’ve coined as IAM, really three little letters that are so simplistic to say. And actually, it’s a beast of an area to get right and implement. And I think the challenge lies with each leap forward in technology that we had with all the different paradigm shifts. We find that although it’s something that we use each and every day in order to access a system, in order to read your email, in order to log into a terminal, you need a user account and password. And, thinking back long ago to the mainframe days, which, it’s kind of funny that, a few years ago, maybe about 10 years ago, every organization was jumping on the bandwagon to get off a mainframe. We just didn’t want to deal with it anymore. But it was very easy to manage. It was basically one environment where it was an ecosystem of data resources, code that everyone accessed from really dumb terminals. Today, if we look at it, I think it’s kind of earth shattering that your average GM car contains more information processing power that was on the Apollo moon landing craft in 1969, and even more processing power than our mainframes back in the 1970s. So it is very much a challenge because of all the technology around us and really all of the lack of integration and I would say lack of standards. It’s very, very simple for us to be able to provision accounts for someone when they come into an organization. Someone joins, onboards today. We create an account for them. We usually have pretty good processes to take that due diligence and give them whatever rights they need, typically, if you have good processes in order. There’s other organizations, though, where the users fill out a form and they say make Mary like Susie. And so in those cases, folks don’t really have a good grasp as to what access the user is receiving really. They have a general knowledge because it works. But is that access appropriate? Is it based on key principles that we like to hold true in security based on a need to know and least privilege? So with every evolution of technology, the challenges to me just increase. And they increase because of the complexity, lack of standards, lack of interoperability, and makes our job much more difficult to get folks the data they need to perform the roles they need to perform in a need to know least privileged strategic way.

Sanjog Aul [00:05:27]:

So your response tells that in many cases, it looks like we could have prevented such issues if we just did not make Mary like Susie or if we did put some standards and actually allowed adherence to that. And frankly, the users are not the ones who are making this access management or identity management a challenge. It is more the administrators. So can we just train people better and put a process in place and call it done?

Connie Barrera [00:05:58]:

I wish it sounds beautiful in concept, and we always should strive to have one cookie cutter solution with one solution that works for everything. But even in healthcare, for example, our sector is a prime example of this. Years ago I worked in an organization where we had basically 300 line of business applications. 85% of those applications did not have any LDAP integration, meaning they weren’t able to integrate, for example, with things such as Active Directory, which means that everyone needed a particular user ID and password. And so the challenge of this is in the healthcare perspective. For example, nurses are the perfect use case for this. A nurse is a nurse, but a nurse can be so different. We have certain nurses, for example, that work in a particular unit all the time. They may work in oncology. And every time they come they come to the organization and have a shift. While other nurses may be assigned to rotate anywhere throughout the hospital. Today they’re in oncology, tomorrow they’re in cardiac, the next day they’re in pediatrics, or even within the day they’re floating around these different units. So even when you have a very solid process in place that you’ve identified, oncology nurses get access to these three applications and certain level of access within that that is appropriate. But when you have different populations that are shifting and it’s dynamic and elastic, if you will, it’s very difficult to account for that. The other difficulty I would say is that the technology isn’t robust enough still to this day in order to accommodate for users’ understanding what the roles really mean. We use, throughout different organizations I work, for example, Lawson. Lawson is an ERP system that generally we use from the HR perspective to manage employees and employees come into the portal to do any number of things such as view their compensation or identify their benefits. And the way that the software is coded is very cryptic. So even when we work with the data owners and work with the data custodians and say these are the different roles that have been made available to the system, so that we again can uphold those principles of least privilege and need to know, these are the roles that are involved. When that output is generated, it really takes a lot of time and effort, even for the people within IT that work with it on a daily basis, to articulate to these data owners what that means. What screens do they see? What fields are on there? What data is obfuscated or not? So no matter how good our processes are, we’re really at the mercy of the application vendors. And I would say even though there’s a lot of solutions out there, I find that we need much more innovation from what these solutions can provide that we’re getting today. Because to me, the technology in place from an IAM perspective, I can’t say that I’ve seen leaps and bounds in improvements in that technology like we’re seeing, for example, we’ve gone from the PC era to some would argue today we’re in the post PC era because we’re really relying on virtualization and cloud. And the endpoint doesn’t really matter anymore. We really care more about our applications and our services, and that’s so true. With Internet of Things, the IoT explosion that we’re having now, which is really exciting. But at the same time, as this explosion is happening all around us with devices all connected to the Internet, whether in our homes and in our businesses, IAM is not keeping up.

