Insight

[Solution Review] SGA ZTA ICAM Goes Beyond Account Management to Become the 'Brain' of Zero Trust

IT DAILY ·

Conceptual diagram of the integrated account, authentication, and authorization management solution “SGA ZTA ICAM” [Photo: SGA Solutions]

✦ AI Summary

As IT environments become more complex and virtualization and cloud services spread, accounts and access privileges are increasing, and it is becoming difficult to manually verify account creation, changes, and deletions, which can lead to security incidents.

SGA ZTA ICAM integrates accounts, identities, access rights, and credentials, and supports unauthorized account detection and self-service automation through connector integration, automated collection, comparison, and policy application.

The solution aims to implement Zero-trust by applying continuous verification and the principle of least privilege through ABAC, security scores, and a PDP-based approach beyond RBAC.

As IT environments grow more complex and virtualization and cloud services spread, the number of systems continues to rise, and so do the accounts and access privileges that must be managed. It is common for an employee to have more than 10 work accounts, and infrastructure administrators may hold dozens to hundreds of individual administrative accounts, making it increasingly difficult to manually verify whether accounts are being created, changed, or deleted. These gaps in account management can lead to security incidents.

SGA ZTA ICAM is an integrated account, authentication, and authorization management solution that uses account management as its foundation and manages user identity, accounts, authentication policies, and authorization policies. It also covers account management, access control, and credentials for identity verification, and is presented as the core of implementing Zero-trust's principle of least privilege as well as its strengthened user authentication.

SGA Solutions presented a conceptual diagram for the integrated account, authentication, and authorization management solution, "SGA ZTA ICAM." According to the diagram, the account management (IM·Identity Management) solution has handled account life-cycle management within IT environments since the 1990s.

The main purpose of early account management was to create, change, and delete accounts distributed across multiple systems in batches. As computer networks and server systems became commonplace, the number of related accounts increased, and structures were used in which accounts for system access such as email and Unix were automatically created and distributed when employees joined the company.

Over time, the number of accounts linked to systems also increased, and as enterprises added more work applications and systems, the number of accounts issued to employees rose as well. With the practice of issuing separate accounts by system, there were cases in which a single employee held more than 10 accounts, and infrastructure administrators such as those managing servers and networks ended up with several times more accounts than ordinary employees.

Against this backdrop, the management scope expanded from account creation and deletion to access control. SGA Solutions presented this as a transition from IM to ICAM.

As environments emerged in which operational accounts were shared to improve efficiency, a single operational account was shared by multiple administrators, reducing the total number of accounts but creating a new problem: it became difficult to identify the actual user when the same account was used. As a result, the need to control access privileges and usage logs, in addition to account management, grew, and IAM is defined as linking accounts to user identities and controlling access.

ICAM is a broader concept than IAM, and its management scope includes credentials used to verify that a claimed identity actually belongs to the user. To improve trust in ICAM, combinations of knowledge-based information such as passwords, possession-based devices and authentication factors, and biometric information are presented, and the criteria for granting access rights after authentication are position and job, with only the access rights needed after authentication being granted.

Image source: SGA Solutions. SGA Solutions presented "SGA ZTA ICAM," a product that consolidates authentication and authorization-related elements. The elements covered include accounts, identities, access rights, and credentials.

SGA ZTA ICAM is structured to centrally manage user and account information distributed inside an enterprise. It was also noted that broad access to user and system information is necessary for precise account management and access control.

Based on this collected and integrated information, policy application becomes possible, and so does privilege control. It also presented the possibility of detecting unauthorized accounts.

For this purpose, SGA ZTA ICAM has connector functions for linking with a wide range of solutions. Examples of connected systems include Microsoft's Active Directory (AD·Active Directory), HR systems, and databases (DB), and file-based integration such as CSV is also possible depending on the system environment.

By comparing the collected information against system accounts and organizational management data on the basis of identity and account management, it becomes possible to detect unauthorized accounts created arbitrarily, and to identify accounts that are registered in records but do not actually exist in the system. Unauthorized accounts created outside the management framework can be abused as Backdoor access for attackers to hide on servers.

