Identity management projects are considered complex because many steps must be taken before the project is complete, such as the product setup, information-gathering, integrations and other configurations.

A traditional information management project follows a similar sequence:

  1. Information-gathering and design
  2. Product setup
  3. Configuration
  4. Creation of X connectors
  5. Creation of X workflows
  6. Tests
  7. Homologation
  8. Production

Now, imagine that in the homologation step, a workflow connector is discovered to be no longer necessary for a business. A connector or workflow could improve a business further if it was in production before that point.

To deliver more accurately and quickly, we will apply an agile development framework, or Scrum.

Scrum is an interactive and incremental agile development network challenged to change the development sequence approach and use self-organized and multidisciplinary teams.

Scrum utilizes the following roles:

  • Product Owner: Responsible for controlling the business demands of the product.
  • Scrum Master: Responsible for executing Scrum processes and eliminating any issues with the project.
  • Development Team: Responsible for creating incremental steps for the project.

Process of Scrum Identity Management

In the Scrum dynamic, there is a product backlog with business requirements of product features. The following is the sequence of its operations:

  1. Spirit Planning: Prioritized backlogged items are analyzed to be addressed in a list known as the sprint backlog.
  2. Sprint: The development time, which must be limited to one month.
  3. Daily Scrum: A short daily meeting where employees discuss what was done in the past day, what will be done the next day and any problems that may arise.
  4. Sprint Review: The result of the developed sprint is presented.
  5. Sprint Retrospective: The process is reviewed to find ways it could be improved.

Using Scrum

So who should use a Scrum model in an identity management project?

First, we need to separate the main activities of an identity management project, such as the following:

  • Information-gathering
  • Process design
  • Product setup
  • Connectors configuration
  • Workflow configuration

Based on these activities, let’s separate the product setup into one activity with a beginning, middle and end that is unrelated to Scrum. This activity must be executed before the Scrum process begins.

After that, we will elaborate on the product backlog, where the product owner must have a list of the business requirements, such as the following:

  • Manage ERP user accounts
  • Revalidate user access
  • Manage user accounts in System X
  • Manage user accounts in System Y

The product backlog is a live, growing list with business requirements and two of the most important stages of identity management projects: information-gathering and process design.

After that, we go to sprint, beginning with the sprint planning. At the sprint planning stage, the prioritized activities of the product backlog are analyzed. In this example, we considered the following:

  • Manage user accounts in System X
  • Manage user accounts in System Y

In other words, managing ERP user accounts is not a priority for businesses and will not be managed now.

The development team then analyzes these topics, confirms whether it is possible to include them in the sprint stage (30 days) and fragments the technical activities to be executed to create an increment of the product. The following is an example of this:

  1. Configure the creation account workflow in System X
  2. Configure the creation account workflow in System Y
  3. Configure the deletion account workflow in System X
  4. Configure the deletion account workflow in System Y
  5. Configure the IAM connector to System X
  6. Configure the IAM connector to System Y
  7. Execute unity tests
  8. Execute integrated tests

After the sprint planning and development and configuration starts, we have the daily Scrum meetings and at the end, the sprint review and sprint retrospective.

Once the sprint ends, another one begins, and prioritized backlog items are analyzed again. Moreover, at the end of a sprint, it is possible to also release in production the produced workflows and connectors, with a fast return to business.

Scrum may be a good approach to give a fast return to business in identity management projects. In this example, if the company didn’t use Scrum, it would have to wait for all workflows and connectors to be developed in order to have access to the product.

More from Identity & Access

CISA, NSA Issue New IAM Best Practice Guidelines

4 min read - The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) recently released a new 31-page document outlining best practices for identity and access management (IAM) administrators. As the industry increasingly moves towards cloud and hybrid computing environments, managing the complexities of digital identities can be challenging. Nonetheless, the importance of IAM cannot be overstated in today's world, where data security is more critical than ever. Meanwhile, IAM itself can be a source of vulnerability if not implemented…

4 min read

The Importance of Accessible and Inclusive Cybersecurity

4 min read - As the digital world continues to dominate our personal and work lives, it’s no surprise that cybersecurity has become critical for individuals and organizations. But society is racing toward “digital by default”, which can be a hardship for individuals unable to access digital services. People depend on these digital services for essential online services, including financial, housing, welfare, healthcare and educational services. Inclusive security ensures that such services are as widely accessible as possible and provides digital protections to users…

4 min read

What’s Going On With LastPass, and is it Safe to Use?

4 min read - When it comes to password managers, LastPass has been one of the most prominent players in the market. Since 2008, the company has focused on providing secure and convenient solutions to consumers and businesses. Or so it seemed. LastPass has been in the news recently for all the wrong reasons, with multiple reports of data breaches resulting from failed security measures. To make matters worse, many have viewed LastPass's response to these incidents as less than adequate. The company seemed…

4 min read

Cybersecurity in the Next-Generation Space Age, Pt. 3: Securing the New Space

8 min read - View Part 1, Introduction to New Space, and Part 2, Cybersecurity Threats in New Space, in this series. As we see in the previous article of this series discussing the cybersecurity threats in the New Space, space technology is advancing at an unprecedented rate — with new technologies being launched into orbit at an increasingly rapid pace. The need to ensure the security and safety of these technologies has never been more pressing. So, let’s discover a range of measures…

8 min read