SlideShare a Scribd company logo
IBM Security Identity Manager at ATP
Impact of On-boarding 1500 Users in a Highly Customized ISIM System
About ATP
The largest pension fund in Denmark managing public pensions
schemes for 4.7 mill. persons
Total assets worth of DKK 700+ billions (app USD 100+ billions)
Generally regarded as one of the best performing pension funds
world wide with a very high return rate and low cost.
ATP has recently been appointed to take responsibility for most
public welfare payments payouts (”Udbetaling Danmark”)
Yearly payouts app. DKK 180 billions (app. USD 27 billions).
Reducing the cost with app. 30%
Onboarding app. 1500 users from the municipalities
History/Background of the ATP ISIM Installation
ATP was converting the pension system from monolithic
(”Silos”) system to a SAP and WebSphere Portal based SOA
Architecture
ISIM (ITIM 4.5.1) was selected as the IdM Platform to automate
user lifecycle management in Q2 2005
Target goal for Security Administration was to keep same
number of headcounts despite additional systems
The system went live 1/1 2006 supporting Windows AD, 2 SAP
systems and TAM 5.1
HRFeed from SAP HR app. 1000 users
ATP ISIM Primary Focus
Automated Lifecycle Management
Fully automated on/off-boarding of employees/consultants via SAP HR
Identity Feed (HRFeed)
Manual Master for external users and technical accounts
All aspects of lifecycle and pasword management :
New Hire/
contract
registrered
Termination
Account
deletion
Graceperiod
Changes
Administration
of user
accounts
ATP ISIM Primary Focus (cont.)
Role Governance
All ATP Business Platform Roles 100% controlled
Roles modelled in top/down process to fit purpose
The role model is owned and maintained by the business owners
and implemented in ISIM by the Security Administration
Roles are recertified regularly
ATP Role Request Management
Intranet custom tool for requests (general system covering all
kinds of requests)
Requests for roles are routed to the Security Administration via
the Service Management tool (”Helpdesk”)
Request are managed by the Security Administration via the
ISIM console
The ATP ISIM Server Setup
ITDI
WAS
TIM application
TAM
Active
Directory
R/3
Provisioning
Provisioning
Provisioning
Person feed
HR extract
SAP XI
DB2
IDS
Adapter
for TAM
HR feed
Adapter
for SAP
Adapter for
Active
Directory
WEMB
(MQ)
R/3
Multiple Systems
Lotus
Domino
Adapter
for
Kerne
Provisioning
Adapter
for Notes
Provisioning
NAFS
Kerne
Adapter
for
KSPCICS
KSP
CICS
Provisioning
internet
ATP ISIM – Systems Managed
In Production 16 system managed
In Pilot 17 system managed
Production Pilot
Windows AD 1 (Windows AD 1 (non-functional system)
SAP NW (ABP) 9 SAP NW (ABP) 9
Custom "Kerne" (ABP) 3 Custom "Kerne" (ABP) 3
SAP XI 2
Lotus Notes 1 Lotus Notes 1 (non-functional system)
KSP CICS UDK 1
ITAM (ABP) 1 ITAM (ABP) 1
ITIM 3 ITIM 3
Important Customizations
Time Based Roles (managing roles with a start- and end-date)
AD Hybrid Management Model
Groups are managed ”hard” (RBAC model) if placed in specific AD
OUs
Groups outside these OUs are non-managed (can be managed
using Accesses)
Auto Create of AD groups (organization based groups)
Workflow for Management of Unauthorized Accounts
Accounts created outside ISIM are detected on reconciliation
Workflow locks account upon detection and triggers approval flow
Provisioning Policy report in CSV format (weekly via mail)
Migration/Synch tool to manage business objects
(Roles/Policies/Workflows etc.) between environments
(Development/Pilot/Prod)
ATP ISIM – History and Future
Original platform ITIM 32 bit version 4.5.1 2005/1/1
Migrated to ITIM 32 bit 4.6 2007/Q2
Migrated to ITIM 5.1 64 bit 2011/Q4
Upgrade to ISIM 6.0 planned for 2013
The UDK project
Agreement between the goverment and municipalities in
06/2010 to :
Centralize welfare payments into a new organization ”Udbetaling
Danmark” (UDK)
Uniform Processing
Saving target DKK 300 million/year
3 Waves starting 10/2012 covering app. 1500 users
ATP deliver Administrative systems support – e.g. IdM
3 new Systems (2 SAP NW + RACF/CICS via WS)
Public Certificate and other govermental systems
Role Governance based on organization and job role (based on
ATPs role governance model) – app. 50 roles
ATP ISIM System – Important Numbers
Users :
14638 Accounts
Roles :
621 Static and 86 Dynamic Roles (plus 50 UDK roles outside ISIM)
20938 Role assignements (403 Roles)
Policies
15 Identity Policies
2 Password Policies
12 Adoption Policies
906 Provisioning Policies
Employees 2273
Consultants 155
External 521
Technical 101
ATP ISIM System – Process Numbers
Process 2012/07 2012/08 2012/09 2012/10 2012/11 2012/12 2013/01 2013/02 2013/03 2013/04
Account Add 263 722 1460 1244 971 616 2230 2060 2478 450
Account Pwd
Chg
126 125 108 160 210 72 130 202 133 145
Account
Delete
385 183 267 274 374 245 474 370 605 460
Account
Modify
25089 26566 24712 23825 19281 19230 19230 11990 11215 11293
Account
Restore
81 141 358 792 297 460 204 1368 1953 176
Account
Suspend
345 256 191 269 362 361 549 315 574 289
Check
Policies
34989 38548 39333 38285 44803 45861 48413 60604 72459 68954
Person Add 44 148 304 141 2429 92 1309 4344 911 122
Person
Delete
67 36 45 42 63 47 68 63 116 68
Person
Modify
682 1859 3074 3338 2006 1729 2946 6689 2451 1084
Reconciliation 517 512 517 527 539 587 640 579 632 610
14
Questions

