Yum! Brands is the world's largest restaurant company operating over 37,000 restaurants across 110 countries. It has over 1,000,000 employees and $11 billion in annual revenue. Managing identity and access for employees across its global, franchise-based business is challenging. Yum! implemented identity and access management solutions to automate provisioning and access for over 400,000 accounts worldwide while meeting the needs of a dynamic workforce. Lessons learned include the need for high availability, real-time provisioning, and single sign-on to reduce passwords.
08448380779 Call Girls In Friends Colony Women Seeking Men
Identity and Access Management in a Highly Distributed and Dynamic Global Enterprise
1. Identity and Access Management in a Highly Distributed and Dynamic Global Enterprise Shannon Tompkins, MBA, CISSP Manager, Global Identity and Access Management Yum! Brands, Inc. Dan Fitzgerald VP, Sales and Marketing intiGrow
2. World’s largest restaurant company in terms of the number of restaurant systems 37,000 restaurants in 110 countries 1,000,000 associates $11 billion in revenue in 2009 Mix of both equity restaurant systems and franchise restaurant systems Primary brands A&W, KFC, Long John Silver’s, Pizza Hut, Taco Bell Three Operating Segments U.S., Yum Restaurants International, China Division Leader in international retail development In 2009 Yum opened more than four restaurants per day internationally On average, China alone opens one new restaurant per day Who is Yum! Brands, Inc.? 2 IBM Pulse11: Feb. 28, 2011
3. Premier IBM Business Partner Focused on IAM Operating in the USA and India Providing service in South America and Australia Became part of Yum! Brands IAM team when IAM expansion took off. Has continued to provide services since 2007. Who is intiGrow? 3 IBM Pulse11: Feb. 28, 2011
4. Yum’s IAM Journey Current Global IAM Drivers Meeting the Challenges Successes Lessons Learned Q&A Agenda 4 IBM Pulse11: Feb. 28, 2011
36. How Did IAM Become Global At Yum? 9 Key global Web applications became strategic Yum global initiatives across brands (e.g., learning management, hiring management) For the first time, restaurant crew-level associates around the globe required individual identity credentials to access global and brand-based applications IBM Pulse11: Feb. 28, 2011
37. The Business Challenges 10 Technology to the restaurants Strategic global Web applications Brand-based Web applications Outsource application hosting Provide rapid and accurate access to resources Reduce costs IBM Pulse11: Feb. 28, 2011
38. The Operational Challenges 11 Dynamic staffing environments Thousands of restaurants around the globe Average ~30-40 associates per restaurant High restaurant employee turnover High franchise-to-equity ownership ratios Outsourced application hosting models IBM Pulse11: Feb. 28, 2011
41. Provides one user account and one password per equity and franchise associate
42. Enables password synch, password self-service, and (new) single sign-on servicesIBM Pulse11: Feb. 28, 2011
43. How Do We Do It? 13 Ha – One of our team whiteboard talks on the “New Hire” process IBM Pulse11: Feb. 28, 2011
44. How Do We Do It? 14 ITIM Provisions to Managed Endpoints by Policy ITIM LDAP AD ITAM LDAP Voice Mail Email ITIM Collab App Attribute Data Market LDAPs AppLDAPs Learning App Hiring App = Internally Hosted = Externally Hosted IBM Pulse11: Feb. 28, 2011
45. How Do We Do It? Provisioning Inputs Batch Feeds Custom throttling applications Performance considerations Equity HR App Data Restaurant Inventory App Franchisee Batch Uploads SFTP Server ITIM UP Web Services TDIs Real-Time 24/7/365 Various Apply for Access Apps = Internally Hosted = Externally Hosted BOH Real-Time Processing = Internal Collection International ITIM 15 IBM Pulse11: Feb. 28, 2011
46.
47. Our HR system was our authoritative source for equity-based corporate and restaurant employee information
48. With the growth of features, function and popularity of our brand-based Portal applications, we suddenly needed a way to grant access to franchisee employees
49. We had no authoritative source for franchisee employee information
50. Java-based Web Services enabled franchisees to submit their data to us through apply-for-access Web applications, batch data feeds, and in-restaurant HR application integrations16 IBM Pulse11: Feb. 28, 2011
51.
52. Creates and tracks a behind-the-scenes “Global Person Number” (GPN) for every individual to follow them indefinitely through rehires and across organizations (separate from their transient logon IDs)
56. (New) Enables near real-time provisioning services from restaurants to third-party Web Applications17 IBM Pulse11: Feb. 28, 2011
57. How Do We Do It? 18 Ha – Another One of our team whiteboard talks on the Web Services process IBM Pulse11: Feb. 28, 2011
58. How Do We Do It? 19 Password Synchronizations AD ITAM Self-Service App ITIM Web Services International ITIM Learning App = Internally Hosted = Externally Hosted = Internal Collection IBM Pulse11: Feb. 28, 2011
59. How Do We Do It? 20 Password Self-Service Learning App ITIM Links to Web App Web App with Forgot Password and Challenge Response Questions Links to Web App Self Service Web App ITIM WS Wrappers Self-Service WS Hiring App = Internally Hosted = Externally Hosted = Internal Collection IBM Pulse11: Feb. 28, 2011
60. How Do We Do it? 21 Access Management All ITIM accounts have corresponding ITAM accounts WebSEAL/ITAM provides access to internal resources via junctions Authentication required Authorization to follow junctions occurs via ITAM policies per membership in designated ITAM LDAP groups Decentralized WebSEAL/ITAM deployment and support strategy IBM Pulse11: Feb. 28, 2011
61. Yum’s IAM Successes IAM has enabled automatic user account provisions, password synchronizations, and password self-care operations to hundreds of thousands of clients around the globe which provides 24/7/365 access to key, strategic, global applications Very high IAM utilization levels Current monthly average metrics: 27,467 user accounts added 75,204 user accounts modified 16,575 user accounts deleted Lean and efficient FTE staffing model to support the IAM environment with staff augmentation support as needed 22 IBM Pulse11: Feb. 28, 2011
62. Lessons Learned Very low downtime tolerance: Our IAM processes support core global, strategic initiatives 24/7/365 Scheduling downtime maintenance windows has become very challenging We overlooked early opportunities to lock-in routine maintenance windows. Now we’re reviewing options to increase resiliency even further to lessen our already low downtime occurrences. Provisioning: Automated provisioning is very logical. To succeed, business partners must be involved in workflow designs. Batch provisioning eventually takes too long for the business. Real-time / near real-time provisioning becomes required. Password Self-Service: Password self-service operations are heavily utilized. Helpdesk calls are substantially reduced. But once it’s in place, password self-service must always work. It quickly builds organizational and operational dependencies. Password Synch, SSO, Etc. Regardless of possible assumptions or directions from project leads to the contrary, every new provisioning project to a third-party hosted application will likely and eventually require a single sign-on, password synch, LDAP integration, or similar service. There is becoming an increasingly low tolerance within the organization for multiple passwords per logon account. 23 IBM Pulse11: Feb. 28, 2011
DescriptionThis package exposes the ITIM end user API through a web services interface and includes an Eclipse-based Reference UI to illustrate how developers can utilize the web services interface to develop their own custom UI.Click to see more.IBM Tivoli Identity Manager (ITIM) Web Services is a J2EE application that can be co-located on ITIM's Websphere server to provide access to most of the end user (self service) related ITIM API thru a standard web services interface. It can be used by customers who need to communicate with ITIM from an external application or custom User Interface (UI) application. A reference application with source code is included with the ITIM 5 archive files to illustrate the usage of the web services API.