Identity and Access Management version 1.0
| Scorecard | Audience | Description |
|---|---|---|
|
|
This scorecard is a template that illustrates the organizations performance. In addition, this displays rollup information as defined by the Control Objective (Level 1) layer of the hierarchy. The Control Objectives focus on three critical control objectives: ensuring proper access to information systems, monitoring of login activity and account status, and compliance of user authentication to policy. |
|
|
|
This scorecard is a template that illustrates the organizations overall performance. In addition, this displays rollup information as defined by the Control (Level 2) layer of the hierarchy. |
|
|
|
This scorecard is a template illustrates the organizations overall performance. In addition, this displays rollup information as defined by the Key Performance Indicator (Level 3) layer of the hierarchy. |
|
|
|
Operations |
Access Control Policies displays statistics on user access provisioning activity. This scorecard presents trended metrics results for account provisioning ticket processing time compared to policy. |
|
|
Operations |
Access Removal Statistics displays trended statistics for user access deprovisioning. This scorecard presents metrics results for account deprovision ticket activities and account deprovision processing time. |
|
|
Operations |
Account Management illustrates how efficiently the organization manages user accounts. This scorecard presents trended metrics results for active accounts by account type, active idle accounts that never expire, and pending account provision and deprovision requests. |
|
|
Operations |
Account Requests Closed In Policy displays trended statistics for identity and access support ticket management. This scorecard presents metric results for support activity compared to policy standards. |
|
|
Operations |
Account Requests Mean Close Time displays trended statistics for identity and access support ticket management. This scorecard presents metric results for account request processing time. |
|
|
Operations |
Accounts With Non-Blank Passwords displays trended metrics results for the percentage of accounts which have a password. |
|
|
Operations |
Active Account Expiration displays trended statistics for user account management activity. This scorecard presents metric results for average time to account expiration. |
|
|
Operations |
Active Idle Accounts displays trended statistics for user account management activity. This scorecard presents metric results for the percentage of idle accounts. |
|
|
Operations |
Content Filtering Statistics displays trended statistics for web content filtering. This scorecard presents metrics results for blocked and allowed content, and percentage of users accessing blocked content. |
|
|
Operations |
Deprovision Ticket Close Time shows the average time it takes the organization to close an account deprovisioning ticket. |
|
|
Operations |
Deprovision Tickets Handled Within Policy illustrates the organization's adherence to account deprovision ticket duration policy.The scorecard displays trended metrics results for the percentage of deprovision requests closed within user-defined policy. The default policy is 10 days. |
|
|
Operations |
This scorecard provides security metrics about the groups in an active directory domain. |
|
|
Operations |
Login Activity displays statistics for user login activity and login frequency. This scorecard presents trended metrics results for volume and latency of successful and failed login attempts. |
|
|
Operations |
Non-Expiring Active Idle Accounts displays trended statistics for user account management activity. This scorecard presents metric results for perpetual accounts. |
|
|
Operations |
Password Auditing illustrates account password strength. The scorecard displays trended metrics results for the percentage of accounts with uncracked passwords. |
|
|
Operations |
Password Hygiene Statistics illustrates adherence to password policies. This scorecard presents trended metrics results for accounts with passwords, and for password strength. |
|
|
Operations |
Password Management Statistics presents statistics for password accounts and password age. This scorecard displays trended metrics results for accounts with expiring passwords, and passwords reset within policy. |
|
|
Operations |
Password Synchronization displays trended statistics for password synchronization efforts. This scorecard presents metrics results for number of registered users, percentage of synchronized accounts, and password reset requests. |
|
|
Operations |
Provision Requests Completed Within Policy assesses how well the organization adheres to access control policies relating to account provisioning process risk. |
|
|
Operations |
Provision Ticket Close Time presents trended metrics results for account provision overall process time. This scorecard displays the mean number of days required to provision a new account. |
|
|
Operations |
This scorecard examines the ability of the organization to ensure secure logins. It examines the distribution of failed and successful login attempts, so that the organization can determine if user-authentication controls are too restrictive, if there have been unauthorized access attempts, and if users have been diligent in safeguarding their sessions. |
|
|
Operations |
Support Activity Statistics displays trended statistics for identity and access support ticket management. This scorecard presents metrics results for account request processing time, and support activity compared to policy standards. |
|
|
Operations |
User Account Statistics displays trended statistics for user account management activity. This scorecard presents metrics results for percentage of active accounts, average time to account expiration, and the percentage of idle and perpetual accounts. |
|
|
Operations |
Volume of Active Accounts displays trended statistics for user account management activity. This scorecard presents metric results for percentage of active accounts. |