<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Anatole Catherin, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/anatole-catherin/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/author/anatole-catherin/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Fri, 12 Jun 2026 08:50:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Anatole Catherin, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/author/anatole-catherin/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>AI for IAM: A pragmatic trajectory rather than a revolution</title>
		<link>https://www.riskinsight-wavestone.com/en/2026/06/ai-for-iam-a-pragmatic-trajectory-rather-than-a-revolution/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2026/06/ai-for-iam-a-pragmatic-trajectory-rather-than-a-revolution/#respond</comments>
		
		<dc:creator><![CDATA[Anatole Catherin]]></dc:creator>
		<pubDate>Thu, 04 Jun 2026 13:13:39 +0000</pubDate>
				<category><![CDATA[Deep-dive]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[access management]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[artificial intelligence]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[Transformation]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=30015</guid>

					<description><![CDATA[<p>1.    AI is no longer a fantasy, it&#8217;s a reality that IAM must not miss Two years ago, we asked whether artificial intelligence (AI) could represent a revolution for IAM in our article “Artificial intelligence: a revolution in IAM? &#8211;...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/06/ai-for-iam-a-pragmatic-trajectory-rather-than-a-revolution/">AI for IAM: A pragmatic trajectory rather than a revolution</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 style="text-align: justify;">1.    AI is no longer a fantasy, it&#8217;s a reality that IAM must not miss</h2>
<p style="text-align: justify;">Two years ago, we asked whether artificial intelligence (AI) could represent a revolution for IAM in our article “<a href="https://www.riskinsight-wavestone.com/en/2024/03/artificial-intelligence-a-revolution-in-iam/">Artificial intelligence: a revolution in IAM? &#8211; RiskInsight</a>”. We already emphasized the need for a <strong>nuanced approach</strong>, based on <strong>concrete use cases</strong>, <strong>test-and-learn</strong> logic, and a requirement for <strong>trust compatible with the specific challenges</strong> of identity and access.</p>
<p style="text-align: justify;">Today, the assessment has become more precise: AI has not caused the disruption that some predicted, but it is beginning to find a <strong>real</strong>, more <strong>targeted</strong>, and above all more <strong>pragmatic</strong> role within IAM.</p>
<p style="text-align: justify;">What we also observe is that AI leads to an expansion of the scope of IAM: IAM must now also address issues related to AI and AI agents. To delve deeper into this point, we invite you to explore our article “<a href="https://www.riskinsight-wavestone.com/en/2026/04/securing-ai-agents-why-iam-becomes-central/">Securing AI Agents: Why IAM Becomes Central &#8211; RiskInsight</a>”.</p>
<p style="text-align: justify;">As a reminder, AI is <strong>progressively establishing itself</strong> as a lever for transforming information systems, and <strong>IAM is no exception to this trend</strong>. Faced with the multiplication of identities driven by transformations of different natures, whether it be infrastructure evolutions with the cloud, business vision changes with the rise of CIAM, or the arrival of new technologies like AI agents, organisations must deal with increasingly rich and difficult-to-maintain authorisation models.</p>
<p style="text-align: justify;">In this context, <strong>AI promises to make IAM services more efficient and accessible</strong>, whether through intelligent recommendations, conversational assistants, better data utilisation, or processing volumes that are difficult to manage with traditional approaches.</p>
<p style="text-align: justify;">However, these contributions call for caution. IAM directly concerns access security: at this stage, <strong>AI must remain an assistance tool</strong>, under human supervision, as <strong>responsibility</strong> cannot be delegated to it. In practice, it still primarily manifests as <strong>peripheral components (copilots, chatbots, agents)</strong> that enhance existing systems without disrupting critical functions. The challenge is therefore no longer so much about whether AI has a place in IAM, but rather about identifying <strong>where and how to apply it in a truly relevant way.</strong></p>
<p><img fetchpriority="high" decoding="async" class="aligncenter wp-image-30078 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img1_AI-IAM-relation_2.png" alt="AI-IAM relation" width="1293" height="609" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img1_AI-IAM-relation_2.png 1293w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img1_AI-IAM-relation_2-406x191.png 406w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img1_AI-IAM-relation_2-71x33.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img1_AI-IAM-relation_2-768x362.png 768w" sizes="(max-width: 1293px) 100vw, 1293px" /></p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">2.    What AI use cases truly make sense in IAM?</h2>
