CUSTOMER SUCCESS STORY Logica Sweden provides secure and compliant cloud services with CA IdentityMinder TM CUSTOMER PROFILE Industry: IT services Company: Logica Sweden Employees: 5,200 (41,000 globally) Revenue: 566 million ( 3,697 million globally) BUSINESS Logica Sweden provides business consultancy and IT outsourcing services that deliver value to customers by helping them integrate people, business and technology. CHALLENGE The company s private cloud services must be secure, compliant and meet customer requirements. Logica Sweden s internally developed identity and access management solution needed a security and reporting upgrade. SOLUTION CA IdentityMinder helps manage employee and customer access privileges for 6,000 physical and virtual servers. The solution s automated processes enable rapid provisioning while its reports aid compliance. BENEFIT Rapid provisioning of access privileges help Logica Sweden to enhance productivity, agility and customer service quality. With greater security and simpler compliance, it will be able to strengthen its cloud-based services. agility made possible
Business Creating value through innovation, collaboration and commitment Logica combines global expertise with local knowledge to help organisations seamlessly integrate people, business and technology. The company provides business consulting, systems integration and outsourcing services in over 40 countries worldwide. The majority of its 41,000 employees are based in Sweden, the UK, France and India. Logica s Swedish operation already has a strong business consultancy division; its primary focus is the delivery and expansion of its outsourcing services, such as infrastructure and application management. Challenge Providing private clouds that meet customers compliance requirements Logica Sweden provides customers with outsourced infrastructure services based on a private cloud delivery model. In total it manages around 10,000 servers on behalf of its customers, which span a wide variety of sectors including financial services, retail, manufacturing and government. When customers are looking for cloud providers, access management controls are very important. Anders Sandell Director of Security, Logica Sweden The security of these cloud-based environments is a key priority for Logica and its customers both in terms of safeguarding confidential data and meeting regulatory requirements. Anders Sandell, Director of Security at Logica Sweden, comments. When customers are looking for cloud providers, identity and access management controls are very important. We could quickly lose contracts if we were unable to demonstrate that we have a robust approach to governing system access. 02
Until recently, Logica Sweden was using a combination of tools the majority of which were developed in-house to manage access privileges within customers private cloud environments. This approach delayed the provisioning process and made reporting for compliance and audit purposes complex and time-consuming. With various systems and processes for different platforms, provisioning our employees with the correct access privileges could take weeks, comments Sandell. Meeting internal security policies is also important for Logica Sweden to retain ISO 27001 accreditation, which it originally achieved in 2008. Sandell comments, We recognised that a centralised structured approach would not only benefit our customers but also make it easier to prove our security credentials for ISO 27001 certification and increase the efficiency of our business. Solution Automated access management across virtual and physical environments Logica Sweden established a three-step process for the selection of a new identity and access management solution. Firstly the company conducted a market overview, from which it selected a shortlist of products for review. Based on responses to Logica Sweden s queries, it then selected CA IdentityMinder TM for a practical proof of concept (PoC). Following the successful exercise, the CA Technologies solution was implemented in 2009 with assistance from CA Services. 6,000 servers access rights are managed via CA IdentityMinder 03
Today, CA IdentityMinder is used to manage role-based access rights to approximately 6,000 physical and virtual servers across multiple operating systems. Sandell comments, CAIdentityMinder enables us to keep track of access privileges for users within customer organisations as well as around 1,000 employees. The solution automates the provisioning process from when an employee requests initial access via CA IdentityMinder s online portal through to the request being approved. It automatically assigns privileges for Windows-based systems in private cloud environments; other systems that are not yet fully integrated currently require manual registration. The ability to automate provisioning is helping Logica Sweden continuously reduce the number of staff with permanent access to multiple systems, in line with best practices and the segregation of duties requirements stipulated by SOX. Access can be granted in real-time and limited to not only particular systems but also specific tasks, which significantly reduces security risks. CA IdentityMinder also facilitates self-service password resets, providing a single point of management for identities across numerous customer platforms and reducing the burden on the help desk to reset users password manually. Access management reporting for auditing and compliance To align system access with user roles, CA IdentityMinder is integrated with Logica Sweden s HR system. As Sandell explains, When an employee leaves the company, their access rights are automatically revoked. When an employee changes team, the integration between the two systems ensures that superfluous access privileges are revoked as well as the new relevant rights assigned. This helps prevent ghost accounts that introduce additional risk. In accordance with best practice processes, users access rights are all terminated, and where appropriate, reinstated, on an annual basis, which eliminates the need for ongoing reviews. Employees and their managers are alerted three months in advance that they need to reapply for access privileges to ensure that this process does not impact productivity. The same controls are available for customer environments using Logica s User Administration Services, as they are moved to the CA IdentityMinder platform. Every quarter, Logica Sweden provides its customers with system access reports. Under SOX, companies have to demonstrate accountability for system changes, explains Sandell. The reports created by CA IdentityMinder enable our customers to prove compliance with SOX and PCI requirements quickly and easily. They are also vital for our own internal and external audits. 04
Benefit Secure, compliant and cost-effective cloud services Logica Sweden is continually expanding its use of CA IdentityMinder, which will eventually become the central point of access control for all 10,000 customer servers under its management. Sandell comments, Our structured, centralised and automated approach to identity and access management means we provide secure and efficient cloud-based services to our customers at a cost they can afford. We can now meet customers security and compliance needs more easily. Anders Sandell Director of Security, Logica Sweden The ability to provide employees and customers with the right access privileges in minutes rather than weeks enables Logica Sweden to: Boost staff productivity Enhance agility as resources can be deployed more rapidly Improve customer service quality as requested changes can be implemented faster. CA IdentityMinder also helps Logica Sweden and its customers safeguard the security of their business-critical systems and comply with industry regulations. We can now meet customers security and compliance needs easily, which helps us maintain our competitive edge and win more business, concludes Sandell. 05
Lorem ipsum dolor sit amet, consectetur Copyright 2012 CA. All rights reserved. All trademarks, trade names, service marks and logos referenced herein belong to their respective companies. The information and results illustrated here are based upon the speaker s experiences with the referenced software product in a variety of environments, which may include production and nonproduction environments. Past performance of the software products in such environments is not necessarily indicative of the future performance of such software products in identical, similar or different environments. CA does not provide legal advice. Neither this document nor any software product referenced herein serves as a substitute for your compliance with any laws (including but not limited to any act, statute, regulation, rule, directive, standard, policy, administrative order, executive order, and so on (collectively, Laws ) referenced herein or any contract obligations with any third parties. You should consult with competent legal counsel regarding any such Laws or contract obligations. This document is for your informational purposes only. CA assumes no responsibility for the accuracy or completeness of the information. To the extent permitted by applicable law, CA provides this document as is without warranty of any kind, including, without limitation, any implied warranties of merchantability, fitness for a particular purpose, or non-infringement. In no event will CA be liable for any loss or damage, direct or indirect, from the use of this document, including, without limitation, lost profits, business interruption, goodwill or lost data, even if CA is expressly advised in advance of the possibility of such damages.