Features and Benefits
Keystone is the industry’s most robust IAM solution that externalizes, unifies, and simplifies the management of fine-grained authorization policies. With a 100% XACML-based engine, Keystone is loaded with features and benefits all designed to save time, reduce costs, increase security and compliance, and enhance business agility.
Save Time and Reduce Costs
By decoupling the authentication and authorization logic away from the core application logic, Keystone helps organizations quickly enable comprehensive security for their applications in a cost-effective way.
- Application development teams no longer need to divert their limited resources writing custom security code for their applications. Instead, they can concentrate their efforts on the core business values of their applications.
- Keystone streamlines security by eliminating the needs to rewrite redundant polices for each application by allowing the reuse of polices across all applications.
- Security administrators can focus their attention on the business aspects of managing security, rather than on the technical implementations of security for each application, which is not their core expertise.
- The costly administration of complex security policies for each application--including current, customized, in-house, and future applications--is greatly reduced.
- By leveraging the XACML open standards, Keystone seamlessly integrates with a broad range of technologies. Organizations can maximize the investments they have already made in their existing infrastructures. Keystone integrates with:
Strengthen Security and Assure Compliance
With Keystone, centralized control and visibility of comprehensive fine-grained access control policies ensures that security aligns with business objectives and that policies are applied immediately and consistently across the enterprise.
- Having security policies externalized and unified across applications/technology silos eliminates the inconsistencies in policy interpretation, creation, deployment, and enforcement. Inconsistencies can grant users unintentional access. Not only does this pose a security risk, but it can also jeopardize an organization's compliance and governance efforts.
- Keystone enforces fine-grained access control for all users across all Keystone-protected applications without the application development team having to know about the relationships between the secured resources, the user cases, roles, and attributes defining those roles. These relationships are maintained in a central, distributed, and audited metadata system.
- Keystone administrators can easily create ethical walls to prevent a conflict of interest, such as separating a user who can make payroll updates from a user who can audit those updates. This permits the enforcement and audit of Segregation of Duties (SoD).
- All actions performed within Keystone are recorded which allows administrators and auditors to generate real-time reports on who has or had access to what functionality and resources, under what conditions, and who made what policy changes.
- The Keystone administration application offers a number of pre-defined and customizable reports to suit an organization's compliance and auditing needs.
Enhance Business Agility
Keystone offers the flexibility, interoperability, and scalability to adapt quickly to business changes as enterprise IT environments become ever more agile, extended, and service-oriented.
- With the Keystone XACML-engine organizations have greater flexibility, freedom of choice, and future-proofing investments in their systems.
- The security administration team can create, deploy, and adjust security policies, and even easily exchange directories according to the business' changing needs without having to modify the applications by writing new code. Development teams are freed from making redundant policy changes, and can therefore focus on more enterprise critical tasks. As a result, development cycles are sped up and organizational agility is achieved.
- Keystone's fine-grained authorization capabilities have the flexibility to satisfy any requirements the business dictates. This is accomplished through a combination of central and application-specific role-based, attribute-based, and rule-based access control.
- Utilizing the advanced caching algorithms and compiling mechanism developed by BiTKOO has allowed us to create an XACML engine that is 500 times faster than the engines used by alternative solutions. This makes Keystone the fastest XACML-based IAM solution in the industry.
- Keystone's highly scalable architecture is designed to support organizations with hundreds to hundreds of thousands of users. It can grow as the demands of the business grow.