Skip to content

Commit

Permalink
Update playbook-ilm.md
Browse files Browse the repository at this point in the history
Add use case from issues #591 above Summary section
  • Loading branch information
claytonjbarnette authored Aug 26, 2022
1 parent 4574156 commit 2f0269c
Showing 1 changed file with 4 additions and 2 deletions.
6 changes: 4 additions & 2 deletions _playbooks/playbook-ilm.md
Original file line number Diff line number Diff line change
Expand Up @@ -264,7 +264,7 @@ An agency can further realize the benefit of ILM by integrating the master user

<p align="center"><b>Figure 5: ILM Integration with Single Sign-On</b></p>

<img src="{{site.baseurl}}/assets/playbooks/ilm-sso-integration.png" alt="Diagram demonstrating an agency use case to integrate a MUR with agency single sign-on to help federate access to other agency applications." style="width:800px;" >
<img src="{{site.baseurl}}/assets/playbooks/ilm-sso-integration.png" alt="Diagram demonstrating an agency use case to integrate a MUR with agency single sign-on to help federate access to other agency applications." style="width:800px;">

The following is an example of the benefits of a master user record and integration with an access management tool for a cross-agency federation use case.

Expand All @@ -288,6 +288,8 @@ Make attributes available for authorization decisions. Federation is not only ac
</div>
</div>

**Detailee use case** - An Agency A employee is detailed to Agency B. How can Agency B use their ILM system for this existing Agency A employee, but short-term Agency B employee. Can Agency A share HR data to do birth-right provisioning in Agency B? I think the corpus of this use case is how Agency B can provision Agency A employee without issuing them an Agency A piv card and an Agency A email.

## Summary

The ILM playbook outlined an identity lifecycle process and four steps to create a master user record and lifecycle process within your agency. ILM is the evolution of an identity from creation to deactivation. There are specific steps within each lifecycle phase of the joiner-mover-leaver process. A master user record is the core of ILM and acts as an aggregation point of identity data for all agency users. A master user record integrated with access management tools provides a foundation for more mature ICAM processes.
Expand Down Expand Up @@ -320,4 +322,4 @@ The ILM playbook outlined an identity lifecycle process and four steps to create
1. [Department of Defense ICAM Reference Design](https://dodcio.defense.gov/Portals/0/Documents/Cyber/DoD_Enterprise_ICAM_Reference_Design.pdf){:target="_blank"}{:rel="noopener noreferrer"}
2. [DHS CDM Max.gov Page](https://community.max.gov/download/attachments/1843519190/CDM-ARCH-2017-01.1.1-MUR-FUNCT-DESCR%2012082017.pdf?version=1&modificationDate=1568732697362&api=v2){:target="_blank"}{:rel="noopener noreferrer"}
3. [IDPro Body of Knowledge - An Overview of Digital Identity Lifecycle](https://bok.idpro.org/article/id/31/){:target="_blank"}{:rel="noopener noreferrer"}
4. [System for Cross-domain Identity Management (SCIM)](http://www.simplecloud.info/){:target="_blank"}{:rel="noopener noreferrer"}
4. [System for Cross-domain Identity Management (SCIM)](http://www.simplecloud.info/){:target="_blank"}{:rel="noopener noreferrer"}

0 comments on commit 2f0269c

Please sign in to comment.