More Related Content

Similar to ATP

Bhawani prasad data integration-ppt
Bhawani prasad data integration-pptBhawani prasad data integration-ppt
Bhawani prasad data integration-ppt
Bhawani N Prasad
 
Data integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcuttaData integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcutta
Bhawani N Prasad
 
ABT / DSM System
ABT / DSM System ABT / DSM System
ABT / DSM System
Kondapi V Siva Rama Brahmam
 
Aspans Tech Pitch Book
Aspans Tech Pitch BookAspans Tech Pitch Book
Aspans Tech Pitch Book
kadyrsizov
 
Topic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdfTopic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdf
luxasuhi
 
Business breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERPBusiness breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERPERPScan
 
Computerised accounting plus_one_chap_12_15_2
Computerised  accounting plus_one_chap_12_15_2Computerised  accounting plus_one_chap_12_15_2
Computerised accounting plus_one_chap_12_15_2
Prasad Melattur
 
November 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDANovember 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDA
JBug Italy
 
Solution Manager Deployment
Solution Manager DeploymentSolution Manager Deployment
Solution Manager Deployment
Tony de Thomasis
 
IBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best PracticesIBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best Practices
Roland Merkt
 
WAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESAWAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESAillustrosystems
 
SAP Influence Council 2009
SAP Influence Council 2009SAP Influence Council 2009
SAP Influence Council 2009Tony de Thomasis
 
Network Operation Center
Network Operation CenterNetwork Operation Center
Network Operation Center
Skillmine Technology Consulting
 
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
Jose Gascon
 
Ch2 v70 config_overview_en
Ch2 v70 config_overview_enCh2 v70 config_overview_en
Ch2 v70 config_overview_en
confidencial
 
Standard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM softwareStandard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM softwareAxios Systems
 

Similar to ATP (20)

Bhawani prasad data integration-ppt
Bhawani prasad data integration-pptBhawani prasad data integration-ppt
Bhawani prasad data integration-ppt
 
