SlideShare ist ein Scribd-Unternehmen logo
1 von 14
IBM Security Identity Manager at ATP
Impact of On-boarding 1500 Users in a Highly Customized ISIM System
About ATP
The largest pension fund in Denmark managing public pensions
schemes for 4.7 mill. persons
Total assets worth of DKK 700+ billions (app USD 100+ billions)
Generally regarded as one of the best performing pension funds
world wide with a very high return rate and low cost.
ATP has recently been appointed to take responsibility for most
public welfare payments payouts (”Udbetaling Danmark”)
Yearly payouts app. DKK 180 billions (app. USD 27 billions).
Reducing the cost with app. 30%
Onboarding app. 1500 users from the municipalities
History/Background of the ATP ISIM Installation
ATP was converting the pension system from monolithic
(”Silos”) system to a SAP and WebSphere Portal based SOA
Architecture
ISIM (ITIM 4.5.1) was selected as the IdM Platform to automate
user lifecycle management in Q2 2005
Target goal for Security Administration was to keep same
number of headcounts despite additional systems
The system went live 1/1 2006 supporting Windows AD, 2 SAP
systems and TAM 5.1
HRFeed from SAP HR app. 1000 users
ATP ISIM Primary Focus
Automated Lifecycle Management
Fully automated on/off-boarding of employees/consultants via SAP HR
Identity Feed (HRFeed)
Manual Master for external users and technical accounts
All aspects of lifecycle and pasword management :
New Hire/
contract
registrered
Termination
Account
deletion
Graceperiod
Changes
Administration
of user
accounts
ATP ISIM Primary Focus (cont.)
Role Governance
All ATP Business Platform Roles 100% controlled
Roles modelled in top/down process to fit purpose
The role model is owned and maintained by the business owners
and implemented in ISIM by the Security Administration
Roles are recertified regularly
ATP Role Request Management
Intranet custom tool for requests (general system covering all
kinds of requests)
Requests for roles are routed to the Security Administration via
the Service Management tool (”Helpdesk”)
Request are managed by the Security Administration via the
ISIM console
The ATP ISIM Server Setup
ITDI
WAS
TIM application
TAM
Active
Directory
R/3
Provisioning
Provisioning
Provisioning
Person feed
HR extract
SAP XI
DB2
IDS
Adapter
for TAM
HR feed
Adapter
for SAP
Adapter for
Active
Directory
WEMB
(MQ)
R/3
Multiple Systems
Lotus
Domino
Adapter
for
Kerne
Provisioning
Adapter
for Notes
Provisioning
NAFS
Kerne
Adapter
for
KSPCICS
KSP
CICS
Provisioning
internet
ATP ISIM – Systems Managed
In Production 16 system managed
In Pilot 17 system managed
Production Pilot
Windows AD 1 (Windows AD 1 (non-functional system)
SAP NW (ABP) 9 SAP NW (ABP) 9
Custom "Kerne" (ABP) 3 Custom "Kerne" (ABP) 3
SAP XI 2
Lotus Notes 1 Lotus Notes 1 (non-functional system)
KSP CICS UDK 1
ITAM (ABP) 1 ITAM (ABP) 1
ITIM 3 ITIM 3
Important Customizations
Time Based Roles (managing roles with a start- and end-date)
AD Hybrid Management Model
Groups are managed ”hard” (RBAC model) if placed in specific AD
OUs
Groups outside these OUs are non-managed (can be managed
using Accesses)
Auto Create of AD groups (organization based groups)
Workflow for Management of Unauthorized Accounts
Accounts created outside ISIM are detected on reconciliation
Workflow locks account upon detection and triggers approval flow
Provisioning Policy report in CSV format (weekly via mail)
Migration/Synch tool to manage business objects
(Roles/Policies/Workflows etc.) between environments
(Development/Pilot/Prod)
ATP ISIM – History and Future
Original platform ITIM 32 bit version 4.5.1 2005/1/1
Migrated to ITIM 32 bit 4.6 2007/Q2
Migrated to ITIM 5.1 64 bit 2011/Q4
Upgrade to ISIM 6.0 planned for 2013
The UDK project
Agreement between the goverment and municipalities in
06/2010 to :
Centralize welfare payments into a new organization ”Udbetaling
Danmark” (UDK)
Uniform Processing
Saving target DKK 300 million/year
3 Waves starting 10/2012 covering app. 1500 users
ATP deliver Administrative systems support – e.g. IdM
3 new Systems (2 SAP NW + RACF/CICS via WS)
Public Certificate and other govermental systems
Role Governance based on organization and job role (based on
ATPs role governance model) – app. 50 roles
ATP ISIM System – Important Numbers
Users :
14638 Accounts
Roles :
621 Static and 86 Dynamic Roles (plus 50 UDK roles outside ISIM)
20938 Role assignements (403 Roles)
Policies
15 Identity Policies
2 Password Policies
12 Adoption Policies
906 Provisioning Policies
Employees 2273
Consultants 155
External 521
Technical 101
ATP ISIM System – Process Numbers
Process 2012/07 2012/08 2012/09 2012/10 2012/11 2012/12 2013/01 2013/02 2013/03 2013/04
Account Add 263 722 1460 1244 971 616 2230 2060 2478 450
Account Pwd
Chg
126 125 108 160 210 72 130 202 133 145
Account
Delete
385 183 267 274 374 245 474 370 605 460
Account
Modify
25089 26566 24712 23825 19281 19230 19230 11990 11215 11293
Account
Restore
81 141 358 792 297 460 204 1368 1953 176
Account
Suspend
345 256 191 269 362 361 549 315 574 289
Check
Policies
34989 38548 39333 38285 44803 45861 48413 60604 72459 68954
Person Add 44 148 304 141 2429 92 1309 4344 911 122
Person
Delete
67 36 45 42 63 47 68 63 116 68
Person
Modify
682 1859 3074 3338 2006 1729 2946 6689 2451 1084
Reconciliation 517 512 517 527 539 587 640 579 632 610
14
Questions