<p style="text-align: justify;">The contributions of AI in IAM are unevenly distributed:</p>
<ul style="text-align: justify;">
<li><strong>Identity Governance &amp; Administration (IGA) </strong>concentrates the bulk of initiatives thanks to its data volumes and frequent decisions (reviews, validations, recommendations).</li>
<li><strong>Access Management (AM)</strong> is also heavily featured, with projects primarily aimed at accelerating and streamlining the user authentication process.</li>
<li><strong>Privileged Access Management (PAM)</strong> is seeing the emergence of more targeted uses, particularly around the detection and monitoring of privileged behaviours.</li>
<li>The potential of AI in <strong>Customer Identity and Access Management (CIAM)</strong> remains relatively underexploited, even as it is becoming strategic. This is particularly evident in the emergence of AI agents capable of interacting or acting on behalf of users, especially through chatbots.</li>
<li>AI currently offers limited value for <strong>Trust Services</strong>, where processes are already largely automatable without AI, and is positioned more as peripheral support.</li>
</ul>
<p style="text-align: justify;">To organise these initiatives without ending up with a long list, two main categories of use cases can be identified:</p>
<ol>
<li>Those that aim to <strong>resolve current challenges</strong> in existing processes.</li>
<li>Those that make it possible to address new issues <strong>that traditional approaches cannot cover</strong><strong>.</strong></li>
</ol>
<h3 style="text-align: justify;">The value of AI first emerges from current IAM pain points…</h3>
<p style="text-align: justify;">This first family of use cases generally constitutes <strong>the most natural entry point</strong>, as it relies on existing IAM processes.</p>
<p style="text-align: justify;">AI then plays an <strong>accelerating role</strong>, by <strong>reducing costs and operational</strong> burden, while <strong>improving the experience</strong>, <strong>quality of service</strong>, and <strong>speed of execution</strong>, without calling into question the control model.</p>
<p><img decoding="async" class="aligncenter wp-image-30080 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img2_AI-use-case_2.png" alt="AI use case" width="1269" height="675" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img2_AI-use-case_2.png 1269w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img2_AI-use-case_2-359x191.png 359w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img2_AI-use-case_2-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img2_AI-use-case_2-768x409.png 768w" sizes="(max-width: 1269px) 100vw, 1269px" /></p>
<p style="text-align: justify;">…to become a lever for overcoming the limitations of traditional approaches</p>
<p style="text-align: justify;">The second category of use cases falls into a different category: here, AI is no longer merely aimed at saving time but <strong>unlocks analytical capabilities that are beyond the reach of traditional approaches</strong>, by cross-referencing multiple data points (identity, organisation, permissions, usage, events) across large volumes of data. In particular, it <strong>enables the large-scale detection of atypical access</strong>, such as rare combinations of rights, authorisations inconsistent with a role, or accumulations linked to successive exceptions.</p>
<p style="text-align: justify;">AI also enables the analysis of career trajectories, identifying how certain profiles evolve over the course of job changes, projects or emergencies, to target remedial actions. It also enables intelligent prioritisation of these remedial actions by combining application criticality, data sensitivity and usage signals, whilst in the field of PAM, emerging uses aim to identify behaviours involving unusual privileges to trigger enhanced controls.</p>
<p style="text-align: justify;">Finally, this also paves the way for delegating lower value-added tasks, such as handling Level 1 tickets, for which automation was technically feasible but economically difficult to justify. Today, some <strong>AI-powered</strong> IAM solutions make this substitution realistic and accessible.</p>
<p style="text-align: justify;">The multiplication of pain points and automation avenues should not lead to the indiscriminate deployment of AI. Some needs can be effectively addressed using simple rules or algorithms, and whenever access is involved, every potential error carries a security risk. It is therefore essential, once use cases have been identified, to select and prioritise them, rather than accumulating initiatives.</p>
<h2 style="text-align: justify;">3.    Prioritise AI in IAM before it becomes a pile of initiatives</h2>
<p style="text-align: justify;">Once relevant use cases have been identified, it is necessary to determine which ones to focus efforts on, as not all justify the same level of investment. Prioritisation can thus be based on two key axes: <strong>added value</strong> and <strong>implementation complexity</strong>.</p>
