How does identity management change within ESA?
It's no longer sufficient to secure the first service encountered by users in a business process (i.e., the interface); in fact, it never has been. Identity management-based security must extend across every system touched by the process about to be initiated because what's ultimately being exposed is not just a single service, but the entire business process. What the user orders at the onset of the process must be verified and delivered at the end with the guarantees that: a) that is indeed what she ordered, and b) she is indeed entitled to request it. If the request were to pass through any unsecured service along its route, neither premise could be proven to have remained true.
From a service infrastructure standpoint, this responsibility will likely fall to the security operations layer in each. But it will also become necessary to integrate identity management processes and user profiles into a single repository. This repository will distribute that information to all the systems, providing them with the information required to assess the validity of a requirement, or it may be accessible from anywhere within the landscape, called by the system hit by the user's request, and provide the information in real time—essentially becoming an enterprise service itself. In the early stages of a company's ESA adoption, this might take the form of an LDAP integration effort. But as the environment continues to grow and evolve, the next step ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access