It should be measured as both, but the article’s core argument is that identity security becomes strategically valuable when it enables growth, reduces operational drag, and lowers risk at the same time. If it only blocks access or only satisfies audit needs, it is missing the business point.
Why the question is really about operating model, not labels
identity security should not be judged only by whether it behaves like an IT control. It is also a business capability because it shapes how quickly people and systems get access, how confidently privileges are granted, and how much operational friction the organisation carries. The strongest programs are those that reduce risk while also enabling delivery, onboarding, automation, and change at speed.
That is why a narrow control-only view usually undersells the function. If identity work is measured only by audit pass rates or blocked access, it can look successful while still slowing teams down, creating workarounds, or failing to support growth. A capability view forces leaders to ask whether the control is usable, scalable, and aligned to business outcomes.
For a broader view of how identity security programmes should be structured, the operating model matters as much as the technology stack. The same is true when the program has to cover business-case thinking for identity security rather than only control compliance.
How to measure identity security as both control and capability
The cleanest measurement model separates outcome, control, and business effect. Control measures answer whether access is protected, reviewed, and revoked on time. Capability measures answer whether identity processes accelerate delivery, reduce manual intervention, and support the organisation without creating bottlenecks. If a metric does not reflect both sides, it usually rewards the wrong behaviour.
Good capability metrics are usually outcome-based rather than tool-based. Examples include time to provision and deprovision, percentage of access paths covered by policy, number of emergency exceptions, and the amount of manual effort required to approve or recover access. Those measures show whether identity is making the business safer and easier to run, not simply whether a control exists.
That is why identity security metrics and KPIs should combine posture, lifecycle, and access outcomes. If the measurement only tracks policy completion, it can miss operational drag; if it only tracks speed, it can miss privilege creep and weak governance.
For a practical control baseline, NIST Cybersecurity Framework 2.0 is useful because it frames identity security as part of governance, protection, detection, response, and recovery rather than as a single technical task. That makes it easier to connect control effectiveness to business resilience.
What changes when identity security is treated as a business capability
Once identity security is treated as a capability, ownership changes. Security teams still define policy and control expectations, but HR, IT operations, platform teams, application owners, and business leaders all influence how identities are created, approved, used, and retired. The question stops being “is the control in place?” and becomes “can the business safely use this control at scale?”
This matters most in high-change environments. Mergers, cloud adoption, contractor populations, and automation increase the number of identities and access paths that must be governed. A control-centric model often reacts late, while a capability-centric model is designed for throughput, visibility, and repeatability from the start.
For organisations that need to cover human and non-human populations together, the identity convergence view is helpful because it shows how one operating model can support workforce, privileged, customer, NHI, and AI-agent identity patterns without fragmenting governance. When the capability is weak, the business usually feels it first as delays, exceptions, and shadow processes.
The architecture lesson is simple: the business value of identity security appears when access is both controlled and consumable. If teams route around the process to get work done, the organisation may still have a control, but it does not yet have a reliable capability.
Risk and Threat Considerations
Identity security that is treated only as an IT control can create hidden exposure. Controls that are hard to use often lead to exceptions, shared access, stale accounts, and excessive permissions, which weaken both governance and resilience. The business risk is not only breach likelihood, but also slower delivery and weaker visibility into who can do what.
Failure mechanism: When identity processes are designed around audit evidence alone, organisations tend to over-rely on manual approvals, delayed revocation, and exception handling. That makes privilege creep, dormant access, and account misuse more likely, especially across fast-moving teams and automation-heavy environments.
Impact: The organisation pays twice, first in operational drag and then in expanded attack surface. Poorly governed access can slow launches, complicate incident response, and increase the blast radius of compromised credentials or over-privileged accounts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 — Organizational Context | Identity security must align to business outcomes and operating context. |
| PR.AA-05 — Least Privilege | Access decisions and privilege scope are central to identity security controls. | |
| GV.RM-01 — Risk Management Strategy | The question hinges on balancing control value with business risk and operational efficiency. | |
| Recommendation — Define identity security outcomes in business terms and connect them to governance priorities. Enforce least privilege for every identity and review it continuously. Set identity security goals that balance risk reduction with business enablement. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Measuring identity security as a control requires privileged-access restraint. |
| IA-5 — Authenticator Management | Identity security depends on managing credentials, lifecycle, and renewal safely. | |
| Recommendation — Limit access to the minimum privileges needed for each role or process. Rotate, protect, and retire authenticators on a defined lifecycle. | ||
Practitioner Guidance
What to measure: Track one control metric and one business metric together. A useful pair is revocation timeliness alongside time-to-access for legitimate users, because it shows whether security is reducing risk without adding avoidable friction.
Decision rule: If an identity control is accurate but routinely bypassed, treat it as an operating-model problem rather than a tool problem. Fix the workflow, ownership, or approval path before adding more policy.
What good looks like: Business teams can onboard, change access, and remove access quickly through a governed process, while security can still explain and evidence who has access, why they have it, and when it will be removed.
Practitioner takeaway: The right measure is not “control or capability”, but whether identity security can prove governance while still helping the organisation move faster.
Related resources from NHI Mgmt Group
- How should security teams make NHI best practices usable across the business?
- Should MFA be the first control for small business identity security?
- Who is accountable for ensuring identity security supports business growth and internal control?
- How should security teams position identity security as a core business control rather than a back-office function?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org