The global skills and competency framework for the digital world

#1473 Establishment of the Skill Identity and Access Management change request pending

In our SFIA Assessments in serveral organizations, we lacked a way to adequately represent the topic of Identity and Access Management. We find IAM partially in the SCAD, but this leads to a mixing of security operations and IAM, which can result in incorrect / incomplete reports and conclusions. We suggest an dedicated Identity and Access Management Skill.

In our SFIA Assessments in serveral organizations, we lacked a way to adequately represent the topic of Identity and Access Management. We find IAM partially in the SCAD, but this leads to a mixing of security operations and IAM, which can result in incorrect / incomplete reports and conclusions. We suggest an dedicated Identity and Access Management Skill. The skill could include tasks like:

  • Creating, updating and deleting user accounts
  • Establishing and updating (automated) access controll and procedures, policies and rules
  • Establishing and updating (automated) role allocation and procedures, policies and rules
  • Establishing Monitoring, Audits and Logging
  • Establishing Single Sign On
  • Establishing Multi-Factor Authentification
  • Identity Life Cycle management
  • Operation and Maintanence of IAM Tools and Self Service portals

The level advancements could be based on the scope (for one, serverall or all IT-Systems in an organization) and responsibilities (e.g. assisting, suggesting, deciding).

After Level 4 you could add further tasks like

  • Responsibility for the overall integration in the whole IT Landscape
  • Responsibility for overall Compliance (e.g. EU GDPR)

Proposed change applies to Security operations

Current status of this request: pending

Matthew Burrows
Sep 28, 2023 11:18 AM

I agree that we should split this out, with one skill for Security operations (SCAD) and a separate skill for Identify and access management. In some organisations these activities are done by the same people, but not all - so they need to be separated in SFIA.

Hannah Ryan
Jan 04, 2024 04:51 AM

I have had similar experiences with the lack of a dedicated IAM skill. Stakeholders have opted to add in 2-4 other skills to 'cover' what would be defined in a dedicated skill for IAM. In favour of this addition.