
Many organizations treat Identity and Access Management (IAM) as a technical installation rather than a set of strategic initiatives/ business programs. They tend to focus solely on the technical aspects of the implementation, such as selecting and deploying the IAM solution, without considering the broader strategic implications of IAM on business outcomes and key value drivers. This approach typically results in a disjointed IAM implementation that does not align with the organization's business objectives or the needs of its users.
Let's look at some of the problems that arise from a technology-centric approach:
Lack of Integration with Business Processes: When an IAM program is not integrated correctly with business processes, it leads to issues such as users not being able to access the resources they need to do their jobs or unnecessary access being granted to resources, which can increase the risk of data breaches.
Inadequate User Experience: When the focus is on the technical aspects of implementation rather than the user experience, users may find it challenging to use the IAM system and may experience delays in getting the access they need, impacting their productivity and satisfaction.
Lack of Alignment with Business Objectives: When IAM is implemented without considering the organization's business objectives, it may not provide the necessary security and access control level. For example, if an organization does not consider its employees' different roles and responsibilities, it may not grant them the appropriate level of secure access to fulfill their roles efficiently.
Poor Risk Management: Organizations that treat IAM as a technical installation may not adequately assess the risks associated with IAM implementation. This can result in deploying IAM systems that do not sufficiently protect the organization's sensitive data, leaving it vulnerable to cyber-attacks.
Planning fallacy: This psychological phenomenon describes humans' tendency to underestimate the time required to complete tasks. Specifically, we are often overly optimistic when setting deadlines, planning budgets, estimating costs, and identifying risks for a project viewed as just a technical installation. This optimism can lead to underestimated project timelines and resources, further complicating IAM implementation.
Poor Resource Management: Inefficient resource management, which can result from a techno-centric approach, leads to increased project costs and declining employee performance. Over-allocating tasks to team members can lead to burnout and higher turnover rates, while under-allocating resources may increase project costs and necessitate a larger workforce than necessary.
Concurrent Engineering (CE) is a project management and product development approach emphasizing parallel processes, collaboration, and integration across different teams and phases. Although CE and Identity and Access Management (IAM) are distinct concepts, there is potential to leverage the benefits of CE in IAM implementations and achieve better overall outcomes. We can apply the CE principles in the following ways:

Simultaneous Processes: Rather than treating IAM as a technical installation, the CE approach views IAM implementation as a set of cross-functional initiatives. Different teams—such as IT, security, HR, legal, compliance, and other business units—collaborate in parallel to identify IAM requirements and develop the IAM system. Specific IAM initiatives can progress simultaneously; for example, Onboarding and Self-Service Password Resets might be active at different stages of their development lifecycles.
Collaboration and Communication: CE facilitates collaboration and communication among different teams and stakeholders, ensuring that the IAM system meets the needs of all involved.
Early Concept Development: IAM implementation using CE promotes the early development of IAM concepts, such as identifying business opportunities, user requirements, user roles, and access controls. One advantage of CE is that it enables organizations to identify initiatives early in the program development, whether managed internally or guided by consultants. This allows organizations to leverage external expertise while building and maturing internal skills.
Integration: IAM involves a complex set of integrated systems and processes. Taking the time to determine the best use of integration to manage and control this complexity is essential given the different components and business processes, such as user provisioning, authentication, authorization, and auditing. By using CE, different teams work together to ensure that the various components and capabilities of the IAM system fit together seamlessly and that the IAM system is designed to meet the needs of the end-users by shifting complexity into the system and away from the user experience as much as possible.
Iterative Design: During IAM implementation, the iterative design approach used in CE helps align the scope with each initiative's key objectives, with each iteration building on the previous one. Different teams collaborate to develop multiple design iterations of the IAM system, incorporating feedback from stakeholders in each iteration. This process ensures that the design evolves more effectively, reduces risks, and aligns more closely with user needs while maturing the IAM program at a manageable rate.
Continuous Improvement: A successful IAM program using Concurrent Engineering will leverage continuous improvement across initiatives, building on iterative design efforts. Different teams work together to identify areas for enhancement and implement changes or upgrades that improve the quality and efficiency of the IAM system. This ongoing process uses insights gained from each iteration to continuously refine and optimize the system.
Risk Management: IAM implementation should involve effective risk management. In a CE approach, teams periodically assess the risks associated with IAM deployment and implement strategies to mitigate those risks. This helps ensure that the IAM system protects the organization's sensitive data and reduces the risk of data breaches.
Flexibility: The CE approach allows IAM implementation to remain flexible and adapt to changing business needs and requirements. This helps ensure that the IAM system stays adequate and relevant and can evolve alongside the organization.
Building an Identity and Access Management (IAM) program using Concurrent Engineering (CE) principles, combined with Waterfall and Agile methodologies as multiple initiatives, offers numerous advantages. CE promotes simultaneous processes across teams like IT, security, HR, legal, and business units, enhancing speed and efficiency through continuous feedback and real-time collaboration. The early and comprehensive concept development ensures a clear understanding of IAM initiatives and requirements, reducing rework and delays by addressing issues early on.
CE emphasizes continuous improvement, effective risk management, and flexibility, involving all teams in ongoing optimization efforts. This proactive approach ensures comprehensive risk coverage and enhances the IAM system's security and reliability. CE's flexibility allows the system to adapt to changing requirements, maintaining its relevance and effectiveness over time. By fostering early development, iterative design, and comprehensive risk management, CE proves to be a superior approach for complex IAM implementations.
Moreover, CE's emphasis on collaboration and communication helps bridge the gap between technical and business perspectives, ensuring that the IAM system meets security standards and aligns with organizational goals. This holistic approach facilitates a more user-centric design, enhancing user adoption and satisfaction. Integrating best practices from Waterfall and Agile methodologies further enables structured progress and adaptive responses to changes, making the IAM program robust and resilient against evolving threats and requirements. CE fosters innovation and agility, positioning the organization to effectively manage identities and access in an increasingly dynamic digital landscape.
Conclusion:
CE's focus on simultaneous processes, early concept development, and iterative design ensures that IAM solutions are developed with a comprehensive understanding of business needs and user requirements. This approach enhances cross-functional collaboration, streamlines integration, and promotes continuous improvement, leading to a more secure and effective IAM system. By leveraging Concurrent Engineering (CE) principles, organizations can transform their Identity and Access Management (IAM) initiatives into a cohesive, strategic business program.
For expert guidance in navigating this complex landscape and implementing a robust IAM system, contact Idenhaus Consulting today.