Data integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcuttaData integration ppt-bhawani nandan prasad - iim calcutta
Data integration ppt-bhawani nandan prasad - iim calcutta
 
OG and Monitors
OG and MonitorsOG and Monitors
OG and Monitors
 
ABT / DSM System
ABT / DSM System ABT / DSM System
ABT / DSM System
 
Aspans Tech Pitch Book
Aspans Tech Pitch BookAspans Tech Pitch Book
Aspans Tech Pitch Book
 
Tally9erp
Tally9erpTally9erp
Tally9erp
 
Mis ppt level 2
Mis ppt level 2Mis ppt level 2
Mis ppt level 2
 
Mis ppt level 2
Mis ppt level 2Mis ppt level 2
Mis ppt level 2
 
Topic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdfTopic_1___Part_1_Introduction.pptx.pdf
Topic_1___Part_1_Introduction.pptx.pdf
 
Business breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERPBusiness breakdown vulnerabilities in ERP via ICS and ICS via ERP
Business breakdown vulnerabilities in ERP via ICS and ICS via ERP
 
Computerised accounting plus_one_chap_12_15_2
Computerised  accounting plus_one_chap_12_15_2Computerised  accounting plus_one_chap_12_15_2
Computerised accounting plus_one_chap_12_15_2
 
November 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDANovember 2009 - Walking on thin ice… from SOA to EDA
November 2009 - Walking on thin ice… from SOA to EDA
 
Solution Manager Deployment
Solution Manager DeploymentSolution Manager Deployment
Solution Manager Deployment
 
IBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best PracticesIBM ECM System Monitor - Cenit Best Practices
IBM ECM System Monitor - Cenit Best Practices
 
WAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESAWAVV 2009 - Migration to CICS TS for VSE/ESA
WAVV 2009 - Migration to CICS TS for VSE/ESA
 
SAP Influence Council 2009
SAP Influence Council 2009SAP Influence Council 2009
SAP Influence Council 2009
 
Network Operation Center
Network Operation CenterNetwork Operation Center
Network Operation Center
 
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
MIPM PCo to Kafka Faurecia SAP co-innovation at Hannover Messe 2017
 
Ch2 v70 config_overview_en
Ch2 v70 config_overview_enCh2 v70 config_overview_en
Ch2 v70 config_overview_en
 
Standard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM softwareStandard Bank - Implementation of assyst ITSM software
Standard Bank - Implementation of assyst ITSM software
 

More from IBM Danmark

DevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinleyDevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinleyIBM Danmark
 
Velkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia RønhøjVelkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia RønhøjIBM Danmark
 
Smarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-AndersenSmarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-AndersenIBM Danmark
 
Mobile, Philip Nyborg
Mobile, Philip NyborgMobile, Philip Nyborg
Mobile, Philip NyborgIBM Danmark
 
IT innovation, Kim Escherich
IT innovation, Kim EscherichIT innovation, Kim Escherich
IT innovation, Kim EscherichIBM Danmark
 
Echo.IT, Stefan K. Madsen
Echo.IT, Stefan K. MadsenEcho.IT, Stefan K. Madsen
Echo.IT, Stefan K. MadsenIBM Danmark
 
Big Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonBig Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonIBM Danmark
 
Social Business, Alice Bayer
Social Business, Alice BayerSocial Business, Alice Bayer
Social Business, Alice BayerIBM Danmark
 
Numascale Product IBM
Numascale Product IBMNumascale Product IBM
Numascale Product IBM
IBM Danmark
 
Mellanox IBM
Mellanox IBMMellanox IBM
Mellanox IBM
IBM Danmark
 
Intel HPC Update
Intel HPC UpdateIntel HPC Update
Intel HPC Update
IBM Danmark
 
IBM general parallel file system - introduction
IBM general parallel file system - introductionIBM general parallel file system - introduction
IBM general parallel file system - introduction
IBM Danmark
 
NeXtScale HPC seminar
NeXtScale HPC seminarNeXtScale HPC seminar
NeXtScale HPC seminar
IBM Danmark
 
