Startseite • Services • IGA Fitness Check

IGA Fitness Check

Put your Identity Governance & Administration (IGA) practices to the test with a quick assessment.

How Strong Is Your
Identity Governance & Administration?


Identity Governance & Administration is a central component of professional IAM. In many organizations, however, structures have evolved over many years. Different applications, manual processes, and historically assigned access rights make it difficult to reliably assess the actual status.

The OEDIV SecuSys IGA Fitness Check provides a structured basis for further development.

IGA Fitness Check at a Fixed Price


€ 9,500 plus VAT

  • 5 consulting days
  • Analysis of your existing IGA landscape
  • Identification of risks and optimization potential
  • Management summary and action plan
  • Individual roadmap for your IGA strategy

What Is the IGA Fitness Check?

An IGA Fitness Check is a structured quick assessment for evaluating your Identity Governance & Administration. The goal is to determine the current maturity level of your Identity and Access Management and identify weaknesses in processes, access rights, and governance at an early stage.

User and Role Management

Joiner-Mover-Leaver Processes

Access Management

Recertification

Segregation of Duties (SoD)

Compliance Requirements

Identity Lifecycle Management

Level of Automation

Governance Processes

Your Benefits

A structured IGA Fitness Check creates transparency and reduces risks.

Enhanced Security

Identify excessive permissions, critical access, and governance gaps at an early stage.

Greater Compliance

Support requirements arising from ISO 27001, NIS2, KRITIS, DORA, or internal compliance policies.

Clear Recommendations for Action

Receive a prioritized roadmap with specific measures and effort estimates.

More Efficient Processes

Optimize access provisioning, approval workflows, and recertification processes.

Investment Security

Identify which technical and organizational measures provide the greatest value.

Frau checkt IGA
Our Process

Our Approach

01

Analysis of the Existing IGA Landscape

We take a close look. Assessments show where you currently stand and which paths forward are available.

This includes, among other things:

  • Identity sources
  • Role and access models
  • Provisioning
  • Recertification
  • Approval processes
  • Reporting
  • Compliance
  • Existing IGA tools

02

Identification of Risks and Gaps

Based on the analysis, we identify technical and organizational weaknesses.

Typical findings include:

  • Overprivileged user accounts
  • Missing role models
  • Manual access provisioning processes
  • Insufficient governance
  • Missing recertifications
  • Media discontinuities
  • Compliance risks
  • Incomplete documentation

03

Development of an Individual Roadmap

You receive an actionable roadmap with short-, medium-, and long-term measures.

This may include, for example:

  • Optimizing governance
  • Improving role models
  • Introducing automated provisioning
  • Implementing Least Privilege
  • Introducing regular recertifications
  • Optimizing Identity Lifecycle Management
  • Selecting suitable IGA solutions

IGA Fitness Check with OEDIV SecuSys

OEDIV SecuSys combines technical IAM expertise with an understanding of organizational interdependencies. As part of the Fitness Check, we analyze the existing situation and identify where concrete action is required.

The result is a reliable basis for the next steps — for example, optimizing existing processes, selecting a technology, or developing an IAM roadmap.

The Fitness Check can therefore be a useful starting point when the first priority is to gain clarity about your current situation. We look not only at the technology itself, but also at existing identity processes, applications, and business models.

Our vendor-independent approach helps assess opportunities and requirements at an early stage and derive concrete next steps.

FAQ

Jetzt IGA Fitness Check
anfragen

Sie möchten den Reifegrad Ihrer Identity Governance & Administration bewerten oder
planen die Einführung einer modernen IGA-Lösung?

Kontaktieren Sie uns für ein unverbindliches Erstgespräch. Gemeinsam identifizieren
wir Optimierungspotenziale und entwickeln eine individuelle Roadmap für
Ihre Identity-Governance-Strategie.

What Is the IGA Fitness Check?
A compact assessment by OEDIV SecuSys that evaluates the effectiveness and efficiency of your Identity Governance & Administration (IGA) in five consulting days at a fixed price of €9,500 plus VAT. We assess user accounts and permissions, joiner, mover, and leaver processes, access policies, regular access reviews, segregation of duties, the level of automation, and compliance requirements. The result is a management summary, a prioritized action plan, and a roadmap with specific recommendations — from process optimization, policies, and training to the implementation of new technologies.
For organizations that need a reliable baseline before implementing IAM, are not making full use of an existing IGA solution or Microsoft Entra ID, need to address audit findings relating to access rights, or want to demonstrate compliance with NIS2 and DORA access management requirements. Typical stakeholders include information security officers, IT management, and data protection officers.
In three steps. First, we assess your existing IGA systems, processes, and policies: user accounts, permissions, access policies, and compliance requirements, supplemented by interviews with key stakeholders from IT, HR, business units, and information security. We then evaluate the results and identify weaknesses and risks, such as inadequate access controls, excessive permissions, or a lack of transparency. Finally, you receive a roadmap with specific recommendations. The assessment is designed to be completed in five consulting days at a fixed price and can be adapted to your requirements, in which case the price will be adjusted accordingly.
A maturity assessment for each area of action, a list of specific findings — typically overprivileged accounts, missing access reviews, manual provisioning processes, gaps in the role model, and orphaned accounts — as well as a prioritized roadmap with effort estimates. The roadmap is structured so that it can be used directly as a basis for budget planning, tool selection, or responding to audit findings.

No. The Fitness Check assesses processes, data quality, and governance independently of the technology used. Without an existing solution, it provides the requirements basis for tool selection. With an existing solution, it shows where configuration, processes, or the role model fall short of the platform’s capabilities.

Yes. It compares your access management controls against the specific requirements of NIS2, DORA, ISO 27001 (Annex A, Controls 5.15 to 5.18), and the BSI IT-Grundschutz framework (ORP.4 module), and identifies gaps for each requirement. The results can be directly incorporated into your Information Security Management System as a gap analysis or presented to auditors as evidence of structured remediation.