IBM Verify

IBM Verify

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  ISIM - ISAM - Customer Requirement questionnaire

    Posted Tue June 02, 2020 04:27 AM

    Hi All,

    One of my customers wanted to deploy and configure ISIM 7.0.2 and ISAM 9.0.6 for their organization.

    Does anybody have any standard questionnaire prepared or published by IBM itself to gather the customer requirement for ISIM and ISAM?

    Of course, I need to modify it to match with the type of business customer is running. However, It will help me a lot to reduce the requirement gathering iterations and to cover all things. 

    Thanks in advance!

    Regards,
    Prashant Narkhede



    ------------------------------
    Prashant Narkhede
    ------------------------------


  • 2.  RE: ISIM - ISAM - Customer Requirement questionnaire

    Posted Tue June 02, 2020 04:44 PM
    ISIM and ISAM are big topics. Your questions should be around, HR data, types of users (internal, external, service accounts) account provisioning, password management, number of target systems you will be provisioning to. You should think about full RBAC or hybrid approach, approval workflows, self service, governance and recertifications

    As per ISAM, capacity, availability, federations, access policies, user directories and much more to think about.

    BTW, why ISIM 7. My understanding is that it is appliance based and you run into many restrictions not having access to the host operating system.

    ------------------------------
    Krishna Baddam
    ------------------------------



  • 3.  RE: ISIM - ISAM - Customer Requirement questionnaire

    Posted Wed June 03, 2020 02:35 AM
    I totally agree - the problem with products in the Identity management area is that they need to be functionally very rich (and extensible to close functional gaps) - but that also means that a generic questionnaire does not really make sense - but the point here are always good discussion points - uncovering and understanding the specific client need is key.

    I often compare IdM to ERP - it is a question of implementing business functions/flows much more than implementing a product - which is also why it is important to understand that it is a security program - not a project...

    I also recommend ISIM 6 for most implementation - even if the appliance is functionally on par it is in real world situations difficult to handle due to the complex nature of the ISIM product and IMHO the importance to debug problems quickly (which is much much easier in ISIM 6) is much more important than the improved upgradability of the VA.

    HTH

    ------------------------------
    Franz Wolfhagen
    IAM Technical Architect for Europe - Certified Consulting IT Specialist
    IBM Security Expert Labs
    ------------------------------