In the past, IT infrastructure was built around a small number of large servers, but today the spread of virtualization and cloud services has greatly increased the number of systems to be managed. Virtual machines (VM·Virtual Machine) can be created on demand, leading to a larger number of accounts as VMs increase, and the ease of creating accounts has also made it harder to search for and delete unused accounts without omissions. To address this, SGA ZTA ICAM supports a comprehensive security framework across multiple environments with automated collection, comparison, and policy application functions.

The spread of generative AI and AI agents is creating new account management challenges. Along with the presence of application accounts, workload accounts, and service accounts in addition to human accounts, the number of non-human identities (NHI·Non-Human Identity) is also increasing.

As a result, the importance of an integrated management framework that encompasses both human and non-human identities, accounts, and privileges is being highlighted. According to SGA Solutions, this change is expanding the role of integrated account, authentication, and authorization management solutions such as SGA ZTA ICAM.

The provision of a "self-service" function in SGA ZTA ICAM is an extension of this trend. The function focuses on automating the process from account and privilege application to approval.

Under the conventional approach, when system access privileges or accounts were needed, users requested them directly from the relevant department, and administrators then created the account or privilege and delivered it. SGA ZTA ICAM automates this through its self-service function.

SGA ZTA ICAM is a solution that applies a self-service approach to reduce multi-step user procedures and improve convenience. Users review information and then apply for the necessary privilege platform, and requests are processed based on predefined approval procedures. Administrators then check whether approval has been granted and whether policy application is proceeding properly, and the system is configured to create accounts and grant user privileges according to the processing results.

The solution automates the entire process of account creation, change, and deletion as a single workflow. As a result, instead of requesting the person in charge by phone, email, or groupware, users follow a set workflow, and records of the management process can be preserved. In addition, when problems such as security incidents occur, it is possible to identify both the privilege requester and the approver as auditable information.

In terms of access control, SGA ZTA ICAM highlights Attribute-based access control. The mainstream method for privilege management in the past was Role-Based Access Control (RBAC) based on a user's job and duties, and RBAC was applied to granting privileges to users in the same role. A representative example of RBAC is the batch configuration of access privileges for specific organizations or roles, such as marketing teams or sales teams.

ABAC is a dynamic access control model that differs from RBAC. ABAC evaluates multiple attributes, including the user, resource, and environment, and then decides whether to grant privileges or deny access after evaluating those attributes in real time. In this process, permission or blocking is determined based on collected information such as the account's security level, device status, and access environment.

In addition, if attribute changes occur after access is granted, the original access decision is re-evaluated. If the re-evaluation shows that the attributes no longer meet policy requirements, access can be reconsidered and blocking policies can be applied.

SGA ZTA ICAM implements sophisticated ABAC based on quantifying security risk. Policy decision factors include not only the user but also the status of the access terminal. Here, the score refers to a risk level value calculated based on user and device information, enabling more granular policy decisions.

There are cases in which a Unified Endpoint Management (UEM) solution is installed on work devices to measure security scores. UEM collects whether the screensaver is configured, whether automatic login is enabled, and the state of account password management, and these become the basis for calculating the security score.

ZTA ICAM controls user access rights based on the security score obtained in this way. However, the way the score is applied is not a simple reflection of collected data in its original form, and in risk score calculations, different weightings can be applied by organization environment and industry. This is intended to ensure suitability for internal conditions, and weight adjustment is provided as part of the ICAM configuration function. The security score serves as the basis for applying different policies depending on the situation at the time of access, even for the same user.

The access control method does not allow access based on a one-time authentication pass alone; policy decisions continuously reflect the user's status and the device's status. The risk level at the time of access is also used in access decisions. SGA ZTA ICAM is distinguished from simple account management solutions in that it uses the risk level at the time of access, which is linked to Zero-trust's principle of continuous verification and least privilege.

The components of a Zero-trust architecture are the user (subject), resource (object), PDP (Policy Decision Point), and PEP (Policy Enforcement Point). The resource access procedure works by having the user go through the PEP, while the PDP collects information such as the user's identity, device status, and target resource to decide whether to allow access.