<p style="text-align: justify;"><strong>The challenge here lies in the ability to analyse these two aspects rigorously for each use case.</strong></p>
<p style="text-align: justify;">The first axis, relating to <strong>value</strong>, can thus be understood through several sub-criteria:</p>
<ul style="text-align: justify;">
<li><strong>Operational cost reduction</strong>: <em>measuring how the use case helps avoid certain recurring costs.</em></li>
<li><strong>Efficiency gains and reallocation of efforts</strong>: <em>the ability to free up time and redirect teams towards higher value-added tasks.</em></li>
<li><strong>Reducing cyber risk</strong>: <em>the impact of the use case on reducing identified cybersecurity, IT, or control risk.</em></li>
<li><strong>Contribution to regulatory and strategic issues</strong>: <em>to what extent does the use case meet a priority regulatory or strategic expectation (e.g., DORA, ECB, audits).</em></li>
<li><strong>Impact on the affected populations</strong>: <em>assess who the use case serves and with what frequency of use, as modest but daily use by a large number of users can create more value than a more ambitious use case limited to a restricted scope. The main populations to consider are generally IAM administrators, IAM integrators, end-users, and approving managers.</em></li>
</ul>
<p><img decoding="async" class="aligncenter wp-image-30098 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value_2-1.png" alt="Persona impact on a use case value" width="1322" height="743" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value_2-1.png 1322w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value_2-1-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value_2-1-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value_2-1-768x432.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img3_Persona-impact-on-a-use-case-value_2-1-800x450.png 800w" sizes="(max-width: 1322px) 100vw, 1322px" /></p>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;">The second axis, <strong>complexity</strong> can be assessed according to four complementary dimensions, consisting of:</p>
<ul style="text-align: justify;">
<li><strong>Technical complexity</strong>: the technological effort required to deploy the use case, whether in terms of integrations, architecture, AI models used, or dependencies on the existing information system.</li>
<li><strong>Organisational complexity</strong>: the level of coordination required between teams, scopes, and processes to effectively support the use case.</li>
<li><strong>Associated risks</strong>: cyber, regulatory, or operational risks that may be introduced or reinforced by the implementation of the use case.</li>
</ul>
<p style="text-align: justify;">As a reminder, this approach aims primarily <strong>to guide thinking and structure decision-</strong>making; it is only a proposal that must therefore be adapted <strong>to each context</strong>.</p>
<p style="text-align: justify;">High-impact but quick-to-deploy use cases should be prioritised. Conversely, those requiring significant effort (unavailable data, complex integrations, high security requirements) for limited benefit should be discarded or deferred. To make the trade-off concrete, a &#8220;matrix&#8221; logic works well:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-30101 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop_2-1.png" alt="How to prioritise use cases to develop?" width="1198" height="673" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop_2-1.png 1198w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop_2-1-340x191.png 340w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop_2-1-69x39.png 69w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop_2-1-768x431.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2026/06/EN_img4_How-to-prioritise-use-cases-to-develop_2-1-800x450.png 800w" sizes="auto, (max-width: 1198px) 100vw, 1198px" /></p>
<p style="text-align: justify;">However, this approach also requires being clear on one point: <strong>AI depends heavily on data</strong> (quality, completeness, traceability, repositories) and the ability to exploit it securely. Without <strong>solid foundations</strong>, even a promising use case will remain at the demonstration stage. To generate value in real-world conditions, it must be able to rely on <strong>sufficiently robust IAM foundations</strong>: data quality, structured repositories, process stability, clarity of the authorisation model, etc. Thus, prioritisation must be confronted with the reality of available solutions and their maturity.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">4.    A booming market, with usage still largely unequal</h2>
<p style="text-align: justify;">The IAM market is strongly energised by AI, with expanding roadmaps and the emergence of so-called &#8220;AI-native&#8221; products, designed from the outset to integrate assistance, analysis, and automation mechanisms. These approaches generally address either a <strong>targeted need</strong> or <strong>a differentiation strategy in a rapidly evolving market</strong>.</p>
