Knowledge Article
Targeted Certifications Milestone
Author
ryan_cutter
SailPoint
Targeted Certifications are a critical milestone in ensuring robust identity security within your organization. By focusing on specific high-risk populations and assigning appropriate certifiers, you can streamline the certification process and enhance security measures. This guide outlines best practices, common pitfalls, and actionable advice to help you effectively plan, configure, and execute targeted certification campaigns. With these guidelines, you'll be well-equipped to mitigate risks, ensure compliance, and achieve successful certification outcomes.
1
Plan for certification campaigns
Resources:
Identity Security Cloud
IdentityIQ
Advice:
Ensure a thorough understanding of certification objectives, requirements, capabilities, and prerequisites. Complete adequate training and education before planning certification campaigns. Develop a comprehensive solution design with mappings to requirements and a test plan.
Pitfalls:
- Inadequate planning for certification campaigns can negatively impact delivery and risk achieving objectives.
2
Identify certification campaign drivers
Resources:
Identity Security Cloud
IdentityIQ
- Creating Populations
- Targeted Certifications
- Best Practices for Sarbanes-Oxley (SOX) Compliance, Reporting, and Auditing
Advice:
Use search, reporting, and business analysis to pinpoint the drivers for certification campaigns, which commonly include regulatory compliance; adherence to data protection laws (e.g., GDPR, HIPAA) and industry standards (e.g., PCI DSS, NIST, SOC); risk management and threat detection/incident prevention; oversight of high-risk populations with privileged access; cost management and reduced license overhead; operational efficiency through streamlined access processes; and organizational changes such as mergers, acquisitions, and employee role transitions.
Consider using the following fields when analyzing the data:
- Identity Type (e.g., employee, contractor)
- Department (e.g., IT, Finance)
- Job Role (e.g., Systems Administrator, Financial Analyst)
- Privileged Access (e.g., Domain Admins, wheel)
Note: Identity Security Cloud customers with Access Insights should leverage Identity Outliers to identify risky access and create certification campaigns for remediation.
Pitfalls:
- Including too many identities in certification campaigns can increase the effort required for change management and end-user education.
- Narrow the focus of the certification campaign or stagger certifications into multiple, successive campaigns.
3
Identify certifiers for each population
Resources:
Identity Security Cloud
IdentityIQ
Advice:
Identify certifiers based on responsibilities and security policies for each population. Certifiers should understand what is being certified (accounts or access) and the access needs of the identity population. This may require different certifiers for different identity populations and access items.
Pitfalls:
- Assigning certifiers without an understanding of the items being reviewed can lead to inappropriate certification decisions.
- Assigning certifiers without authority over the items being certified can lead to inappropriate certification decisions.
4
Configure and test targeted certifications
Resources:
Identity Security Cloud
IdentityIQ
- Targeted Certification
- Testing Certification Reminders and Escalations
- Managing Large Certifications
- Automatic Closing of Certifications
- Access Review and Certification Reports
Advice:
Configure and test the targeted certification campaigns for identified certification campaign drivers. Divide campaigns to ensure appropriate certifiers review the correct identity populations and certification items. Further divide and stagger campaign execution to avoid certification fatigue. Ensure business-friendly display names and descriptions for reviewed items for informed certification decisions. Identify what action steps should be taken on undecided certification access items.
Pitfalls:
- Inadequate testing or evaluation of certifications can lead to inaccurate campaigns, requiring additional time and effort to rectify.
- Certification fatigue can result in inappropriate certification decisions, negatively impacting efficacy.
- Lack of business-friendly display names and descriptions can result in inappropriate certification decisions, negatively impacting efficacy.
5
Conduct end-user education
Resources:
Identity Security Cloud
IdentityIQ
- Access Reviews - A Guide for End Users
- Delegation, Reassignment, and Forwarding - IdentityIQ 7.1+
- How to Use "Changes Detected" to Quickly Spot New Users and New Access in Access Reviews
Advice:
Educate certifiers and others involved in the certification campaign. Adapt existing end-user documentation for tailored internal enablement. Ensure adequate understanding through mandatory education requirements.
Pitfalls:
- Inadequate end-user education can lead to a need for additional certification execution support and inappropriate certification decisions.
6
Run and monitor certification campaigns
Resources:
Identity Security Cloud
IdentityIQ
Advice:
Run, monitor, and complete all initial in-scope certification campaigns. Ensure compliance with certification completion. Plan for exceptions or reassignments as needed. Document efforts to address non-compliance or execution issues for future policy, process, and solution improvements.
Pitfalls:
- Inadequate preparation for running a certification campaign can negatively impact delivery and outcomes.
- Failure to perform necessary reassignments can delay certification campaign execution and completion.
- Inadequate monitoring can negatively impact completion time and outcomes.
7
Confirm certification outcomes
Resources:
Identity Security Cloud
IdentityIQ
Advice:
Confirm certification campaign outcomes and gather feedback for future improvements. Work with auditors and stakeholders to provide adequate reporting and analysis of certification decisions, actions, and issues, if any.
Pitfalls:
- Inadequate confirmation of certification outcomes can lead to costly audit findings and issues, negatively impacting delivery.
- Failure to action certification decisions can increase security risk.
- Lack of feedback and documentation can result in missed opportunities for improvement.