Sanjog Aul [00:10:02]:

You gave a number of examples, and it looks like that if we somehow had our own control on the applications we developed, then we would know which particular screen and which particular field has to be accessed by who. And you could have built a matrix, if you will, and then made that available to the system administrator and then have set of processes which could work. So couple of issues that you spoke about here. One is the semantics. So we do not understand semantics, or perhaps the semantics itself changes based on which room or which patient type is the person seeing. And you can correct me if I’m wrong. And secondly, we’re talking about our, we want to grow. We want to innovate, and we want to move quick. And agility is coming at a price because then you want to go to a third party vendor who’s not keeping IAM in mind and exposing that matrix to you the way you would have had as a control if you had your own application. So are we saying that we are embracing new technology, but we are also introducing risk with respect to IAM if you go that route. Is the vendor community which is serving you hearing this? And have they done anything about it?

Connie Barrera [00:11:17]:

I would say secure you’re absolutely right. Security always lags behind technology and innovation, unfortunately. But the reality that we must face and so as security practitioners, it’s really our job to make sure that we’re ahead of the game, that we’re always up to speed with the latest technologies, testing them, and really looking into everything about them. It’s not good enough. Many times I’ve been in organizations that we deploy a particular software technology. And it may be that it’s vendor supported. And in those cases, it’s even worse because people have no idea what it runs, what the requirements are, what the controls are, whether the controls are up and running appropriately. Because it’s easy to say, well, the vendor supports that. At the end of the day, it’s our organization that is on the hook if there’s a security breach, if there’s an issue. So we must know everything about it as if we were reverse engineering it. So to me, don’t put anything in place that you don’t know everything about it, the nuts and bolts, how it works on the back end. And so I would say, yes, the vendor community is not really stepping up. And when we work with different partners and different vendors over the years, many times we’ll get, well, this is what we provide, and all the customers are using it in this way. I’ll give you a perfect example. From a patient system and billing perspective that we use that we call EHR, electronic health record solution, in this solution, we were looking to integrate, to do AD integration, to streamline the process for user authentication and access to the system, which meant we didn’t need to keep one additional user ID password for folks to remember. It was just going to be their AD account, which they already had, making it easier streamlining the IAM effort. So in talking to the vendor, their current solution was so archaic that it really required us to put in a lot more hardware and almost force a square peg into a round hole. And their response was, well, this is how we do it. So as consumers within an organization, we’re really currently, I think, at the mercy of vendors, and we really need to take a concerted effort to push them into the right direction. When it even comes to cloud, there really aren’t that great of options from an IAM perspective. When you look at SaaS applications, there really are big gaps within the way that we can manage user identities. And managing user identities are really a big deal because when you look at all the breaches that have happened in 2014 and 2015, a lot of those breaches resulted because of breaches to user accounts. It wasn’t that attackers got in and just exfiltrated the data magically. It was that attackers were able to compromise credentials within the organization. And by and large, these were credentials that were not necessarily appropriately managed, were not necessarily having the most robust passwords. Because when users are faced with managing anywhere upward of 5, 10, 15 credentials, it’s almost impossible for them not to fall back on bad practices, such as writing them down or keeping them in a spreadsheet.

Sanjog Aul [00:15:00]:

So let’s take a quick break. Listeners will be right back. And let’s inventory a couple of issues, Connie, that you had shared. So in a way, the central team looks like that the cloud providers or the SaaS application providers are having their own limitations or maybe they have not purposely per se, but they have not been able to give you the required control so that you can use identity access management. On the other hand, a security tool or solution provider, which says that I can give you the best identity access management solution, they can just give you the tools. But they really don’t understand the semantics, and they can only make it so flexible. On the third side, you have semantics issue or the changing roles or something which a user does today could be changing tomorrow, and that you have to keep track of or sometimes things fall through the cracks. So you got this three pronged problem. God bless. How will how are we even actually trying to handle it? Let’s talk about it more when we come back. Please stay tuned.