<p style="text-align: justify;">In parallel, traditional IAM solutions are progressively enhancing their offerings with AI functionalities and generally benefit from greater resources than AI-native players to support this transformation, primarily in cloud environments, which are more conducive to their deployment than on-premises architectures.</p>
<p style="text-align: justify;">However, there remains <strong>a notable gap between promise and reality in production</strong>: most of the functionalities available today are still peripheral assistance (search, summarisation, copilots) rather than AI truly embedded in critical functions.</p>
<p style="text-align: justify;">Adoption also remains gradual, particularly in large organisation, <strong>where the priority remains optimising existing systems</strong>, <strong>stabilising</strong><strong> repositories, reducing technical debt, and ensuring compliance</strong>. AI-native approaches, still relatively new, must be integrated into a realistic roadmap and a clear operating model. <strong>AI should not be seen as a miracle product, but rather as a lever to be incorporated into a global IAM transformation.</strong></p>
<p style="text-align: justify;"><strong> </strong></p>
<h2 style="text-align: justify;">5.    Conclusion – From the announcement effect to a controlled trajectory</h2>
<p style="text-align: justify;">AI applied to IAM seems to be reaching a turning point. The real challenge is not to accumulate use cases: it is to <strong>build a coherent, selective, and sustainable approach</strong>. Because it intervenes in access decisions, AI in IAM requires a higher level of caution than in other areas. The promise of automation <strong>must never mask the responsibility of humans and organisations</strong>. Any recommendation must be understandable, contestable, and justifiable, especially in an audit context. It is necessary to clearly define who validates and who arbitrates, ensure the acceptance of business teams without which AI will be bypassed, ensure regulatory compliance, and rigorously frame the data exposed to assistants to prevent any exfiltration of sensitive information.</p>
<p style="text-align: justify;">To maintain this trajectory, <strong>it is not enough to evaluate use cases in isolation</strong>: the <strong>foundations must be evolved</strong> (quality of identity data, repositories, role model, controls), <strong>an operational model capable of supervising AI</strong> on a daily basis <strong>must be defined</strong>, and emerging uses, particularly around AI agents, must be secured. AI for IAM should therefore <strong>not be thought of as an immediate revolution</strong>, but as <strong>a gradual progression</strong>, from assistance modules to advanced analysis capabilities, ultimately leading to better-controlled automation.</p>
<p style="text-align: justify;">Ultimately, approaching AI in IAM well means moving forward pragmatically, targeting uses that offer <strong>the best balance between value and complexity</strong>, maintaining control over sensitive decisions, and staying attentive to the real market maturity.</p>
<p style="text-align: justify;"> </p>
<h2 style="text-align: justify;">6.    Five priorities to move from AI ambition to IAM results</h2>
<p style="text-align: justify;">In summary, here are the key points to bear in mind to adapt to this transformation:</p>
<ol>
<li style="text-align: justify;"><strong>Identify AI use cases that truly make sense for IAM</strong>, whether they involve improving existing processes or unlocking new capabilities for analysis and automation.</li>
<li style="text-align: justify;"><strong>Objectively define the value and complexity of each use case</strong> to prioritise them for implementation.</li>
<li style="text-align: justify;"><strong>Build a progressive, controlled, and governed trajectory</strong>, rather than accumulating initiatives without an overall vision.</li>
<li style="text-align: justify;"><strong>The market is structuring itself rapidly</strong>: talk to your vendors to understand what they are really offering.</li>
<li style="text-align: justify;"><strong>Also inquire about emerging new solutions</strong>, particularly AI-native ones, and do not hesitate to contact us if you wish to discuss your initial field feedback or broaden your market vision.</li>
</ol>




<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2026/06/ai-for-iam-a-pragmatic-trajectory-rather-than-a-revolution/">AI for IAM: A pragmatic trajectory rather than a revolution</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2026/06/ai-for-iam-a-pragmatic-trajectory-rather-than-a-revolution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>[INTERVIEW] IAM Maturity Assessment &#8211; Where do you stand and why is it crucial?</title>
		<link>https://www.riskinsight-wavestone.com/en/2023/05/interview-iam-will-no-longer-hold-any-secrets-for-you-thanks-to-the-iam-framework/</link>
					<comments>https://www.riskinsight-wavestone.com/en/2023/05/interview-iam-will-no-longer-hold-any-secrets-for-you-thanks-to-the-iam-framework/#respond</comments>
		
		<dc:creator><![CDATA[Anatole Catherin]]></dc:creator>
		<pubDate>Mon, 22 May 2023 09:00:00 +0000</pubDate>
