August 22, 2014 By Ravi Srinivasan 2 min read

IBM recently acquired CrossIdeas, adding to the IBM Security Systems division and its existing identity and access management (IAM) portfolio.

Prior to this acquisition, the company had already partnered with IBM in the Ready for IBM Security Intelligence program, and it integrated its identity and access governance solution platform with the IBM Security Identity Manager. CrossIdeas’ identity and access governance capabilities work to help enterprises reduce the risk of insider fraud while addressing regulatory compliance and audit exposures.

Organizations are increasingly relying on ongoing compliance reviews, new audit findings and identity and access governance tools to help determine security risks and govern who should have access to which resources and why.

A comprehensive identity and access governance solution integrated with enterprise IAM helps determine the granularity and integrity of user entitlements so that governance, risk and compliance policy guidelines are met. Granularity is granting access only to those who need it, while integrity ensures no unauthorized access is available from the existing business processes. With key capabilities such as role and entitlement management, identity analytics, context-based access control and ongoing monitoring/reporting in place, organizations are able to protect their business’s critical applications from unauthorized access — and be able to prove it to auditors.

What Analysts Have to Say About the CrossIdeas Acquisition

According to leading industry analysts, CrossIdeas’ solutions offer a business-centric focus on identity governance and analytics. This approach helps minimize the cost and complexity of automating access certification campaigns, auditing granular segregation of duties violations and managing access requests for all enterprise and cloud applications.

In a Forrester Research report, analysts stated that with the acquisition of CrossIdeas, “IBM will add a number of notable IAM capabilities to its product line, including access governance, access request management, role design and management, separation of duties and SAP governance.”

Further, analyst firm Gartner just issued a First Take report on the CrossIdeas acquisition, saying that CrossIdeas brings fine-grained segregation of duties, risk-based role mining, attribute-based access control, IAM-as-a-service readiness and compliance reporting based on the way auditors define policies. These functions, it said, could enable IBM to take a leading role within the identity governance and administration market.

More from CISO

X-Force Threat Intelligence Index 2024 reveals stolen credentials as top risk, with AI attacks on the horizon

4 min read - Every year, IBM X-Force analysts assess the data collected across all our security disciplines to create the IBM X-Force Threat Intelligence Index, our annual report that plots changes in the cyber threat landscape to reveal trends and help clients proactively put security measures in place. Among the many noteworthy findings in the 2024 edition of the X-Force report, three major trends stand out that we’re advising security professionals and CISOs to observe: A sharp increase in abuse of valid accounts…

Boardroom cyber expertise comes under scrutiny

3 min read - Why are companies concerned about cybersecurity? Some of the main drivers are data protection, compliance, risk management and ensuring business continuity. None of these are minor issues. Then why do board members frequently keep their distance when it comes to cyber concerns?A report released last year showed that just 5% of CISOs reported directly to the CEO. This was actually down from 8% in 2022 and 11% in 2021. But even if board members don’t want to get too close…

The CISO’s guide to accelerating quantum-safe readiness

3 min read - Quantum computing presents both opportunities and challenges for the modern enterprise. While quantum computers are expected to help solve some of the world’s most complex problems, they also pose a risk to traditional cryptographic systems, particularly public-key encryption. To ensure their organization’s data remains secure now and in the future, chief information security officers (CISOs) should educate themselves about quantum computing, proactively address the coming quantum risks to cybersecurity and work to establish cryptographic agility in their enterprise.A future cryptographically…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today