Sanjog Aul [00:17:36]:

Welcome back. So we’d actually discussed three areas that cloud or SaaS providers are not providing you enough capability to handle IAM effectively because the features and functions and application screens, etcetera, are not being dissected to the degree where you have granular control. Then on the other hand, technology solution providers who say that they have the most robust tools, they can only be so generic or customizable to any degree, but they still may not be able to get us to a level where we can be feeling comfortable. The third is the semantics of what a person does and how they can use it or maybe if you’ve got two different roles, how they can combine into, making or creating a security hole. So you got this three pronged problem. So we can talk about the problems and get more depressed than we started the show, but that’s not the case here, and we don’t want to do it. So let’s talk solutions. Let’s talk about how are you even tackling this? Is there a light at the end of the tunnel? Is there a blueprint?

Connie Barrera [00:18:43]:

I think so. And I think the most important point is that sometimes, depending on the culture of the organization, you really need to take a step back and say we’re not going to be able to solve everything. But just because the problem may be overwhelming is not enough reason to say, well, let’s just throw our hands up and give up. Sometimes there are throughout the years I’ve encountered folks that want to solve everything. And because you can’t answer the question for every one of the systems, it’s difficult to get them on board. But I think the first key steps are this. You want to make sure that you have the right person leading this initiative. It really needs to be somebody with expertise in this area. This is an area that I’ve seen several organizations rejoice at the fact that they’ve purchased, that they made the decision, they purchased an IAM solution, and they feel that that’s the magic wand. That that’s really a key first step in identifying and selecting the right solution, but by no means are your problems solved. It’s only the beginning of the really manual and heavy lifting that needs to happen. One word of warning or caution that I would say about selecting a solution. I think most of us in the IT community are very familiar with Gartner, and we uphold their suggestions and especially their Gartner Magic Quadrants to refer to them as to what solutions should we look at, who are the leaders, so on and so forth. But it’s critical to realize that just because there’s a solution in the upper right hand quadrant, it doesn’t mean it’s the right solution for your organization. And you must really dissect a solution and see what are your business goals, what are your drivers, what are your key requirements. And only then, and having done really a proof of concept that you see that the solution can really work should you make that purchase decision. I’ve seen organizations really go into a really deep hole because they’ve just selected something that their peers oftentimes when I worked in an organization that was both higher ed and healthcare, one of the things we did for every project was what are our 10 partnering co peers doing in this space and tried to mirror that because there was always a suggestion why reinvent the wheel. And while that’s true, the fit needs to be right. So selecting the right solution is key. Having the right person with that expertise. And then culturally, from an organization perspective, understanding that identity and access management really is a process that is a life cycle, that is cyclical in nature. That like it or not, it’s never going to end. We really need to come to grips that we constantly need to be provisioning, deprovisioning. We need to be enforcing. And I think one other key aspect is that we need to be reporting and auditing. We cannot assume that we put a process in place and that it’s working appropriately. That’s probably one of the biggest pitfalls that you put a process in place. Even if it was tested aggressively upfront, you need to constantly be on a we like to do quarterly reviews, but whatever that timeframe for your particular organization is, that’s critical and very important. And part of those reviews are really a wonderful opportunity for process improvement. So as you go through the cycle over and over, hopefully you’ll be fine tuning your process and just making it better overall. The other thing from the reality that it is a cyclical process is that the organization really needs to understand there’s a long term commitment. IAM is not an area that is on the cheap. These solutions are all hugely expensive, not only from purchasing the solution from a licensing perspective, but also the man hours and the staff that you need to really run it and to really keep it finely tuned. And so, not even talking about deployment. Deployment is labor, again, very labor intensive. But I think the difference between a successful identity and access management deployment and not is really in that, identifying, really documenting the business drivers, documenting your goals, and then taking it one baby step or one little step at a time. As we say, you don’t want to boil the ocean, really can’t boil the ocean, and that couldn’t apply any better to IAM because it really requires taking one bit at a time. And I would say this, for example, whenever you’re bringing in an application, and you really shouldn’t try to do too many at a time. When you’re starting the project, you probably want to do one application at a time. Pick probably your easiest applications. This will give you the business a win. It’ll give you quick turnaround. And then you’ll see right away user acceptance, the users enabling or embracing the technology, I should say. Because at the end of the day, it’s all about your users and it is about security, but if the users aren’t cooperating, they will find a way to circumvent. And I think to me, I don’t really see it as users wanting to be malicious. Most of the time by and large is users wanting to get their job done. And if technology gets in the way, they get really creative and they find ways to get around it. So IAM needs to be run as a very formal project with very well defined milestones and many projects within. The other thing I would say is that it’s really key throughout the project as well as afterwards to establish key metrics. How do you know that something is successful unless you’re measuring it and really seeing your performance your key performance indicators? And so in this space, it is an area that really we can have a lot of metrics easily, but they must, again, be appropriate to the organization. So one real easy one that I can share is, as a result of IAM and users not having to have 10, 15 different credentials, what are your service desk calls? Usually, your service desk calls for, hey, I need my password reset, I can’t log on to the system, will dramatically go down. Also, those FTEs can be reassigned to do something else, something perhaps more involved, more creative, more innovative instead of answering calls to help people reset their passwords. So establishing metrics is also very, very important throughout the project as well as once you’re bringing in the different applications on board.