				<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[Focus]]></category>
		<category><![CDATA[Framework]]></category>
		<category><![CDATA[IAM]]></category>
		<category><![CDATA[Maturity]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=20502</guid>

					<description><![CDATA[<p>For over twenty years, Wavestone has been supporting clients develop and strengthen their Identity and Access Management programs. Within this area, Wavestone has observed  that organizations do not always approach IAM in a comprehensive manner. While Security is an obvious...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/05/interview-iam-will-no-longer-hold-any-secrets-for-you-thanks-to-the-iam-framework/">[INTERVIEW] IAM Maturity Assessment &#8211; Where do you stand and why is it crucial?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p style="text-align: justify;">For over twenty years, Wavestone has been supporting clients develop and strengthen their Identity and Access Management programs. Within this area, Wavestone has observed  that organizations do not always approach IAM in a comprehensive manner. While Security is an obvious dimension covered by IAM, other dimensions (e.g. UX enhancement, internal procedures improvement, etc.) are often overlooked. Additionally, accurately assessing  maturity in IAM is complex &#8211; market standards, such as NIST, does not allow evaluation across all issues.</p>
<p style="text-align: justify;">To dive deeper into IAM, our experts have created an IAM maturity assessment tool.</p>
<p style="text-align: justify;">Interview with Anatole CATHERIN, Manager and IAM expert for almost 10 years at Wavestone.</p>
<p style="text-align: justify;"><strong> </strong></p>
<h1 style="text-align: justify;">Hi Anatole, thanks for your time! First of all, can you explain what IAM really is?</h1>
<p style="text-align: justify;">Identity and Access Management (IAM) is a discipline that sits at the crossroads of three worlds:</p>
<ol style="text-align: justify;">
<li>Cybersecurity strengthening: It comprises managing identities, the rights granted to these identities and user access to company resources. Each user has access confined to the limits of their role within an organization. To successfully achieve this, <strong>organizations need to know who, within their information system, can perform which actions and why</strong>. IAM is therefore an essential component of cybersecurity, especially during implementation of a Zero Trust policy.</li>
<li>Business enablement: Identity and Access Management is also a business enabler and a <strong>facilitator for successful digital transformation within organizations as it increases operational process efficiency to </strong>employees and customers. For example, IAM enables the control and fluidity of arrivals, departures or mobility by ensuring that new employee benefit from accurate accesses. In case of subsequent mobility or departure, the relevant accesses are removed and no information is lost.</li>
<li>UX enhancement: <strong>IAM facilitates a seamless user experience for employees</strong> within an organization. Moreover, the best IAM systems operate behind the scenes to enable work on arrival and enhanced connectivity based on security requirements.</li>
</ol>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">Why is it so difficult to build an IAM system that works?</h1>
<p style="text-align: justify;">As you can imagine, the challenge and complexity of IAM is striking (and maintaining) the balance between security and fluidity of navigation.</p>
<p style="text-align: justify;">To successfully implement IAM, it is important to assess the current state. With good reason, <strong>clients have difficulty measuring the effectiveness of their existing IAM system</strong>. There is no dedicated benchmark in the market evaluation.. The NIST pillars are high-level and do not cover all the challenges related to IAM; the existing benchmarks only deal with the cybersecurity aspect of IAM and ignores the impact on the operational efficiency of an organization&#8217;s internal procedures and the fluidity of the user experience.</p>
<p style="text-align: justify;">The goal in creating the IAM Framework was to create a <strong>framework that evaluates the entire discipline and that can be used to build an efficient roadmap.</strong></p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">Can you tell us a bit about the IAM maturity assessment tool?</h1>
<p style="text-align: justify;"><strong>More than a tool, it&#8217;s a framework and a tool-based methodology</strong> that supports customers and provides them an overview of their IAM maturity.</p>
<p style="text-align: justify;">The Framework enables the understanding of an<strong> organization’s current state (</strong>which IAM perimeters are deployed (or not), which IAM axes require further work, etc.). It provides an overview, with the right framework, the right angle and the right resolution to cover all IAM topics.</p>
<p style="text-align: justify;">The maturity assessment consequently <strong>allows the prioritization of workstreams that culminates in an IAM action</strong> <strong>plan</strong>!  Thanks to this framework, we can identify the main areas for improvement, while accounting for organizational nuances by introducing the notion of scope.</p>