Future of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian NielsenFuture of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian Nielsen
IBM Danmark
 
Future of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve SibleyFuture of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve Sibley
IBM Danmark
 
Future of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren RavnFuture of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren Ravn
IBM Danmark
 
Future of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim MortensenFuture of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim Mortensen
IBM Danmark
 
Future of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik RexFuture of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik Rex
IBM Danmark
 
Future of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim EscherichFuture of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim Escherich
IBM Danmark
 
Future of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-JensenFuture of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-Jensen
IBM Danmark
 

More from IBM Danmark (20)

DevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinleyDevOps, Development and Operations, Tina McGinley
DevOps, Development and Operations, Tina McGinley
 
Velkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia RønhøjVelkomst, Universitetssporet 2013, Pia Rønhøj
Velkomst, Universitetssporet 2013, Pia Rønhøj
 
Smarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-AndersenSmarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
Smarter Commerce, Salg og Marketing, Thomas Steglich-Andersen
 
Mobile, Philip Nyborg
Mobile, Philip NyborgMobile, Philip Nyborg
Mobile, Philip Nyborg
 
IT innovation, Kim Escherich
IT innovation, Kim EscherichIT innovation, Kim Escherich
IT innovation, Kim Escherich
 
Echo.IT, Stefan K. Madsen
Echo.IT, Stefan K. MadsenEcho.IT, Stefan K. Madsen
Echo.IT, Stefan K. Madsen
 
Big Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter JönssonBig Data & Analytics, Peter Jönsson
Big Data & Analytics, Peter Jönsson
 
Social Business, Alice Bayer
Social Business, Alice BayerSocial Business, Alice Bayer
Social Business, Alice Bayer
 
Numascale Product IBM
Numascale Product IBMNumascale Product IBM
Numascale Product IBM
 
Mellanox IBM
Mellanox IBMMellanox IBM
Mellanox IBM
 
Intel HPC Update
Intel HPC UpdateIntel HPC Update
Intel HPC Update
 
IBM general parallel file system - introduction
IBM general parallel file system - introductionIBM general parallel file system - introduction
IBM general parallel file system - introduction
 
NeXtScale HPC seminar
NeXtScale HPC seminarNeXtScale HPC seminar
NeXtScale HPC seminar
 
Future of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian NielsenFuture of Power: PowerLinux - Jan Kristian Nielsen
Future of Power: PowerLinux - Jan Kristian Nielsen
 
Future of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve SibleyFuture of Power: Power Strategy and Offerings for Denmark - Steve Sibley
Future of Power: Power Strategy and Offerings for Denmark - Steve Sibley
 
Future of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren RavnFuture of Power: Big Data - Søren Ravn
Future of Power: Big Data - Søren Ravn
 
Future of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim MortensenFuture of Power: IBM PureFlex - Kim Mortensen
Future of Power: IBM PureFlex - Kim Mortensen
 
Future of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik RexFuture of Power: IBM Trends & Directions - Erik Rex
Future of Power: IBM Trends & Directions - Erik Rex
 
Future of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim EscherichFuture of Power: Håndtering af nye teknologier - Kim Escherich
Future of Power: Håndtering af nye teknologier - Kim Escherich
 
Future of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-JensenFuture of Power - Lars Mikkelgaard-Jensen
Future of Power - Lars Mikkelgaard-Jensen
 

Recently uploaded

GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
Neo4j
 
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Albert Hoitingh
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
Kari Kakkonen
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
James Anderson
 
Microsoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdfMicrosoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdf
Uni Systems S.M.S.A.
 
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AI
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AIEnchancing adoption of Open Source Libraries. A case study on Albumentations.AI
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AI
Vladimir Iglovikov, Ph.D.
 
