In most modern organisations, there is a natural tension at the interface between the IT and security departments. The Chief Information Officer (CIO) strives for continuous optimisation of processes, operational efficiency, automation and ensuring that staff can exchange information seamlessly. The Chief Information Security Officer (CISO), on the other hand, focuses on risk mitigation, access control, regulatory compliance (such as the NIS2 Directive or the GDPR) and building a Zero Trust architecture.

From a cybersecurity engineer’s perspective, the field of IAM (Identity and Access Management) is where the objectives of both directors not only can, but indeed must, converge. The key to success is not choosing between security and convenience, but implementing an architecture that achieves both objectives simultaneously. The technical foundation enabling the consolidation of these requirements is the Okta Identity Cloud platform.

The divide between the CIO and the CISO – where are the points of friction?

In order to design a coherent IAM architecture, a security engineer must map out the key expectations of both parties:

The CIO’s Perspective (Performance and Business)The CISO’s perspective (security and compliance)
Quick onboarding: Access to the app from day one.
Least Privilege Access: Strictly minimal and verified access.
No barriers (User Experience): Quick login (SSO).Strong authentication: Phishing-resistant MFA.
Low maintenance costs: Fewer helpdesk enquiries.Auditability and visibility: Detailed logs and continuous monitoring.
Flexibility: Easy implementation of new SaaS/Cloud tools.Supply chain security: Control of external users.

Okta as a technology bridge

The Okta platform provides tools that meet the needs of both roles within a unified identity architecture.

1. Authentication: Single Sign-On (SSO) vs. Adaptive MFA

  • Meeting the CIO’s needs: Thanks to Okta Single Sign-On (SSO) technology, users log in once and gain access to all authorised resources. This eliminates the problem of forgotten passwords and the constant need to reset credentials, which significantly reduces the volume of helpdesk enquiries.
  • Addressing the needs of CISOs: Okta’s SSO works in conjunction with Adaptive MFA and the passwordless technology Okta FastPass (FIDO2/WebAuthn). Instead of cumbersome and vulnerable SMS codes, access is verified in the background based on strong biometrics, IP address reputation and device context. The CISO gains resilience against phishing, whilst the CIO is pleased to see employees logging in quickly.

2. The identity lifecycle: automated provisioning (OLM)

  • Addressing the CIO’s needs: Using Okta Lifecycle Management (OLM) and integration with the HR system (HR-as-a-Source), the process of creating accounts and assigning applications takes place automatically based on the SCIM protocol. New employees start work with a full set of essential tools from ‘day one’.
  • Addressing the CISO’s needs: Integration ensures deterministic offboarding. When an employee is deactivated in the HR system, a Universal Logout signal is sent immediately and access is blocked across all SaaS/IaaS systems. The CISO eliminates the risk of inactive accounts (‘ghost accounts’), whilst efficiently meeting the cyber hygiene requirements set out in NIS2.

3. Governance and compliance: Okta Identity Governance (OIG)

  • Addressing the CIO’s needs: Traditional access reviews (known as ‘Access Certifications’) can be a manual, labour-intensive process imposed by security departments. OIG automates the assignment of access rights and supports the Just-In-Time Access (JIT) mechanism – elevated access is granted temporarily at the employee’s request.
  • Addressing the CISO’s needs: OIG generates transparent and indisputable reports on access rights reviews and provides universal logs (Okta System Log). Legal requirements and standards such as ISO/IEC 27001 and the NIS2 Directive are met through clear audit evidence without the need for engineers to manually generate reports.

Synergy through Zero Trust architecture

By implementing Okta technology, a security engineer shifts the focus from securing network perimeters to securing identities and devices. Okta integrates natively with EDR/XDR solutions (e.g. CrowdStrike, SentinelOne) and MDM.

As a result, the decision to grant access is made in real time:

  1. The CIO can be confident that staff can work securely from any location and on any device (the hybrid working model).
  2. The CISO is assured that if a device is not configured in accordance with policy or is infected, access to production applications will be immediately blocked.

IAM implementation with Softinet

Reconciling IT operational objectives with stringent security requirements calls for well-designed processes and in-depth integration expertise. Simply purchasing a platform is just the start of the journey.

The team of engineers at Softinet has extensive experience in implementing and configuring IAM and Zero Trust solutions based on the Okta platform. We help organisations develop an architectural model that will satisfy both the CIO (through automation and greater ease of use) and the CISO (by reducing the attack surface and ensuring compliance with standards and NIS2). Contact Softinet’s experts to find out how to turn identity into your business’s most important operational advantage.