IAM in Practice: Where Identity Management Falls Short
研究显示多数组织的身份识别与访问管理(IAM)平台成熟度处于中等水平。仅50%认为其平台有效管理用户访问配置,46%对认证和授权持同样看法。机器身份管理、访问审查自动化及特权访问控制等方面存在显著差距。技术采用方面进展缓慢,多数仍在规划向云或SaaS迁移。 2025-8-25 10:32:0 Author: www.guidepointsecurity.com(查看原文) 阅读量:7 收藏

How confident are you in your IAM platform? According to new research, most organizations are stuck at the maturity midpoint.

In a recent study by Ponemon Institute and GuidePoint Security, only 50% of organizations rated their IAM platform as “very or highly effective” at managing user access provisioning. Just 46% said the same for authentication and authorization.

Key process areas continue to lag:

  • Machine and non-human identities: Only 28% manage these using policy-driven, IAM-integrated approaches.
  • Access reviews: 34% still rely on spreadsheets. Only 17% have automated this process through identity governance platforms.
  • Privileged access: 43% of organizations assign elevated permissions to a primary account permanently — a major risk vector. Even worse, 40% say privileged passwords are managed solely by the account owner.

There’s also a gap in technology adoption. While 39% of organizations have refreshed their IAM platforms to cloud or SaaS-based models, the majority are still planning a transition — some as far as four years out.

Organizations are also falling short in deprovisioning non-human identities, with 40% still handling the process manually — a critical blind spot given the rise of automation and service accounts.

If your IAM platform feels like a patchwork of manual processes and limited oversight, you’re not alone — but you are at risk.

Download the full report to learn how to move beyond basic IAM and build a future-ready identity security program.


Laura Babbili

Integrated Marketing Campaigns Manager,
GuidePoint Security

Laura Babbili is a cybersecurity marketer with a background leading integrated marketing campaigns that engage technical audiences and drive business impact. She has held roles at global companies including TikTok, Cisco, and IBM, where she developed and executed strategies around small business, cloud security, and IT infrastructure, respectively. She holds a bachelor’s degree in Journalism from the University of Northampton in the United Kingdom and is now based in Austin, Texas, where she lives with her husband, daughter, and dog.


文章来源: https://www.guidepointsecurity.com/blog/iam-in-practice-where-identity-management-falls-short/
如有侵权请联系:admin#unsafe.sh