Sanjog Aul [00:26:10]:

Alright. So when we talk about the specific areas where you mentioned the third party providers are not up to speed and perhaps SaaS or the IAM providers. And you did mention the ways that you should look within. When we look within, if you notice that some of the areas where you start building an application or identify what needs to go where falls in the CIO’s group. And then when it comes to the accountability for whether something got breached, etcetera, the CISO, are you trying to manage or take responsibility while just having influence on the people who could be actually making this happen, making the applications robust and/or creating vulnerabilities in it? What’s the interplay?

Connie Barrera [00:27:02]:

Absolutely. I think that’s one of the biggest and most challenging factors within the work in the IT space. Throughout different organizations that I’ve worked, the question, I think more so the past 8 to 9 years or so, especially with the proliferation of CISOs in different organizations, some of which were prompted by all the massive breaches that we’ve had the last year or so especially, has been where does the CISO need to report? And what is the relationship between the CISO and the CIO? In my current role within my current organization, I report to the CIO. I’m very fortunate and lucky to say that our CIO is 100% security minded and supportive. And not just saying the right things, but through his actions and through funding and not only through the financial aspects and budgeting for what we need and what the organization must have to have our solid controls in place and be proactive, but also from the perspective of the FTEs within IT. Basically, he tells me, whether or not they report to me, they report to me when security needs something, and they must action. I realize probably my situation is unique. There have been other places that I’ve worked at where the security team has wanted to report outside of IT because it was a constant struggle to make headway on any initiatives when it’s a fine balancing act because when let’s say there’s an important project and one could argue that every project is important or at least important from the security perspective because no matter what the cost factor or no matter what that project will service, the potential risk if that data set were to be breached could be huge and could mean huge liabilities for that organization. So to me, when something is coming in, whether it is costing the organization $500, $5,000 or $5,000,000 we review and analyze that with the same scrutiny and make sure that the controls and identity and access management needs are dealt with in the same consistent manner. So I think the key thing is that, to me I view security not just as a role of the CISO or the role of the security team. From the first moment that I joined Jackson Health, my message was always we are in this together. While the buck stops at my desk from the security perspective and I own that and embrace that reality, I need to have security deputies everywhere, especially in IT, especially with the infrastructure folks, with the network folks. They need to be security minded. I remind them of that all the time. I also ensure and I think the other very important aspect is that CISOs and security people for a long time have a really bad reputation. I think somewhat self inflicted many times because it’s a known quantity that some people enjoy saying no. And they may be on a power trip by saying you can’t do that, you can’t do this, you can’t do that. To me, it’s not my role to get in the way to be a roadblock. It’s my role to be a trusted adviser and to make sure I point things out, to make sure that I am firm on recommending alternatives so that at the end of the day, we’re not standing on the way. We’re allowing the technology to move forward, and we are enabling us to be innovative while we’re being secure. I do that with the constituents all the time. While it is very time consuming, I walk around the different areas of the hospital. I talk to people very much informally, not because we’ve had any type of scheduled meetings. And I always say to them, when something is not working, if you’re not getting the appropriate response, let me know. Because even if it’s not a security matter, even if you don’t think it has anything to do with me, at the end of the day, it does. Because when you want to get a file to someone and email didn’t work because your quota was too high, you’re going to go around and try to use something else. You’re going to try to use Dropbox. You’re going to try to use one of the cloud providers to do that. We want to make sure that that doesn’t happen. So the relationship between me and my boss, I think, is very solid. We’re constantly communicating, I think, on a daily basis. We’re talking about different security initiatives, and we’re very much lock in step. He knows exactly everything that’s happening in my program, and I understand not only the initiatives and the goals of the rest of the IT division, as well as the goals of the business. Sometimes within IT, we may lose sight of the fact that we’re here to serve the business. We don’t just exist because technology is cool. I’m very much a technologist. I love technology. I like to be, if not on the bleeding edge, certainly on the leading edge of research and testing. But at the end of the day, we need to take a step back and figure out, is the technology getting in the way or is the technology enabling our constituents? And if it’s getting in the way, we need to do something about it.