<p style="text-align: justify;">In short, it meets <strong>three objectives: Evaluate, Improve and Extend </strong>IAM to other perimeters (beyond internal and service providers, with customers or partners). It was intended to be exhaustive to highlight our customers&#8217; shortcomings and subsequently measure their progress and the effectiveness of their transformation program.</p>
<p style="text-align: justify;">Our ambition is to make it <strong>the primary evaluation standard, entirely dedicated to IAM</strong>, with a sufficient level of granularity to cover all issues!</p>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">How is it structured?</h1>
<p style="text-align: justify;">Concretely, our tool is composed of about fifty questions that cover the <strong>6 IAM themes</strong>:</p>
<ol style="text-align: justify;">
<li>Governance</li>
<li>Identity management</li>
<li>Entitlement management</li>
<li>Access control</li>
<li>Privileged access management</li>
<li>Reporting and controls</li>
</ol>
<p style="text-align: justify;">It can be used in several cases, here are 2 examples:</p>
<table>
<tbody>
<tr>
<td style="background-color: #503078; width: 601px;" width="601">
<p><span style="color: #ffffff;"><u>Use case 1: </u></span></p>
<p><span style="color: #ffffff;">During an audit or (pre)scoping mission, i.e. when you do not know your level of maturity in terms of access and identity management.</span></p>
<p><span style="color: #ffffff;">In this case, the questions allow you to identify areas for improvement in order to launch IAM evolution projects.</span></p>
</td>
</tr>
</tbody>
</table>
<p style="text-align: justify;"> </p>
<table>
<tbody>
<tr>
<td style="background-color: #503078; width: 601px;" width="601">
<p><span style="color: #ffffff;"><u>Use Case 2: </u></span></p>
<p><span style="color: #ffffff;">As part of a transformation program (medium or long term). This type of maturity assessment can be relevant at the halfway point of a transformation program in order to determine the progress made and to redirect the strategy if necessary.</span></p>
</td>
</tr>
</tbody>
</table>
<p style="text-align: justify;"> </p>
<h1 style="text-align: justify;">Can you tell us about the last time you used it with a concrete example?</h1>
<p style="text-align: justify;">We tested the questionnaire in the field through several missions, during which the use of the IAM Framework helped accelerate the process. These missions comprised:</p>
<ul style="text-align: justify;">
<li>the definition of an IAM roadmap for a large energy company</li>
<li>the framing of a migration to an IAM tool for a banking group, which allowed the measurement of gaps between their existing solution and the new one</li>
<li>IAM maturity assessment for an insurance company, to identify friction points and areas for improvement and to establish a roadmap</li>
</ul>
<p style="text-align: justify;">For these three projects, the assessment grid made it possible to identify all addressable topics (regardless of whether the client was aware of them at the outset) in order to provide an actionable roadmap covering all IAM issues. In other words, the Framework can be used as an analysis framework for the implementation of a project.</p>
<p style="text-align: justify;">We plan to launch new missions on the subject and we are looking forward to supporting new customers in their journey to improve their IAM structure!</p>
<p> </p>
<h1 style="text-align: justify;">A final word?</h1>
<p style="text-align: justify;">I will end by reminding you of the key components of the Framework:</p>
<ul style="text-align: justify;">
<li><strong>It is “ready to use”</strong>: the fifty questions encompassed in the framework designed by Wavestone experts covers all IAM topics</li>
<li>It offers a <strong>standardized and formalized vision of its maturity</strong> on the subject of access and identity management: this assessment is also an opportunity to involve all the key players impacted by IAM: cyber teams, IT teams, internal audit teams and business teams,</li>
<li>It <strong>facilitates the prioritization of actions</strong> within a transformation program:as explained above, it can be used at different times and can therefore be used as a support for a broader reflection,</li>
<li>Finally, <strong>it is a flexible means of use:</strong> It can be used at a very high level (a strategic level) or to develop very specific actions.</li>
</ul>
<p style="text-align: justify;"> </p>
<p style="text-align: justify;"><strong>Want to evaluate yourself? Please contact us!</strong></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2023/05/interview-iam-will-no-longer-hold-any-secrets-for-you-thanks-to-the-iam-framework/">[INTERVIEW] IAM Maturity Assessment &#8211; Where do you stand and why is it crucial?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.riskinsight-wavestone.com/en/2023/05/interview-iam-will-no-longer-hold-any-secrets-for-you-thanks-to-the-iam-framework/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
