The report proposes a practical set of Key Risk Indicators (KRIs) and supporting Key Performance Indicators (KPIs) for Access Governance, designed to be easy to measure and to provide a fast, management-friendly view of how access-related risks evolve over time. It positions KRIs as a missing complement to traditional KPI scorecards: KPIs show process performance, while KRIs express risk in terms of probability and impact, enabling “management by risk” and “management by exception.” A central theme is that many modern attacks succeed by abusing apparently legitimate credentials, making abnormal behavior in real user accounts a key early warning signal. Access Governance is therefore framed as both a cyber-risk control (reducing theft, fraud, ransomware-driven subversion) and a compliance mechanism that also produces evidence for auditors, including privacy regimes affecting PII and even customer identity contexts (CIAM).
The KRIs/KPIs are organized across four domains: classification of applications and information; identity lifecycle management; access management (authentication plus allocation/review, including roles, entitlements, attestation, and segregation of duties); and identity/access monitoring. Each indicator includes a target “direction,” associated risk categories (security, operational, cost, performance, efficiency, availability, compliance), and optimization actions. Examples include increasing data classification toward full coverage, minimizing orphan accounts, reducing multiple digital identities per person, expanding systems governed by centralized lifecycle management (with pragmatic limits), shortening time to provision/deprovision access, advancing delegated administration maturity, increasing central authentication and SSO reach while deploying strong authentication, and improving federation support—especially for cloud services.
Implementation guidance emphasizes starting lean without major restructuring: define targets, metrics and thresholds, responsibilities, and control actions; then establish collection, aggregation, reporting, alerting, escalation, and auditing routines. A KRI scorecard should track current value, change, direction, and a red/yellow/green status to inform IT and corporate decision-making and investment.
See All Locations
See All Locations