A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...
sonjaschweigert1
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
Matthew Sinclair
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
Neo4j
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
Quotidiano Piemontese
 
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
Neo4j
 
UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5
DianaGray10
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
Alan Dix
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
KatiaHIMEUR1
 
Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
Kari Kakkonen
 
Large Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial ApplicationsLarge Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial Applications
Rohit Gautam
 
Mind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AIMind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AI
Kumud Singh
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
DianaGray10
 

Recently uploaded (20)

GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
GraphSummit Singapore | Neo4j Product Vision & Roadmap - Q2 2024
 
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
Encryption in Microsoft 365 - ExpertsLive Netherlands 2024
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
 
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
Alt. GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using ...
 
Microsoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdfMicrosoft - Power Platform_G.Aspiotis.pdf
Microsoft - Power Platform_G.Aspiotis.pdf
 
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AI
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AIEnchancing adoption of Open Source Libraries. A case study on Albumentations.AI
Enchancing adoption of Open Source Libraries. A case study on Albumentations.AI
 
A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...
 
20240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 202420240605 QFM017 Machine Intelligence Reading List May 2024
20240605 QFM017 Machine Intelligence Reading List May 2024
 
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
GraphSummit Singapore | Graphing Success: Revolutionising Organisational Stru...
 
National Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practicesNational Security Agency - NSA mobile device best practices
National Security Agency - NSA mobile device best practices
 
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024GraphSummit Singapore | The Art of the  Possible with Graph - Q2 2024
GraphSummit Singapore | The Art of the Possible with Graph - Q2 2024
 
UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5UiPath Test Automation using UiPath Test Suite series, part 5
UiPath Test Automation using UiPath Test Suite series, part 5
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
 
Epistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI supportEpistemic Interaction - tuning interfaces to provide information for AI support
Epistemic Interaction - tuning interfaces to provide information for AI support
 
Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !Securing your Kubernetes cluster_ a step-by-step guide to success !
Securing your Kubernetes cluster_ a step-by-step guide to success !
 
Climate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing DaysClimate Impact of Software Testing at Nordic Testing Days
Climate Impact of Software Testing at Nordic Testing Days
 
Large Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial ApplicationsLarge Language Model (LLM) and it’s Geospatial Applications
Large Language Model (LLM) and it’s Geospatial Applications
 
Mind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AIMind map of terminologies used in context of Generative AI
Mind map of terminologies used in context of Generative AI
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1Communications Mining Series - Zero to Hero - Session 1
Communications Mining Series - Zero to Hero - Session 1
 

