Skip to content

Identity Governance

What is Identity Governance?

The policies and processes that manage and control user identities, access rights, and entitlements across the organisation. Identity governance includes access certifications, segregation of duties enforcement, and role management.

Information Security

Each of these is named in at least one of the same controls as identity governance. The number is how many controls name both.

What the standards actually require on identity governance

Requirements naming identity governance across 5 standards, quoted from the control text.

Where the primary driver is identity rather than network topology, deploy zero trust using an enhanced identity governance approach. Access is granted based on identity, device, and attribute assertions, with the network providing limited reachability only.

SP800-207-4.1 · Enhanced Identity Governance Deployment

Least privilege, MFA, identity governance, and data loss prevention across critical systems.

FFIEC-CAT-CC-2 · Cybersecurity Controls - Access and Data Management
HKMA TM-G-11 control

HKMA TM-G-1 Information Security Programme. Comprehensive technical + administrative + physical security controls. (1) INFORMATION SECURITY PROGRAMME (TM-G-1.6.1) - documented + Board-approved information security programme + governance + roles + ISMS-style al...

HKMA-TMG1-InfoSec-Access-PAM-Network-Crypto-DLP-Endpoint · TM-G-1 Information Security Programme + Access + PAM + Network + Crypto + DLP + Vulnerability + Endpoint

Architect ISCM technology stack per Section 3.3 + 3.4 including: SIEM (Splunk + QRadar + Elastic Security + Sentinel + Chronicle + Sumo Logic) + EDR/XDR (CrowdStrike + SentinelOne + Microsoft Defender + Palo Alto Cortex) + vulnerability scanners (Tenable + Qua...

NISTSP137-3 · ISCM Technical Architecture and Automation

Questions people ask about identity governance

What is Identity Governance?
The policies and processes that manage and control user identities, access rights, and entitlements across the organisation. Identity governance includes access certifications, segregation of duties enforcement, and role management.
Why is Identity Governance important for compliance?
Identity Governance is a key concept in Information Security. Understanding identity governance helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Identity Governance?
Identity Governance appears in the requirement text of NIST SP 800-207, FFIEC Cybersecurity Assessment Tool (CAT), HKMA TM-G-1, ISMAP (Japan), NIST SP 800-137. Across these standards we have identified 5 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Identity Governance?
Explore our compliance framework pages to see how identity governance applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Identity Governance applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.