Weitere ähnliche Inhalte

Ähnlich wie IBM Security Identity Manager Onboards 1500 Users

Bhawani prasad data integration-ppt
Bhawani prasad data integration-pptBhawani prasad data integration-ppt
Bhawani prasad data integration-pptBhawani N Prasad
 
Data integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcuttaData integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcuttaBhawani N Prasad
 
Aspans Tech Pitch Book
Aspans Tech Pitch BookAspans Tech Pitch Book
Aspans Tech Pitch Bookkadyrsizov
 
Topic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdfTopic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdfluxasuhi
 
Business breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERPBusiness breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERPERPScan
 
Computerised accounting plus_one_chap_12_15_2
Computerised  accounting plus_one_chap_12_15_2Computerised  accounting plus_one_chap_12_15_2
Computerised accounting plus_one_chap_12_15_2Prasad Melattur
 
November 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDANovember 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDAJBug Italy
 
Solution Manager Deployment
Solution Manager DeploymentSolution Manager Deployment
Solution Manager DeploymentTony de Thomasis
 
IBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best PracticesIBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best PracticesRoland Merkt
 
WAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESAWAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESAillustrosystems
 
SAP Influence Council 2009
SAP Influence Council 2009SAP Influence Council 2009
SAP Influence Council 2009Tony de Thomasis
 
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017Jose Gascon
 
Ch2 v70 config_overview_en
Ch2 v70 config_overview_enCh2 v70 config_overview_en
Ch2 v70 config_overview_enconfidencial
 
Standard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM softwareStandard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM softwareAxios Systems
 

Ähnlich wie IBM Security Identity Manager Onboards 1500 Users (20)

Bhawani prasad data integration-ppt
Bhawani prasad data integration-pptBhawani prasad data integration-ppt
Bhawani prasad data integration-ppt
 
Data integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcuttaData integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcutta
 
OG and Monitors
OG and MonitorsOG and Monitors
OG and Monitors
 
ABT / DSM System
ABT / DSM System ABT / DSM System
ABT / DSM System
 
Aspans Tech Pitch Book
Aspans Tech Pitch BookAspans Tech Pitch Book
Aspans Tech Pitch Book
 
