Questions
The questions for the questionnaire have been devised based on the research gathered throughout the investigation and market research. The answers from the questionnaires will help pull together all the ideas and topics covered by importance and priority from the perspective of IT Security and Audit professionals.
The Questionnaire Responders
The questionnaire responders are made up of the author’s colleagues within the IT Industry. Due to the sensitivity of the information returned details of some of the participants have been kept anonymous.
The Questionnaire - Keys Features for Identity Access Management Tools
Introduction
Thank you for clicking on the link to participate in this online survey. The survey consists of six questions. The purpose of the survey is to ask questions designed to help steer the requirements for a new product positioned within the Identity Access Management (IAM) market space.
The concept is to provide a web based tool that is easy for organisations to use instantly, which offers high quality audit and risk reporting functions typically found in more comprehensive, fully fledged IAM solutions. The tool would focus solely on providing audit and access management reports based on Segregation of Duties (SoD).
To perform this operation quickly without the need for application integration API's or connectors, the tool would operate using custom templates to enable the uploading of flat exported user lists and related privileges for analysis.
The purpose of the tool could be:
Your input as an IT professional is important to help the guide the development on which features you consider important in an IAM reporting tool of this nature.
Question 1
Please state your job role.
Please note at any personal information and company information will stay anonymous. The results of this survey will be published online at https://sites.google.com/site/userguardian1/
Question 2
In your experience of IAM tools please set your priority of the following features (1 highest), based on providing effective access management?
Purpose of the question: Based on the software review forms market research, it would be useful to know which areas/ideas for the system should be developed in more depth, based on how desirable or useful they could be.
Question 3
Please rate the following features in order with business benefit in mind.
Purpose of the question: This question helps put focus around question 1, to discover which features could be linked to the features provided in the first question.
Question 4
Based on your previous experience of IAM tools, do you feel there are any key functionality areas within IAM tools that could be improved to satisfy the demands of the auditors?
Purpose of the question: To discover any additional requirements based on actual experience.
Question 5
The tool could be licensed in two possible ways. It would be useful to know of which you would find most appealing and why?
As an in-house implementation
An annual license charge based on the number of applications and user accounts to be loaded into the tool. All data would remain within the organisation. The tool would allow for unlimited uploads and changes to the imported user data.
As a cloud based tool (SaaS)
Pay-as-you-go (PAYG) licensing model. In this model costs could be tiered towards usage.
The PAYG charging model:
Package
Top package
Lowest package
Description
Unlimited usage, allowing for unlimited applications to be added and data modified at any time at a set annual rate.
Charged per application or number of users and dependent on frequency of usage.
In all charging models, the data/reports will be saved for each audit with free unlimited access to past and present data sets.
Purpose of the question: To work out if a SaaS offering would be a viable charging method or not?
Question 6
Does your current IAM system (if you have one) offer adequate functionality for audit reporting and setting SoD profiles for all your applications? Would a complementary reporting tool be something of interest?
Please select an answer:
Purpose of the question: To determine if there is a market need for the tool.