Sanjog Aul [00:33:05]:

Let’s take a quick break, listeners. We’ll be right back. And let’s talk about the importance. And, yes, it is important. IAM is important, but then there are so many other things that happen and are to be handled under the umbrella of risk management. So what is the way for us to keep it at least top of mind if possible, or should it remain top of mind in order for it to get the attention and investment? Because based on prior conversation with some CISOs that anything which is supposed to be more strategic usually gets at the top of the list, and IAM is something that you have to do on a regular basis. It’s like a regular security or a management function. So if you try to go in there and try to bring attention to it, it’s like the same old same old. So how do you make it one of the top priorities? Because this could become the very reason why you introduce risk knowingly or unknowingly within the organization. Please stay tuned, listeners. We’ll be right back.

Sanjog Aul [00:35:32]:

Welcome back. So how do we get the IAM, identity and access management, on the priority list? Because there are many other things and perhaps seemingly more strategic versus same old, same old, which IAM could be considered as. 

Connie Barrera [00:35:51]:

Absolutely. I think there’s in this realm as well, while it is many times difficult to have the right focus on a particular need or a particular solution, I think there’s a ray of light here simply because boards, organization boards are constantly being bombarded via different vendors and board topic type of literature and periodicals that they receive from the perspective of cyber attack. And while I think sometimes that’s a word that is in some regards kind of overly used, it is very much a reality that ties directly to that. So we certainly can have the conversation about identity and access management from even cyber attack prevention. I remember reading something in Computer Weekly, highlighting that identity and access management was really set to move forward to the forefront in 2015. Because as I mentioned earlier, most of the high profile security breaches that occurred within the past year resulted because it is a result of some staff with credentials and privileged user accounts. There’s a website that I actually love, and I refer to this many times when I’m meeting with different people. I use it with folks around the hospital when I have little informal meetings with them. Or I’ve also shared it with the board. Use whatever search engine you like and you browse for Information Is Beautiful data breaches. And you’ll get this grid that shows you over time, I believe it’s from 2004 to present. And you’ll see an explosion of bubbles. Some of them are much larger, which indicate the larger breaches. Click and you can drill down and you get more information. But that depiction is priceless. Like they say, the picture is worth a thousand words, and in this case it really is. Because you can make a solid case where you see organizations that, at least on the surface would expect, don’t lack for funding in the security space, such as finance. You see Chase on there. You see Sony. You see mammoth organizations that have all been breached. And sometimes multiple times, such in the case of Sony. And so I think that’s one way that is really impactful in not only reaching the board, but executive leadership within an organization. The other thing is that other ways to bring attention to IAM is talking about finances and talking about cost avoidance, for example. That’s a really good one, where you can show how you’re reducing future expenditures by leveraging IAM. And you can tie this to not only reducing risk, but eliminating the possibility of what I call permission creep, which is, an employee that may have worked in HR, and then they worked in finance, and then they worked to another business division. And all along, you did not have a good process in place, and so they’ve accumulated all these permissions over time, giving them sometimes as much or more access than an admin who would have administrative permissions to the back end server but not necessarily access to the data. So you have a really large potential for internal user threats, users that for whatever reason have an opportunity to do wrong. And so you really want to keep that opportunity away by making sure the permissions are appropriate. You can also show cost reduction because it really is quite costly to have a fully operational customer service center up and running 24/7. And if it’s not operational 24/7, then you have potentially service interruptions. In the hospital, we’re 24/7. We’re not 8 to 5. And so, there’s patients coming in throughout the day and night. And actually, we have spikes, usually at rush hour and then beyond the night as people are getting out of work is when much of our emergency department activity spikes. And so that’s typically the area in most organizations where our service desk is shutting down. So having a solution like this in place will really streamline interruptions and issues people are having with their user ID and passwords. The other thing that could be highlighted is timed productivity and process improvements, where employees are really up and running without the guesswork. Because sometimes, even though generally the make John like Jack and, John is working, John was a new employee and copying or cloning those permissions generally is effective. Sometimes it’s not 100% effective because maybe that person’s role is slightly different and may have other things that they need to be able to access. And so we waste a lot of time scrambling to really find a way around that and to really finding that needle in a haystack, if you will. Because at the end of the day, no one really knows what the roles mean or what permissions they’re getting. User convenience and satisfaction I think is huge. I think in IT most of us would agree that IT doesn’t have the best of reputation as a division, right? Though I would say at the same time people usually have their IT favorite. All of the people around the organization have a person they’d like to call because they know they’re going to solve their issues. And so from just not having to manage all those different user IDs and passwords and, in security we always tell folks, don’t use the same password for everything. For example, if you’re logging into your banking site, you certainly don’t want that to be the same user ID and password that you’re using for Twitter or Facebook. But who can manage all of that? So making the users’ lives easier and simpler goes a long way. So also for security and compliance, I worked in organizations that the plethora of different compliance requirements that we had to adhere to was huge. We had HIPAA for patient records, PCI, the credit card standard, FDA Part 11, and we’ve had FTC red flag rules. I mean, it goes on and on and on. And without a formal IAM process in place, you’re really going to have a very hard time being successful with your compliance initiatives. So I think at the end of the day, I’d really like to stay away from the sky is falling because that really loses its momentum quickly. But I think right now, like I said, we’re at a good point where cyber and the talk of cyber is everywhere. You can’t open a website, whether it’s any of the traditional antivirus vendors or security organizations, you can’t search the Internet or receive a newsletter where there’s some mention of cyberattack or cyberwarfare or cyberdefense. And so to me, we can make a very strong case within IAM in attaching it to that very directly.