Tally9erp
Tally9erpTally9erp
Tally9erp
 
Mis ppt level 2
Mis ppt level 2Mis ppt level 2
Mis ppt level 2
 
Mis ppt level 2
Mis ppt level 2Mis ppt level 2
Mis ppt level 2
 
Topic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdfTopic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdf
 
Business breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERPBusiness breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERP
 
Computerised accounting plus_one_chap_12_15_2
Computerised  accounting plus_one_chap_12_15_2Computerised  accounting plus_one_chap_12_15_2
Computerised accounting plus_one_chap_12_15_2
 
November 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDANovember 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDA
 
Solution Manager Deployment
Solution Manager DeploymentSolution Manager Deployment
Solution Manager Deployment
 
IBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best PracticesIBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best Practices
 
WAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESAWAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESA
 
SAP Influence Council 2009
SAP Influence Council 2009SAP Influence Council 2009
SAP Influence Council 2009
 
Network Operation Center
Network Operation CenterNetwork Operation Center
Network Operation Center
 
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
 
Ch2 v70 config_overview_en
Ch2 v70 config_overview_enCh2 v70 config_overview_en
Ch2 v70 config_overview_en
 
Standard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM softwareStandard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM software
 

Mehr von IBM Danmark

DevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinleyDevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinleyIBM Danmark
 
Velkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia RønhøjVelkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia RønhøjIBM Danmark
 
Smarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-AndersenSmarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-AndersenIBM Danmark
 
Mobile, Philip Nyborg
Mobile, Philip NyborgMobile, Philip Nyborg
Mobile, Philip NyborgIBM Danmark
 
IT innovation, Kim Escherich
IT innovation, Kim EscherichIT innovation, Kim Escherich
IT innovation, Kim EscherichIBM Danmark
 
Echo.IT, Stefan K. Madsen
Echo.IT, Stefan K. MadsenEcho.IT, Stefan K. Madsen
Echo.IT, Stefan K. MadsenIBM Danmark
 
Big Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonBig Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonIBM Danmark
 
Social Business, Alice Bayer
Social Business, Alice BayerSocial Business, Alice Bayer
Social Business, Alice BayerIBM Danmark
 
Numascale Product IBM
Numascale Product IBMNumascale Product IBM
Numascale Product IBMIBM Danmark
 
Intel HPC Update
Intel HPC UpdateIntel HPC Update
Intel HPC UpdateIBM Danmark
 
IBM general parallel file system - introduction
IBM general parallel file system - introductionIBM general parallel file system - introduction
IBM general parallel file system - introductionIBM Danmark
 
NeXtScale HPC seminar
NeXtScale HPC seminarNeXtScale HPC seminar
NeXtScale HPC seminarIBM Danmark
 
Future of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian NielsenFuture of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian NielsenIBM Danmark
 
Future of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve SibleyFuture of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve SibleyIBM Danmark
 
Future of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren RavnFuture of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren RavnIBM Danmark
 
Future of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim MortensenFuture of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim MortensenIBM Danmark
 
Future of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik RexFuture of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik RexIBM Danmark
 
Future of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim EscherichFuture of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim EscherichIBM Danmark
 
Future of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-JensenFuture of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-JensenIBM Danmark
 

Mehr von IBM Danmark (20)

DevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinleyDevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinley
 
Velkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia RønhøjVelkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia Rønhøj
 
Smarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-AndersenSmarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
 
Mobile, Philip Nyborg
Mobile, Philip NyborgMobile, Philip Nyborg
Mobile, Philip Nyborg
 
IT innovation, Kim Escherich
IT innovation, Kim EscherichIT innovation, Kim Escherich
IT innovation, Kim Escherich
 
Echo.IT, Stefan K. Madsen
Echo.IT, Stefan K. MadsenEcho.IT, Stefan K. Madsen
Echo.IT, Stefan K. Madsen
 
Big Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonBig Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter Jönsson
 
Social Business, Alice Bayer
Social Business, Alice BayerSocial Business, Alice Bayer
Social Business, Alice Bayer
 
Numascale Product IBM
Numascale Product IBMNumascale Product IBM
Numascale Product IBM
 
