I have just published a series of articles on the IBM Security Identity & Access blog (
https://www.ibm.com/blogs/security-identity-access/) proposing an
Identity Governance Data Model which came out of some other work I've been doing.
The challenge we see in the ever-expanding Identity Governance and Administration (IGA) space is the lack of a data standard for shipping identity changes between one or more identity management/governance systems and the target systems with access repositories. We've seen the old guard, like DSML and SPML, slip into obscurity, and the new kid on the block (SCIM) is too light to cover the rich data needs of identity governance data. Thus the proposed Identity Governance Data Model.
There are three articles in the thread:
1.
IGDM Part 1 – Proposing an Identity Governance Data Model (
https://www.ibm.com/blogs/security-identity-access/igdm-part-1/)
2.
IGDM Part 2 – Validating the Proposed Identity Governance Data Model (
https://www.ibm.com/blogs/security-identity-access/igdm-part-2/)
3.
IGDM Part 3 – Implementing the Identity Governance Data Model (
https://www.ibm.com/blogs/security-identity-access/igdm-part-3/)
This is not a live implementation, or something you will see in a product, just something I've been working on in the background. Happy to take any feedback.
------------------------------
David Edwards,
WW Tech Enablement SME for Identity Products
IBM Security
------------------------------