ATP

  • 1. IBM Security Identity Manager at ATP Impact of On-boarding 1500 Users in a Highly Customized ISIM System
  • 2. About ATP The largest pension fund in Denmark managing public pensions schemes for 4.7 mill. persons Total assets worth of DKK 700+ billions (app USD 100+ billions) Generally regarded as one of the best performing pension funds world wide with a very high return rate and low cost. ATP has recently been appointed to take responsibility for most public welfare payments payouts (”Udbetaling Danmark”) Yearly payouts app. DKK 180 billions (app. USD 27 billions). Reducing the cost with app. 30% Onboarding app. 1500 users from the municipalities
  • 3. History/Background of the ATP ISIM Installation ATP was converting the pension system from monolithic (”Silos”) system to a SAP and WebSphere Portal based SOA Architecture ISIM (ITIM 4.5.1) was selected as the IdM Platform to automate user lifecycle management in Q2 2005 Target goal for Security Administration was to keep same number of headcounts despite additional systems The system went live 1/1 2006 supporting Windows AD, 2 SAP systems and TAM 5.1 HRFeed from SAP HR app. 1000 users
  • 4. ATP ISIM Primary Focus Automated Lifecycle Management Fully automated on/off-boarding of employees/consultants via SAP HR Identity Feed (HRFeed) Manual Master for external users and technical accounts All aspects of lifecycle and pasword management : New Hire/ contract registrered Termination Account deletion Graceperiod Changes Administration of user accounts
  • 5. ATP ISIM Primary Focus (cont.) Role Governance All ATP Business Platform Roles 100% controlled Roles modelled in top/down process to fit purpose The role model is owned and maintained by the business owners and implemented in ISIM by the Security Administration Roles are recertified regularly
  • 6. ATP Role Request Management Intranet custom tool for requests (general system covering all kinds of requests) Requests for roles are routed to the Security Administration via the Service Management tool (”Helpdesk”) Request are managed by the Security Administration via the ISIM console
  • 7. The ATP ISIM Server Setup ITDI WAS TIM application TAM Active Directory R/3 Provisioning Provisioning Provisioning Person feed HR extract SAP XI DB2 IDS Adapter for TAM HR feed Adapter for SAP Adapter for Active Directory WEMB (MQ) R/3 Multiple Systems Lotus Domino Adapter for Kerne Provisioning Adapter for Notes Provisioning NAFS Kerne Adapter for KSPCICS KSP CICS Provisioning internet
  • 8. ATP ISIM – Systems Managed In Production 16 system managed In Pilot 17 system managed Production Pilot Windows AD 1 (Windows AD 1 (non-functional system) SAP NW (ABP) 9 SAP NW (ABP) 9 Custom "Kerne" (ABP) 3 Custom "Kerne" (ABP) 3 SAP XI 2 Lotus Notes 1 Lotus Notes 1 (non-functional system) KSP CICS UDK 1 ITAM (ABP) 1 ITAM (ABP) 1 ITIM 3 ITIM 3
  • 9. Important Customizations Time Based Roles (managing roles with a start- and end-date) AD Hybrid Management Model Groups are managed ”hard” (RBAC model) if placed in specific AD OUs Groups outside these OUs are non-managed (can be managed using Accesses) Auto Create of AD groups (organization based groups) Workflow for Management of Unauthorized Accounts Accounts created outside ISIM are detected on reconciliation Workflow locks account upon detection and triggers approval flow Provisioning Policy report in CSV format (weekly via mail) Migration/Synch tool to manage business objects (Roles/Policies/Workflows etc.) between environments (Development/Pilot/Prod)
  • 10. ATP ISIM – History and Future Original platform ITIM 32 bit version 4.5.1 2005/1/1 Migrated to ITIM 32 bit 4.6 2007/Q2 Migrated to ITIM 5.1 64 bit 2011/Q4 Upgrade to ISIM 6.0 planned for 2013
  • 11. The UDK project Agreement between the goverment and municipalities in 06/2010 to : Centralize welfare payments into a new organization ”Udbetaling Danmark” (UDK) Uniform Processing Saving target DKK 300 million/year 3 Waves starting 10/2012 covering app. 1500 users ATP deliver Administrative systems support – e.g. IdM 3 new Systems (2 SAP NW + RACF/CICS via WS) Public Certificate and other govermental systems Role Governance based on organization and job role (based on ATPs role governance model) – app. 50 roles
  • 12. ATP ISIM System – Important Numbers Users : 14638 Accounts Roles : 621 Static and 86 Dynamic Roles (plus 50 UDK roles outside ISIM) 20938 Role assignements (403 Roles) Policies 15 Identity Policies 2 Password Policies 12 Adoption Policies 906 Provisioning Policies Employees 2273 Consultants 155 External 521 Technical 101
  • 13. ATP ISIM System – Process Numbers Process 2012/07 2012/08 2012/09 2012/10 2012/11 2012/12 2013/01 2013/02 2013/03 2013/04 Account Add 263 722 1460 1244 971 616 2230 2060 2478 450 Account Pwd Chg 126 125 108 160 210 72 130 202 133 145 Account Delete 385 183 267 274 374 245 474 370 605 460 Account Modify 25089 26566 24712 23825 19281 19230 19230 11990 11215 11293 Account Restore 81 141 358 792 297 460 204 1368 1953 176 Account Suspend 345 256 191 269 362 361 549 315 574 289 Check Policies 34989 38548 39333 38285 44803 45861 48413 60604 72459 68954 Person Add 44 148 304 141 2429 92 1309 4344 911 122 Person Delete 67 36 45 42 63 47 68 63 116 68 Person Modify 682 1859 3074 3338 2006 1729 2946 6689 2451 1084 Reconciliation 517 512 517 527 539 587 640 579 632 610