Mellanox IBM
Mellanox IBMMellanox IBM
Mellanox IBM
 
Intel HPC Update
Intel HPC UpdateIntel HPC Update
Intel HPC Update
 
IBM general parallel file system - introduction
IBM general parallel file system - introductionIBM general parallel file system - introduction
IBM general parallel file system - introduction
 
NeXtScale HPC seminar
NeXtScale HPC seminarNeXtScale HPC seminar
NeXtScale HPC seminar
 
Future of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian NielsenFuture of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian Nielsen
 
Future of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve SibleyFuture of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve Sibley
 
Future of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren RavnFuture of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren Ravn
 
Future of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim MortensenFuture of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim Mortensen
 
Future of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik RexFuture of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik Rex
 
Future of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim EscherichFuture of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim Escherich
 
Future of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-JensenFuture of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-Jensen
 

Kürzlich hochgeladen

Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhisoniya singh
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking MenDelhi Call girls
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Neo4j
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Alan Dix
 
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024BookNet Canada
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Mattias Andersson
 
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024BookNet Canada
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptxLBM Solutions
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksSoftradix Technologies
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDGMarianaLemus7
 

Kürzlich hochgeladen (20)

Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | DelhiFULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
FULL ENJOY 🔝 8264348440 🔝 Call Girls in Diplomatic Enclave | Delhi
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men08448380779 Call Girls In Friends Colony Women Seeking Men
08448380779 Call Girls In Friends Colony Women Seeking Men
 
Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024Build your next Gen AI Breakthrough - April 2024
Build your next Gen AI Breakthrough - April 2024
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...Swan(sea) Song – personal research during my six years at Swansea ... and bey...
Swan(sea) Song – personal research during my six years at Swansea ... and bey...
 
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
 
Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?Are Multi-Cloud and Serverless Good or Bad?
Are Multi-Cloud and Serverless Good or Bad?
 
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
New from BookNet Canada for 2024: BNC BiblioShare - Tech Forum 2024
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Key Features Of Token Development (1).pptx
Key  Features Of Token  Development (1).pptxKey  Features Of Token  Development (1).pptx
Key Features Of Token Development (1).pptx
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Benefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other FrameworksBenefits Of Flutter Compared To Other Frameworks
Benefits Of Flutter Compared To Other Frameworks
 
APIForce Zurich 5 April Automation LPDG
APIForce Zurich 5 April  Automation LPDGAPIForce Zurich 5 April  Automation LPDG
APIForce Zurich 5 April Automation LPDG
 

