Identity Governance
What is Identity Governance?
The policies and processes that manage and control user identities, access rights, and entitlements across the organisation. Identity governance includes access certifications, segregation of duties enforcement, and role management.
Terms that appear alongside identity governance
Each of these is named in at least one of the same controls as identity governance. The number is how many controls name both.
- governance 4 shared controls
- zero trust 2 shared controls
- least privilege 2 shared controls
Frameworks that govern identity governance
What the standards actually require on identity governance
Requirements naming identity governance across 5 standards, quoted from the control text.
Where the primary driver is identity rather than network topology, deploy zero trust using an enhanced identity governance approach. Access is granted based on identity, device, and attribute assertions, with the network providing limited reachability only.
SP800-207-4.1 · Enhanced Identity Governance Deployment →Least privilege, MFA, identity governance, and data loss prevention across critical systems.
FFIEC-CAT-CC-2 · Cybersecurity Controls - Access and Data Management →HKMA TM-G-1 Information Security Programme. Comprehensive technical + administrative + physical security controls. (1) INFORMATION SECURITY PROGRAMME (TM-G-1.6.1) - documented + Board-approved information security programme + governance + roles + ISMS-style al...
HKMA-TMG1-InfoSec-Access-PAM-Network-Crypto-DLP-Endpoint · TM-G-1 Information Security Programme + Access + PAM + Network + Crypto + DLP + Vulnerability + Endpoint →ISMAP Identity and Access Management requires comprehensive IAM controls covering customer + CSP + administrative + service-to-service identities.
ISMAP-Identity-Access-MFA-Privileged-Federation-SSO-API-Tokens-CloudIAM-PIV-PASETO · ISMAP Identity and Access Management - Cloud IAM + Multi-Factor Authentication + Privileged Access + Federation/SSO + API Security + Access Tokens + My Number Card Integration + Government IAM →Architect ISCM technology stack per Section 3.3 + 3.4 including: SIEM (Splunk + QRadar + Elastic Security + Sentinel + Chronicle + Sumo Logic) + EDR/XDR (CrowdStrike + SentinelOne + Microsoft Defender + Palo Alto Cortex) + vulnerability scanners (Tenable + Qua...
NISTSP137-3 · ISCM Technical Architecture and Automation →Questions people ask about identity governance
What is Identity Governance?
Why is Identity Governance important for compliance?
Which compliance frameworks address Identity Governance?
Where can I learn more about Identity Governance?
See how Identity Governance applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.