Customer CaseHow HR player Liantis took control of user access in daysDownload →
Guide

KPI-Driven Approach to Identity & Access Management

Everything you need to start using KPIs to measure and improve IAM effectiveness in your organisation.

Guide — KPI-Driven Approach to IAM

Download the Full PDF

The metrics that move the needle on your identity programme.

Identifying IAM inefficiencies and gaps remains a challenge for organisations with numerous applications and valuable data. This guide walks you through a comprehensive set of KPIs that have proven to be applicable to the majority of organisations striving for risk reduction and improvement of process and data quality.

✅ 8 essential KPI categories
✅ Based on the ISO 27001 framework
✅ Increasing IAM effectiveness

Why KPIs Matter for IAM

Over the past decades, many organisations have introduced proper IAM to securely manage their ever-increasing digital identities and their accesses. Still today, new challenges emerge and new layers are added. IAM systems should evolve accordingly.

KPIs in themselves are just KPIs. IAM effectiveness can only be improved if those KPIs are actually used to drive decisions, actions, and their prioritisation. The proposed closed-loop model — measure, report, act — enables exactly that.

The Right Choice of KPIs

Which KPIs are relevant is derived from the overall IAM goals. In many organisations the main goal — or combination of goals — of IAM can differ. In strongly regulated organisations, regulatory compliance is an obvious driver. For others, reducing security risk or improving operational efficiency may take priority.

Once the goal(s) are determined, ask: "Which questions define the goal(s) more precisely?" The relevant metrics are then the answers to those questions. By following this approach, KPIs will be aligned with the IAM strategy and contribute to the accomplishment of the goal(s).

The choice of KPIs is not set in stone. Strategies develop, more information becomes available, and regulations change. Revisit your KPI set regularly.

IAM KPI goals framework

The 8 Key KPI Categories

1. Roles

What is the relation between the number of roles and users in your organisation? A rule of thumb: the total number of roles should be no more than 10% of the total number of users. In many organisations without proper role management this percentage is greatly exceeded.

2. Privileged Accounts

It is important to know how many and what kind of privileged accounts exist in the organisation. Consider standard admin accounts, service accounts, accounts with domain-level access, accounts shared among multiple people, and accounts that have never been used.

3. Excessive Permissions

One of the most important principles in information security is the principle of least privilege. A rule of thumb: a user can be identified as having excessive permissions when their total number of roles or permissions exceeds twice the average. The attack surface of your organisation is the sum of all cumulated access rights — keep it as small as possible.

4. Separation of Duties

Separation of duties is considered one of the most difficult identity controls to implement properly. The objective is to disseminate tasks and associated permissions among multiple people to avoid fraud. Key metrics include the number of detected conflicts and the percentage of conflicts that have been remediated or mitigated.

5. User Hygiene

A well-maintained IT environment is better protected against security risks. User hygiene metrics include: number of inactive accounts, accounts without an assigned manager, accounts without a last login date, and accounts not correlated to an HR record.

6. Role Hygiene

Role hygiene metrics include: number of empty roles (with zero members), number of roles without an assigned owner, number of duplicate or overlapping roles, and number of roles not used in the past 90 days.

7. Entitlement Hygiene

Beyond users and roles, entitlement hygiene tracks the health of individual permissions and access rights — ensuring they are still in use, correctly assigned, and have an accountable owner.

8. Data Quality

In order to get accurate results from all of the controls above, it is crucial that all relevant data attributes are entered correctly. KPIs will only reflect the actual state if the data in the IAM system is accurate, complete, and consistent.

ISO 27001 based identity KPI wheel

Using KPIs to Drive Action

KPIs in itself are just KPIs. IAM effectiveness can only be improved if those KPIs are actually used to drive decisions, actions, and their prioritisation. The closed-loop model consists of three steps:

  • Measure: Collect and baseline your identity KPIs across all connected systems
  • Report: Present KPI trends to management and IAM teams to provide context
  • Act: Use the KPIs to prioritise clean-up projects, process improvements, and investments

Once actions are taken, this will be reflected in the KPIs. Tracking progress enables you to evaluate the success of a certain activity in improving IAM effectiveness, and provides knowledge that allows for better prioritisation of future efforts.

KPI closed-loop model for IAM

Key Takeaways

  • All organisations benefit from a metrics-based approach to IAM
  • Choose KPIs that align with your specific IAM goals and regulatory context
  • Combine KPI measurement with clear reporting and actionable clean-up projects
  • Revisit and update your KPI set as your organisation and regulations evolve
  • Maximise the value of your existing IAM system by knowing where you are, where you are going, and where you want to be
Talk to us

Ready to apply this to your environment?

Book a 20-minute call with our team — we'll walk you through Elimity Insights on your own scenarios. No pressure.