Building the Enterprise Identity Operating Model: A Framework for Identity Governance, Architecture, and Risk
暫譯: 建立企業身分識別營運模型:身分識別治理、架構與風險管理框架
Masserini, John J.
商品描述
- Gain an understanding of the criticality of identity management and the role it plays across both employee and consumer risk mitigation strategies Know what an Identity Warehouse is, how it benefits the enterprise, and successful deployment strategies Understand how modern identity protocols are driving both interoperability and risk visibility across the entire ecosystem Communicate the overall business value of a centralized identity ecosystem, and how it drives new business features, empowers users, and reduces overall enterprise risk
Who This Book Is For
CISOs, as well intermediate to advanced cybersecurity architects or strategists
商品描述(中文翻譯)
在高度互聯、以雲端優先(cloud-first)為核心的運作環境中,身分識別(identity)已成為企業安全的主要控制平面(control plane)。然而,在許多組織中,身分識別仍然彼此分散、治理標準不一致,且需要大量的營運投入。本書重新定位身分識別的角色:它不再只是單一的存取管理功能,而是一套支撐企業風險管理、法規遵循與數位營運的系統性規範,涵蓋員工、合作夥伴、客戶及第三方生態系。其目標並非進行漸進式改善,而是重新調整整體架構:將身分識別定位為一項具備治理、可衡量且可強制執行的企業能力。
《Building the Enterprise Identity Operating Model》挑戰將身分識別視為單純存取權限模型的傳統觀點。相反地,本書將身分識別定義為一項持續評估的風險構造,要求具備集中式可視性、政策協調(policy orchestration)與生命週期控制。此模型的核心概念是 Identity Warehouse,這是一個權威的彙整層,能夠標準化身分資料、支援決定性自動化(deterministic automation),並在完整的身分生命週期中進行即時風險評估。這種方法為大規模環境中的可稽核性、政策一致性與適應性存取強制執行奠定基礎。
本書內容以實務架構為基礎,探討如何設計及實作可擴充的身分識別生態系、與企業控制層整合,以及因應持續演變的法規義務。本書也涵蓋現代環境中的實際營運情況,包括混合式環境、傳統基礎架構、分散式工作團隊與第三方相依性。同樣重要的是,本書將身分治理提升至高階主管層級,因為身分相關風險的責任必須明確歸屬。身分識別失效不再只是孤立的技術事件,而是會造成全企業影響的系統性崩潰。
本書適合負責設計、治理或轉型身分識別能力的身分架構師與資安領導者。無論是建立基礎身分識別計畫,或是重新整頓已成熟的環境,本書都提供一套結構化架構,協助組織將身分識別發展為策略性控制系統,以降低攻擊面、精準執行政策,並讓組織能夠在大規模環境中安全地運作。
您將學到的內容
• 了解身分管理的重要性,以及其在員工與消費者風險降低策略中所扮演的角色
• 了解何謂 Identity Warehouse、它如何為企業帶來效益,以及成功部署的策略
• 了解現代身分識別通訊協定如何推動整個生態系的互通性與風險可視性
• 能夠傳達集中式身分識別生態系的整體商業價值,以及它如何推動新的業務功能、賦能使用者並降低整體企業風險
本書適合哪些讀者
CISO,以及中階至進階的資安架構師或策略規劃人員
作者簡介
John J. Masserini is an accomplished global CISO and trusted board advisor with 30+ years of experience building enterprise security programs from the ground up. He has a proven record of aligning cybersecurity with business strategy across media, financial services, and tech sectors, specializing in heavily regulated industries including fintech, capital markets, and global telecom. John is a renowned expert in integrating cybersecurity strategy with high-velocity digital innovation, M&A, and cloud transformation. He is recognized for building cyber-resilient, audit-ready environments to drive regulatory compliance, an influential leader skilled in risk governance, cyber resilience, digital transformation, and stakeholder communication, and known for building award-winning teams, mentoring future CISOs, and providing exceptional leadership to high-growth firms.
作者簡介(中文翻譯)
John J. Masserini 是一位傑出的全球資訊安全長(CISO)及深受信賴的董事會顧問,擁有超過 30 年從零開始建構企業安全計畫的經驗。他在媒體、金融服務及科技等領域,成功將資安與企業策略相互結合,並專精於金融科技(fintech)、資本市場及全球電信等高度受監管的產業。
John 是將資安策略整合至高速數位創新、併購(M&A)及雲端轉型領域的知名專家。他擅長建構具備網路韌性且符合稽核要求的環境,以推動法規遵循;同時也是一位具影響力的領導者,專精於風險治理、網路韌性、數位轉型及利害關係人溝通。他亦以打造屢獲殊榮的團隊、培育未來的資訊安全長(CISO),以及為高速成長企業提供卓越領導力而聞名。