Sanjog Aul [00:43:53]:

Now let’s take a quick break, listeners. We’ll be right back. And let’s talk about the way you can get the people who are application administrators or the users or even the CFO who actually have a better outcome, intended outcome when they are able to get things done in an isolated manner or even be able to go for the pay-per-use. So when you look at a business as a business, they would like to save the buck wherever possible or make their life easier. Can you eat the cake and have it too by you getting what you want and so also does the CFO and the other communities? What solutions, what creative ways can we achieve it? Let’s explore it. When we come back, please stay tuned.

 

Sanjog Aul [00:46:12]:

Welcome back. So we could have challenges related to inertia from the users or application administrators who have been doing it a certain way, and they may even have different applications to manage as individuals. So why would they want to come to a unified approach and work for each other? And finally, the CFO who would like to see a pay-per-use approach and promote cloud services because that actually helps them with the bottom line. So on one hand, you are there, Connie, and anyone in your role trying to pitch IAM and what it’s, the cost savings. On the other hand, they see many other benefits coming from not going that route or posing hindrances. How do you handle

Connie Barrera [00:46:55]:

that? Absolutely. And that’s really a balancing act. But I think, the same as I was sharing earlier that the relationship between my boss, the CIO, and myself is very strong because we’re in, I think, perfect harmony from security initiatives, so on and so forth. We’re very fortunate where he reports to the CFO of the organization. And from that reporting line, we couldn’t have a better champion. And while that’s not always the case, I think the key point is this, when you’re working with an IAM vendor, there are certain cost factors that one is able to calculate internally. And I think it’s very important to look at your FTE count, put the solid numbers in there as to what it would mean to bring this new solution in place from a cost reduction perspective, not necessarily thinking that people are going to be laid off, and that’s not the spirit of this at all, but people being able to be repurposed and reassigned to more important things. And such from the man hours perspective, being able to articulate that in solid numbers. The other thing is that one of the things I didn’t mention before, which I think is critical, is finding the right third party partner. We are also very fortunate, I think, in large part is the size of our organization. We’re the third largest healthcare from a bed perspective in the country. And so many times partners are very hungry to fine tune their application, to make their solution better. And so they just want to use us, let’s say, as their test bed in order to say what features are required, what is lacking in the application. And they put their development teams to work and work on that. Right now from an identity perspective, we are testing some pretty innovative and interesting solutions that deal with palm vein technologies. So not only could there be an application on the employee side, but there’s certainly an application on the patient side. So as patients come in, they will hover their hand over a particular device that will perform a scan of their palm. This is huge because many times people have come into the ED and for many number of reasons, impersonated a relative so that they can leverage the insurance of their relative. And so, that’s a big problem because if their relative was treated and they had certain diagnoses, this person would be treated based on that knowledge and information. So it’s technology that you want to make sure it’s not always the case, but that you can find a partner that’s willing to work with you and is not going to give you that response, well, take it or leave it. That’s what we’re offering and that’s what everybody does. The other thing is show value. Show value to your CFO. If he or she is not on board initially, I’m sure they’re willing to try a small proof of concept with a particular area. And then showing the benefits of that having been well managed from a project management perspective, where you can show them evidence of how you’re saving from all the different aspects of the business unit. The other thing that I would say from a lessons learned perspective or