IBM Security Identity Manager Onboards 1500 Users

  • 1. IBM Security Identity Manager at ATP Impact of On-boarding 1500 Users in a Highly Customized ISIM System
  • 2. About ATP The largest pension fund in Denmark managing public pensions schemes for 4.7 mill. persons Total assets worth of DKK 700+ billions (app USD 100+ billions) Generally regarded as one of the best performing pension funds world wide with a very high return rate and low cost. ATP has recently been appointed to take responsibility for most public welfare payments payouts (”Udbetaling Danmark”) Yearly payouts app. DKK 180 billions (app. USD 27 billions). Reducing the cost with app. 30% Onboarding app. 1500 users from the municipalities
  • 3. History/Background of the ATP ISIM Installation ATP was converting the pension system from monolithic (”Silos”) system to a SAP and WebSphere Portal based SOA Architecture ISIM (ITIM 4.5.1) was selected as the IdM Platform to automate user lifecycle management in Q2 2005 Target goal for Security Administration was to keep same number of headcounts despite additional systems The system went live 1/1 2006 supporting Windows AD, 2 SAP systems and TAM 5.1 HRFeed from SAP HR app. 1000 users
  • 4. ATP ISIM Primary Focus Automated Lifecycle Management Fully automated on/off-boarding of employees/consultants via SAP HR Identity Feed (HRFeed) Manual Master for external users and technical accounts All aspects of lifecycle and pasword management : New Hire/ contract registrered Termination Account deletion Graceperiod Changes Administration of user accounts
  • 5. ATP ISIM Primary Focus (cont.) Role Governance All ATP Business Platform Roles 100% controlled Roles modelled in top/down process to fit purpose The role model is owned and maintained by the business owners and implemented in ISIM by the Security Administration Roles are recertified regularly
  • 6. ATP Role Request Management Intranet custom tool for requests (general system covering all kinds of requests) Requests for roles are routed to the Security Administration via the Service Management tool (”Helpdesk”) Request are managed by the Security Administration via the ISIM console
  • 7. The ATP ISIM Server Setup ITDI WAS TIM application TAM Active Directory R/3 Provisioning Provisioning Provisioning Person feed HR extract SAP XI DB2 IDS Adapter for TAM HR feed Adapter for SAP Adapter for Active Directory WEMB (MQ) R/3 Multiple Systems Lotus Domino Adapter for Kerne Provisioning Adapter for Notes Provisioning NAFS Kerne Adapter for KSPCICS KSP CICS Provisioning internet
  • 8. ATP ISIM – Systems Managed In Production 16 system managed In Pilot 17 system managed Production Pilot Windows AD 1 (Windows AD 1 (non-functional system) SAP NW (ABP) 9 SAP NW (ABP) 9 Custom "Kerne" (ABP) 3 Custom "Kerne" (ABP) 3 SAP XI 2 Lotus Notes 1 Lotus Notes 1 (non-functional system) KSP CICS UDK 1 ITAM (ABP) 1 ITAM (ABP) 1 ITIM 3 ITIM 3
  • 9. Important Customizations Time Based Roles (managing roles with a start- and end-date) AD Hybrid Management Model Groups are managed ”hard” (RBAC model) if placed in specific AD OUs Groups outside these OUs are non-managed (can be managed using Accesses) Auto Create of AD groups (organization based groups) Workflow for Management of Unauthorized Accounts Accounts created outside ISIM are detected on reconciliation Workflow locks account upon detection and triggers approval flow Provisioning Policy report in CSV format (weekly via mail) Migration/Synch tool to manage business objects (Roles/Policies/Workflows etc.) between environments (Development/Pilot/Prod)
  • 10. ATP ISIM – History and Future Original platform ITIM 32 bit version 4.5.1 2005/1/1 Migrated to ITIM 32 bit 4.6 2007/Q2 Migrated to ITIM 5.1 64 bit 2011/Q4 Upgrade to ISIM 6.0 planned for 2013
  • 11. The UDK project Agreement between the goverment and municipalities in 06/2010 to : Centralize welfare payments into a new organization ”Udbetaling Danmark” (UDK) Uniform Processing Saving target DKK 300 million/year 3 Waves starting 10/2012 covering app. 1500 users ATP deliver Administrative systems support – e.g. IdM 3 new Systems (2 SAP NW + RACF/CICS via WS) Public Certificate and other govermental systems Role Governance based on organization and job role (based on ATPs role governance model) – app. 50 roles
  • 12. ATP ISIM System – Important Numbers Users : 14638 Accounts Roles : 621 Static and 86 Dynamic Roles (plus 50 UDK roles outside ISIM) 20938 Role assignements (403 Roles) Policies 15 Identity Policies 2 Password Policies 12 Adoption Policies 906 Provisioning Policies Employees 2273 Consultants 155 External 521 Technical 101
  • 13. ATP ISIM System – Process Numbers Process 2012/07 2012/08 2012/09 2012/10 2012/11 2012/12 2013/01 2013/02 2013/03 2013/04 Account Add 263 722 1460 1244 971 616 2230 2060 2478 450 Account Pwd Chg 126 125 108 160 210 72 130 202 133 145 Account Delete 385 183 267 274 374 245 474 370 605 460 Account Modify 25089 26566 24712 23825 19281 19230 19230 11990 11215 11293 Account Restore 81 141 358 792 297 460 204 1368 1953 176 Account Suspend 345 256 191 269 362 361 549 315 574 289 Check Policies 34989 38548 39333 38285 44803 45861 48413 60604 72459 68954 Person Add 44 148 304 141 2429 92 1309 4344 911 122 Person Delete 67 36 45 42 63 47 68 63 116 68 Person Modify 682 1859 3074 3338 2006 1729 2946 6689 2451 1084 Reconciliation 517 512 517 527 539 587 640 579 632 610