How can you secure the access of an employee working remotely on an unmanaged device, who has access to your internal resources? With remote employees reaching applications located inside the company’s network, the usual security offered by that internal network — firewall, VPN — is no longer sufficient. How can you simultaneously secure access to applications for a group of employees whose rights have been suddenly altered by a significant change in context? And how does the OrBAC model help?
These employees need to receive their new rights and access quickly, they should no longer retain their old access, and it must happen within an extremely short time frame, because the situation demands a high level of responsiveness.
The main IAM challenge: granting access to the right person at the right time
Effective management of identities and digital rights protects against a wide range of use cases, all while maintaining strict security. The key challenge is ensuring the right person has the right access at the right time. Nothing more, nothing less.
That is one of the two major challenges of IAM (Identity and Access Management): granting the right access at the right time to the right person — identity management — by managing their lifecycle, and handling their authentication — access management — by verifying their identity when they present themselves at the access portal, using credentials, multi-factor mechanisms such as biometrics, or a federation mechanism.
Gartner positions IAM as the new perimeter of security. This perimeter must now be managed at a logical level: at the level of the people and the applications they use, in a much more detailed and granular way, both in space and in time. Identity and access management is thus the first link in the Zero Trust security chain. Before individuals access your network — which has become much more open with remote work and the rise of the cloud — and even before they authenticate, you take control of what they can reach. That allows you to respond calmly to exceptional events: you modify access rights in an organised and rigorous way, because you have a complete grasp of the perimeter the affected users have access to.
This is the strength of an IAM software product or cloud service, which allows you to:
- Track the rights granted as well as the origin of those rights. In other words, you track who granted a user access to a particular application. There is no room for uncertainty.
- Define the rights in great detail. You define user groups flexibly, taking into account roles, context, contracts and so on. You use the filters that suit your needs, set the access rules, and provision the granted rights in the applications.
So a head of department has access to their department’s applications and not those of another department. Within a given application, the user can access resources inside their designated scope: a sales representative may see deals in the region assigned to them, but not in other regions.
This is possible because advanced IAM solutions let you define each user’s roles, structure and context, and determine access rights from authorisation rules. That is what we will explore next.
The OrBAC model: simplified and secure identity management
Defining roles
Take the role of a nurse. Assume that all nurses have access to a software system for daily patient visit tracking. Nurses retain that same right whether they move from cardiology to the emergency department: their role does not change, regardless of the organisation. This method of assigning rights is the RBAC — Role-Based Access Control — model.
Organisation-Based Access Control (OrBAC)
In an OrBAC model, the organisation’s structure is defined and plays a key role in determining access rights.
An administrator can easily account for the fact that a cardiology nurse at Hospital 1 does not necessarily have the same access rights as a cardiology nurse at Hospital 2, even though both hospitals are part of the same group.
The administrator can also treat a cardiology nurse as holding a nursing role and having specific access to cardiology applications. So when the nurse moves to oncology, they retain the rights tied to the nursing role — access to the daily patient visit tracking application — lose the rights related to their original department, and gain the rights related to the new one.
The strength of an OrBAC-based solution is that the administrator does not need to define two separate roles, one for oncology nurse and one for cardiology nurse, as would be required with an IAM solution based solely on RBAC. In OrBAC the administrator defines the role of nurse, and attaches the access rights for cardiology applications to the cardiology department. Those applications are then accessible to everyone in that department.
This level of efficiency allows administrators to assign rights easily. When opening a new department or service, the administrator can distribute rights rigorously without having to create a large number of roles, which is error-prone.
Defining context
The concept of context enables rights to be adjusted according to the circumstances.
When a hospital switches to emergency mode, or a community enters a heightened security situation such as a terrorist threat, access rights are adjusted to the context and may not exactly match the usual ones. Thanks to this, rights continue to be managed rigorously.
Defining authorisation rules
Once all the previous steps are complete, the administrator assigns each identity a role, a structure, an organisation and authorisation rules. After calculating the rights, an access model is generated. A person may, for example, be a general nurse at Hospital 1 and a general nurse at Hospital 2 within the same hospital group.
IAM products based on the OrBAC model, such as CyberElements, enable highly agile management of rights and authorisations, allowing you to significantly enhance the security of your information system while providing a transparent experience for the end user, who also benefits from improved access.
Tags
- Articles
- IGA
- Defence & Critical Infrastructure
- Healthcare
- Industrial & Manufacturing
- Public Sector
- Financial Services
Check other relevant resources

Meurthe-et-Moselle Departmental Council
Delivering a seamless remote working experience for employees.

Hautes-Alpes Departmental Fire and Rescue Service
Securing and simplifying volunteer firefighters’ access to operational applications.

Bièvre Isère Regional Authority
Bièvre Isère authority chose cyberelements to streamline employee integration and enable staff to be fully operational on their first day.
View All
