YouTube recording: http://www.youtube.com/watch?v=BS2n3A3B4lQ If IT empowers users to take on risks beyond corporate policy limits, the bank may have to pick up the bill. This is the reason multi-factor authorization is becoming increasingly popular in the financial services industries. It enables deployment of new services subject to strict enforcement of corporate policies. If you can define exactly who is authorized to do what, why, where, when, and how, your risk assessments can have an immediate impact on access control. Based on customer experiences, we discuss business values achieved from externalizing authorization in the financial industries. Enabling more precise control over financial transactions in trading applications or consolidating and streamlining controls across multiple channels - the use cases differ but externalized authorization is the common denominator. The webinar covers topics such as: Drivers for externalized authorization Experiences of customers Benefits achieved

PresenterGerry Gebel, President, Axiomatics America

Externalized Authorization – overview Security and compliance requirements evolving

Complex authorization requirements

“Internal controls” with a new meaning – avoiding penalties

New models for mature risk management and governance

Examples: Simplifying complex infrastructures

Maintaining existing applications drives up costs

Managing access across multiple channels

One application version per region vs. external policy definition

Conclusions – business values in the financial services

New opportunities, security/compliance, cost reductions)

Externalized authorizationBasic concepts

Axiomatics solution benefits

Secure access to sensitive information without sacrificing business agility

Execute business transactions with risk-aware controls

Provide accurate identity authorization governance

Enable secure information sharing across your value chain

Improve regulatory compliance readiness

Facilitate efficient software development

Axiomatics technology solutions – issues addressed







Axiomatics technology solutions – what we do







Authorization for applications:

Axiomatics Policy Server (APS)

Authorization for data storage:

Axiomatics Data Access Filter (ADAF)

Policy enforcement in complex infrastructures

External partiesPartners


AssistedBranch Agent

End-user self service

External providers

Visa MasterCard

State agencies

Internal usersBusiness units

Connected systems

Business intelligence

Content managementDatabases

IntegrationETL – Data virtualization

Bus – Gateway - Bus

Transaction processing

Industry trend toward externalized authorization

“By 2020, 70% of organizations will be implementing ABAC for authorization” Felix Gaehtgens, Gartner, November 2013

Internal controls changingEvolving security and compliance requirements

Risk of business loss and cost of penalties

Standard 2110: GovernanceStandard 2120: RiskStandard 2130: Control process

NYSE Listing Rules 2003 Internal audit requirements

Sarbanes Oxley

Observed Developments in the Last 25 Years...

Audit efficiency: re-performance

New focus on control frameworks

COSO Internal Control –

Integrated Framework

New focus on controls in operations for ongoing compliance & internal control over financial reporting

New focus on risk and governance

New compliance pressures: avoiding severe penalties

EU Data Protection Regulation and Directive 2014:severe fines, the right to be forgotten, notification mandates, audits

Conventional authorization management




Inefficient identity authorization governance

Policies reflect different domains / concerns Regulatory compliance

Risk mitigation

Business process-specific or application-specific concerns

Combined they entail a 360° view

Policies for different domains of concerns

Legal requirements / Third-party obligations

Policies matching regulations / contractual obligations


Risk mitigating policies

Application-specific concerns

Application controls

From reactive to pro-active risk management

Authorization embedded in risk-management


Three lines of defense model

Policy Enforcement Policy Management Policy Analysis

Examples• Designing applications for risk-awareness and change• Simplifying complex infrastructures

Why externalize authorization – answers from a bank

Why externalize –Forrester/Microsoft study

Compliance with complex policy provisions urgent Access policies change after software was deployed –

hard coding authorization is not acceptable

Multiple application versions drive up costs

Current situation Access controls are hard coded in the application

Multiple versions of an application must be deployed per region

Results Drives up operational costs

Slow to implement changes

Lack of consistency in access control

Goal state Manage access policies centrally

Deploy one version of the application

Privacy concerns take center stage

“Brussels, 25 January 2012 – The European Commission has today proposed a comprehensive reform of the EU's 1995 data protection rules to strengthen online privacy rights and boost Europe's digital economy.”

New Regulation (replacing Directive 95/46/EC) “General Data Protection Regulation”

New Directive (replacing Framework Decision 2008/977/JHA)

Banks grant access via multiple channels

Branch Backend Layer

TreasuryLendingCard mgmt

Finance/ Trade CorporateTradingRetail


Branch Backend Layer

The multi-channel challenge

Mobile Tablet PC POS InternetKioskATM

TreasuryLendingCard mgmt

Finance/ Trade CorporateTradingRetail

Enterprise Service Bus layer

Multi-channel services layersCentralized Policy Enforcement

BYOD and Mobile Banking

Banks want the flexibility to Change application flows according to device type and access


Distinguish between registered and unmanaged devices

Incorporating risk analytics in proactive, instead of reactive mode Utilize device type, user behavior and other risk scores during

the authorization process



