implementation quetionaries
implementation quetionaries
Project Details
Business / Timelines
This section details requirements and discussion points around how the
project is run and its purpose.
What are high-level requirements you are trying to achieve with the
implementation?
What are different groups within the business that might interract with
the system? If so, for what? And whom? e.g. Managers, Security,
Auditors, Help Desk, etc.
Testing
o Unit Testing
o Functional Testing
o Integration Testing
o Penetration Testing
Architecture / Infrastructure
o Normal Deployment
o Proxy
o Secure Tunnel
VA placement:
Ownership:
Sources / Integrations
What are your Authoritative Source(s)? Or said another way, what are
the data sources that contain your identity information?
o Typically this is some sort Human Resources (HR) system, but
could be others.
In general, about how many accounts are on this system? How many
accesses / entitlements?
o Business Owners
o Technical Owners
o Other?
o Is it manual?
o Read / Aggregations?
o Creating accounts?
o Password management?
o Are there any Service Level Agreements (SLAs) you have with
the business? How rigid are these?
What information may tie an account back to its owning identity? (i.e.
correlation data)
How do you structure your account data? What does an ideal account
look like? What are the data mappings?
Identity Model
o SAML
For each identity, are there specific information / attributes you want to
collect?
o Spreadsheet of these?
What should we use for first and last name? The legal name? Or
preferred name? e.g. Robert Smith vs Bob Smith
o Leaver / Disable
o Rehires?
o Transfers?
IdentityNow Features
In this section, we should validate the features they have purchased, and
which they want to implement. This will determine which specific feature
requirements we discuss in next sections. Only go through specific sections
as needed, or required.
Do you have any specific order or priority of features you would like to
implement in a certain order?
Provisioning
When is someone first given access? X days before start? On the day
they start? As needed?
o Enable of accounts?
o Disable of accounts?
o Send emails?
o Grant access?
o Remove access?
Are there any simple packages or patterns of access that you can
easily grant?
Are there specific attributes that you want to enforce across the
sources?
Access Request
This section will detail requirements around access request. Most of the time
this is a supplement to provisioning (above). This can sometimes be a longer
conversation than the questions here, depending on their expectations, and
needs. It is a good idea to document as much as you can.
Request process
Requestable items
Approval Processes
Are there any other access request requirements that haven't been
covered so far?
Certifications
o Manager
o Source Owner
o Entitlement Owner
o Other?
Entitlement Descriptions? Do you have these? Can you get them? Are
they already part of group description?
Reporting
Password Management
o KBA - What the questions that you need? How many? Do these
need to be multi-lingual?
o Integrations
Duo
RSA
Symantec
SafeNet
Branding
Do you have specific colors or logos we can use with the product?