Leo Grohmann, Senior Solutions Architect at Omada, discusses the challenges surrounding selection bias, especially when survivorship bias is added to the mix.
Selection biases in IGA
Survivorship bias is a type of selection bias that occurs when people only look at information or items that have passed a selection process, ignoring those that haven’t due to a lack of visibility. This can be a big obstacle to identity access management teams and it鈥檚 particularly widespread in access certificates and surveys. That can lead to decision-making that is based on insufficient datasets.
An example of how this bias can happen is a situation where not all applications are integrated with the IGA solution. In this case, there鈥檚 an incomplete picture of what needs to be or is being recertified. You might think you have good control over permissions in the IT landscape, but the reality is that you鈥檙e only seeing a small part of that entire landscape.
Another problem that can happen is that when permissions are re-certified, managers might only recertify them based on what access other people have. In other words, if some access has been granted to a large number of people, there鈥檚 a risk that managers will just re-certify that access for everyone without really thinking it through.
The problem with inappropriate recertifications
听
Organizations can use access certification campaigns to audit entitlements and legally confirm that identities have adequate access privileges. These campaigns are intended to remove access if it鈥檚 no longer necessary 鈥 or permanently approve access that was previously granted ad hoc. Certification campaigns are a useful method for making sure least privilege is in place.
Why does this matter? Inappropriate recertification of access or privileges can lead to many problems 鈥 such as data leaks or even data breaches, which can happen accidentally or with malicious intent. Imagine that someone has access to specific IT systems that they shouldn鈥檛 have access to. If, for some reason, the employee decides to cause damage to the company, they鈥檇 be able to do that because of their access.
Inappropriate recertification of access also makes things like attacking the company from the outside easier. The more access that鈥檚 unknown to the organization, the bigger the risk that it exposes itself to both insider and outsider threats.
More from News
- Meta Promised Unmatched Privacy For Muse 鈥 So How Did Researchers Crack It So Quickly?
- Digital Avatars Are Bringing Deceased Artists Back To The Stage 鈥 Where Do We Draw The Line?
- Can Europe Solve Its Critical Minerals Problem Fast Enough To Support Its Tech Ambitions?
- Google Has Agreed To A 拢260 Million Settlement: Who’s Eligible For Compensation?
- China Wants To Build A Third Global AI Bloc 鈥 What Does That Mean For Everyone?
- Advanced AI Society Joins the Linux Foundation And Launches Open Verification Ecosystem
- What Could Snap鈥檚 Partnerships With Big Tech Mean For The AR Industry?
- Why Did A Four-Year Bomb Threat Campaign Involving 500,000 Gmail Accounts Go Unchecked?
Combatting survey fatigue
听
Avoiding selection bias and ensuring that recertification is done right also requires that you鈥檙e mitigating the risk of survey fatigue. Requiring employees to go through, say, 100 questions to recertify their access isn鈥檛 realistic. They鈥檙e either not going to do it or they鈥檙e going to speed through some questions for the sake of time and say, 鈥淪ure, this information looks fine.鈥 But that leads to risks about whether the right things are being recertified. One way to combat this is to do more frequent but smaller recertifications rather than one giant yearly one, for instance.
Another option is to establish a 鈥渞ole model鈥 in which certain accesses are bundled by job role. That way, it is sufficient to recertify the business roles that are assigned to identities instead of recertifying all contained permissions for everyone. Using a consistent role model with a business-friendly naming standard ensures that managers will spend less time on recertifications while making better and more thorough decisions.
Toward better recertification
Recertification shouldn鈥檛 be treated as just something to give to the auditors to fulfill certain regulations. It should be viewed as something crucial to the business, as well as a key part of security efforts. It should be driven by the business (not IT) and treated as something that is ultimately beneficial to the organization as a whole. Incorporate the best practices discussed above to beat survivorship bias and survey fatigue while streamlining the recertification process.
