#329 - Discovering Effective User Access Reviews with Stephen Washington

#329 - Discovering Effective User Access Reviews with Stephen Washington

In this episode of the Identity at the Center podcast, hosts Jeff and Jim discuss the vital role of user access reviews, device identity, and the evolving landscape of Identity Access Management (IAM) with guest Stephen Washington, Head of IAM at Discover Financial. The conversation delves into regulatory compliance, the use of AI in IAM, and practical steps for improving user access certifications. They also explore the importance of managing service accounts, innovations in IGA, and the role of identity in modern cybersecurity frameworks. The episode wraps up on a lighter note with a chat about fitness challenges like Tough Mudder and personal cheese preferences for grilled cheese sandwiches.


Chapters

00:00 Introduction to Regulatory Compliance in Financial Services 01:54 Welcome to the Identity at the Center Podcast 02:07 Exploring Device Identity 03:19 The Role of Identity in Modern Security 06:44 Engaging with the IAM Community 10:31 Upcoming Conferences and Events 13:58 Interview with Stephen Washington 25:36 The Importance of User Access Reviews 33:55 Backend Changes in IGA Systems 35:04 The Concept of Identity Data Lake 36:37 AI and Identity Fatigue 37:22 Importance of Identity Hygiene 38:32 Challenges with Access Reviews 39:42 Regulatory Compliance and Policy Changes 41:06 Advice for Practitioners on Access Reviews 45:47 NYDFS and User Access Reviews 47:41 The Role of NIST Cybersecurity Framework 52:35 Training Auditors and Policy-Based Access Control 57:38 Fitness and Stress Relief 01:05:38 Grilled Cheese and Final Thoughts


Connect with Stephen: https://www.linkedin.com/in/stephen-washington-jr-5569b57/


Gartner IAM Summit - Code IDAC425 saves 425€: https://www.gartner.com/en/conferences/emea/identity-access-management-uk

European Identity and Cloud Conference 2025 - Use code idac25mko for 25% off: https://www.kuppingercole.com/events/eic2025?ref=partneridac

Identiverse 2025 - Use code IDV25-IDAC25 for 25% off: https://identiverse.com/


Connect with us on LinkedIn:

Jim McDonald: https://www.linkedin.com/in/jimmcdonaldpmp/

Jeff Steadman: https://www.linkedin.com/in/jeffsteadman/

Visit the show on the web at http://idacpodcast.com

Jaksot(393)

Identity At The Center #41 - Server Access Management 101 with Paul

Identity At The Center #41 - Server Access Management 101 with Paul

Jim and Jeff talk with Paul Volosen from Centrify about the IAM concepts used to secure server access. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

27 Huhti 202051min

Identity At The Center #40 - IAM ROI

Identity At The Center #40 - IAM ROI

Jim and Jeff talk about how to develop a Return on Investment (ROI) strategy when it comes to IAM. Link to Auth0 Forrester report we discuss: https://auth0.com/forrester-total-economic-impact/ Risk Management Concepts: https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/security-and-risk-management/cissp-risk-management-concepts/ Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

20 Huhti 202039min

Identity At The Center #39 - Digital Transformation and CIAM

Identity At The Center #39 - Digital Transformation and CIAM

Jim and Jeff talk about how consumer/customer IAM (CIAM) is a fundamental part of a digital transformation strategy. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

13 Huhti 202042min

Identity At The Center #38 - Data Privacy Regulations are Dead On Arrival with Richard Bird

Identity At The Center #38 - Data Privacy Regulations are Dead On Arrival with Richard Bird

Jim and Jeff talk with Richard Bird, Chief Customer Information Officer at Ping Identity, about data privacy and why data privacy regulations are dead on arrival. LinkedIn article by Richard: https://www.linkedin.com/pulse/data-privacy-joke-your-town-nation-richard-bird/ Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

6 Huhti 202050min

Identity At The Center #37 - Access Management with Andy

Identity At The Center #37 - Access Management with Andy

Jim and Jeff talk with Andy Clark, Principal Consultant at Okta, about access management including the why's of OIDC and SAML, scopes, and flows. To register for the free virtual Oktane 2020 conference, visit https://www.oktane20.com/ Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

30 Maalis 202036min

Identity At The Center #36 - Assessing CIAM Maturity

Identity At The Center #36 - Assessing CIAM Maturity

Jim and Jeff talk about how assessing CIAM (customer/consumer identity & access management) can be different than an enterprise IAM assessment. Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

23 Maalis 202050min

Identity At The Center #35 - Managing IAM Through A Pandemic

Identity At The Center #35 - Managing IAM Through A Pandemic

Jim and Jeff talk about the current global health situation and things to consider from an IAM perspective. Jeff also finds a way to talk baseball with Jim as it relates to the Houston Astros and their brute force hacking of pitchers and catchers for the last few seasons (allegedly). Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

16 Maalis 202045min

Identity At The Center #34 - Managing IAM Risk with Esteban

Identity At The Center #34 - Managing IAM Risk with Esteban

Jim and Jeff talk with Esteban about the approach he takes in managing IAM risk for his organization. The Institute of Internal Auditors (IIA) Position Paper: The Three Lines Of Defense In Effective Risk Management And Control Want to join the conversation? Leave us a message here: anchor.fm/identity-at-the-center/message or email us at questions@identityatthecenter.com.

9 Maalis 202035min