Hi,
I am currently completing a masters in cyber security and my final work is on IAM and why it seems to continue to be a problem despite being a longstanding security fundamental and many organisations investing significant funds into the problem...
I have worked at a few places where sustainability of good IAM seems to be a challenge.
My own working theory is that it is seen as a technology problem when in fact it is a business process which needs technology support and that controls degrade after investment due to poor connection with wider corporate governance.
If anyone has any thoughts and views they would be very welcome.
Best,
Gareth