Data Access Management

The Challenge

One of the main risks enterprises face today is derived from insiders accessing information to which they are not entitled. Certain compliance regulations have been imposed to mitigate access concerns. Such concerns include privacy breaches, unlawful use of data and fraud.

Some of the more known rules are HIPAA for the health care industry and the Sarbanes Oxley act for US public companies. The challenge organizations face is how to comply with all the security and entitlement constraints while still providing the most effective flow of business information. Currently the common way of handling this challenge is by coding the data access rules into each individual application. This approach impose the following issues:

  • Accuracy problems, risks of blocking legitimate users or enabling unauthorized access.
  • Users have access to multiple systems. The entitlements are set for each system individually.
  • Due to long turnaround time for changes, the required data, when finally available, may be outdated.
  • Audit of security policies is expensive and inaccurate.
  • Confirmation of work completed is missing. No feedback to the business unit that the policy was correctly implemented.

Solution

The "Data Access Manager" product fundamentally changes the way Corporations control the Data Access. Utilizing Business Intelligence techniques and metaphors the Data Access Manager allows business users to define the Data Access rules using system agnostic metaphors. The Data Access Manager compiles a Data Access "Map" that is communicated to the target systems. The Data Access Manager is an enterprise application that supports all the workflow and audit requirements typical to large and complicated enterprises. The immediate benefits of using Spatiq's Data Access Manager are:

  • Increase in productivity, by relieving technical resources that formerly handled the task.
  • Reduce the turnaround time for the provisioning and change of rules and entitlements, this includes faster on boarding of new employees.
  • Putting the control and responsibility for Data Access in the hands of the business.
  • Reduction in the risk of breach, theft and malicious activities.
  • Increase in control and audit capabilities.