things to avoid would be that some people have the mentality, well, if we build it, they will come. That’s not the case. That’s not the case at all. People are busy. And by and large, they’re focused on completing their tasks and getting the job done and going home to their families or whatever it is they would like to do. So communication is key, and we’ve really not talked about that this morning, but communication and training not only from the perspective of your technical folks that obviously need to be really well trained in the solution to know how to tweak it and know how to refine it over time in that cyclical IAM process, but most especially your users, that they really feel empowered. From the times that I walk around the organization and talk to people and mentor them, one of the main things is I see a spirit of wanting to do the right thing. And I see users sometimes just a little bit frustrated because they usually say, yeah, I want to do the right thing, but I just don’t know I don’t have a clue as to what to do. And really that’s our job. We shouldn’t expect people to understand technology necessarily. We need to make sure we provide that nurturing, fostering environment that really could help them and enable them to learn. IAM is not an initiative that’s a DIY project. Do it yourself is certainly not going to cut it here. It’s costly, but the benefits of that are huge. And I think taking it in small pieces, doing a proof of concept, showing value to your CFO will really bring them on board. When they see, for example, our trauma unit. Our trauma unit, we’re level one trauma, the only one in this region of the state. And those folks, to say they don’t have seconds to lose when they’re logging into a machine is an understatement. So having a good level of satisfaction in key business units is huge. I also read a stat that said through 2016 and of course that’s only going to extend with the complexity of things such as Internet of Things but through 2016 that any enterprises that lacked any type of formal identity and access management programs would be spending anywhere in the neighborhood of about 40% more. And their experiences, they would experience many times failures with that of organizations that actually had any type of program. We’re not even talking about mature programs, but organizations that were working day to day. And that’s what it takes. It really takes a team. At the organization I mentioned early on that I worked on years ago that we had about 300 line of business applications. In that organization we had 26 people on the security team to manage creating and disabling user accounts. That’s all they did. And they were busy all day. So I think it’s not a stretch. And I think if we sit down with all the relevant parties, this is not strictly IT in a bubble coming up with solutions. This is communication. This is working with the business unit. This is getting the application experts, the super users in a room and identifying the challenges. And then we’re able to better identify the rewards that we will reap by putting an appropriate program in place that far extends throughout different areas of the organization.

Sanjog Aul [00:54:30]:

On behalf of the show and our listeners, I’d really like to thank you, Connie, for your thoughts on how we can handle and rather tame this beast related to identity and access management.

Connie Barrera [00:54:43]:

It’s been my pleasure. It’s been a lot of fun and I am grateful for the time to discuss this very important topic with you and I hope your listeners have enjoyed our what to me was a wonderful conversation with you. Thank you so very much.

Sanjog Aul [00:54:58]:

Thank you so much again. And, listeners, hope you enjoyed Connie’s comments and insights that she shared about identity and access management. Please like us on Facebook, search for CIO Talk Radio, and be sure to follow us on Twitter. Thank you again for listening to CIO Talk Radio. This is Sanjog Aul, your talk show host. Till next week. Take care, and God bless.

Contributors

Connie Barrera

Connie Barrera, Chief Information Security Officer, Jackson Health System

Connie Barrera Chief Information Security Officer, Jackson Health System Connie Barrera is the Chief Information Security Officer at Jackson Health System with over 24 years of experience in the IT industry. Connie has spent considerab... More   View all posts
Add Comment
Click here to post a comment

Advertisement

TECHM - GENAI - MPU05 - 300x300
Connie Barrera