OM-IND-0011: Revocation Automation Level (Indicator - IAM)

ID

OM-IND-0011

Process

Revocation Automation (Process - IAM)

Indicator

Revocation Automation Level

Version

1.0 Ready for peer review

Formula

Where:

  • is the set of IT systems in the scope

  • is the set of IT systems for which revocation is automated

  • is the set of IT systems for which revocation is not automated

  • is the set cardinality function

Benchmarking

This indicator is improper for benchmarking because it uses absolute numbers. Use OM-IND-0010: Revocation Automation Ratio (Indicator - IAM) instead.

Rationale

The level of revocation automation shows the absolute number of IT systems for which revocation is automated and for which it is unautomated. Assuming that automation accelerates and makes revocation more reliable, it is expected that an increase in automation or a decrease in unautomation leads to higher productivity, strengthened security and reduced risks. Showing absolute values, this indicator also reflects newly setup and decommissioned IT systems.

Stakeholders

  • IAM Manager

  • CISO

  • IT Risk Managers

Scopes

This indicator may be specialized for different scopes. See Revocation Automation (Process - IAM) for typical scopes.

Negative Effects

  • In certain circumstances, the economical benefits of automation may be unjustifiable (e.g.: when processing low volumes of IAM artifacts on non-sensitive IT systems). Pursuing this indicator blindly could lead to economical waste.

  • Poorly implemented automation may lead to new risks, e.g. silent automation errors leading to a false sense of security, automation mechanisms that are vulnerable to compromission or lead to denial of service.

Data Sources

  • IT System inventory

  • CMDB

  • IAM software platform

Typical Frequency

Monthly

See Also

Sample Visual Representation

If the number of automated systems is out of proportion with the number of unautomated systems, we recommend to use a broken Y axis and not use a logarithmic scale that would be misleading.


Follow us on LinkedIn | Discuss on Slack | Support us with Patreon | Sign-up for a free membership.


This wiki is owned by Open Measure, a non-profit association. The original content we publish is licensed under a Creative Commons Attribution 4.0 International License.