In this structure, the PDP is responsible for determining whether to allow access based on information such as user identity, device status, and the target resource, while the PEP is responsible for applying the PDP's decision to the actual access path. Accordingly, access control between the user and the resource is operated with decision-making and enforcement separated.

SGA ZTA ICAM is the core solution that performs the role of the PDP within a Zero-trust architecture. The solution treats accounts, identities, and credentials as elements to be collected and verified, and uses them to validate the safety of user access.

Accounts, identities, and credentials form the foundation for applying continuous verification and least privilege principles. SGA ZTA ICAM passes these decision results to the PEP, which supports strengthened security policies.

SGA Solutions is focusing on implementing a Zero-trust architecture centered on SGA ZTA ICAM, and is promoting integration with its other solutions, including the server security RedCastle, the cloud security platform vAegis, and the cloud-native container platform cAegis. This is intended to support the creation of a Zero-trust-based microsegmentation environment, and it also supports API integration with other security products such as firewalls and network access control (NAC), enabling flexible integration with a company's existing security infrastructure.

Lee Seong-jun, head of the Quality Certification Center at SGA Solutions, said that the starting point of security problems is people and that identity cannot be excluded from Zero-trust. He added that if multiple solutions are the hands and feet, ZTA ICAM corresponds to the brain that directs them, and that ZTA ICAM is the center of the beginning and completion of Zero-trust.

In the context of placing the starting point of Zero-trust in people and identity management, Lee Seong-jun, executive director and head of the Quality Certification Center at SGA Solutions, first distinguished between account and identity.

Lee Seong-jun explained that an Account is an account that exists in an IT system. He also explained that an identity is a subject such as a person.

He then said that the target of work in the system is the account. By contrast, he defined the subject that handles the account as the identity.

In the past structure, one account was issued per person. As a result, a one-to-one matching structure between account and identity was formed.

The basis of past security policies was also one-to-one matching between account and identity. Under that premise, security policies could be established by linking accounts and identities.

However, a change emerged in which multiple people began using a single account. As a result, the validity of the existing access approach weakened, and Lee Seong-jun explained that this was the point at which the importance of identity began to stand out.

Following this explanation, the next question moved to what changes result from adding Credential to ICAM compared with IAM.

Credentials are elements that prove identity. The most widely used credential is a password, which is familiar and convenient but relatively weak in security because others may be able to learn it. To compensate, hardware tokens and OTP (One-Time Password) generators are used; these are safer than passwords but have the drawback of being lost. The strongest credentials are presented as biometric information such as fingerprints and facial recognition.

Regarding what differentiates SGA ZTA ICAM, the solution has functions that integrate the management of identities and credentials. Through this, it provides a more sophisticated and dynamic security model. While IAM focuses on who can enter, the ICAM approach strengthens verification with multiple credentials.

SGA Solutions explained that it is positioning SGA ZTA ICAM as a key axis for implementing a Zero-trust architecture. It also said that the core of security problems is people. While necessary resources do not move, information leaks or server outages occur when people misuse access or when malicious attackers gain access.

It then summarized the indicators used to determine trustworthiness in IT environments as identity and credentials. It emphasized that controlling human access is also central to implementing Zero-trust, and that identity and credentials are the criteria that distinguish it.

SGA ZTA ICAM is an integrated account, authentication, and authorization management solution that encompasses identities and credentials, and all information gathered in SGA ZTA ICAM is directly linked to Zero-trust's pursuit of least privilege and continuous verification. Its distinguishing feature also lies in the organic linkage between the PDP and the PEP: SGA ZTA ICAM takes on the role of the PDP, which determines access policy based on identities and credentials, while the PEP implements actual access control, creating a single flow that runs from information collection to policy decision to enforcement.

Source: IT DAILY · Kim Ho-jun
Original: https://www.itdaily.kr/news/articleView.html?idxno=241202

References

This article was produced with the help of an automated content generation algorithm.


Source: IT DAILY

View original

This article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.