Combining SSO with strong authentication devices provides two-factor authentication for improved security

01 February 2010
Technology has evolved to address the challenges of the modern business market. Mobile working and round-the-clock communication have tested information security, as has the need to lock down data from the inside-out. Securing the firewall was previously top of the CISO agenda, but today, securing internal access to applications by employees is equally important.

Internal and external regulations exist to protect personal data and restrict employee access to information. As a result, staff are often required to input multiple passwords a number of times each day. To avoid locking themselves out of critical applications by forgetting complex passwords, employees resort to jotting down information which has an adverse effect on security. Users that attempt to fully comply with password policies often find themselves locked out of applications after forgetting credentials. This leads to disrupted workflow and pressure on the IT helpdesk.

To avoid security challenges caused by multiple passwords, technologies such as single sign-on (SSO) have emerged to allow users to log-on with one set of details. The single point through which users can authenticate alleviates the problem of disparate passwords/forgetful users. Combining SSO with strong authentication devices including fingerprint biometrics, smart cards and password tokens, results in two-factor authentication and improved security. By opting for SA that compliments the working practices of the staff, business can take advantage of the extra benefit of improved productivity. So what are the various methods on offer?

ID tokens

One-time-password tokens are often used for online banking facilities. The customer/employee enters a string of numbers uniquely generated by the token, which is valid for a short period of time. Password tokens are particularly useful where employees work remotely and can authenticate users while preventing any shoulder surfing that is more likely to occur outside the office environment. Password tokens improve security employee workflow by safely avoiding multiple passwords.

Biometrics

Biometric devices provide hardened security for compliance, and streamlined end-user access. As security threats and regulations become more rigid, organisations choose biometrics to comply with regulatory demands. Biometric authentication has become increasingly affordable and effective, particularly as many modern laptops are equipped with biometric readers as standard. Biometrics are steadfast and non re-creatable, proving popular environments like healthcare where speed and ease are essential.

Smart Card Technology

Facility access badges or smart cards from simple swipe cards to passive proximity and chip cards have traditionally been used to enter the office building. The card grants access by communicating with the PC to authenticate the user to the IT network, used alongside a PIN. Smart cards can be linked into other projects meaning extra information is hosted on the card. This saves hardware costs and further eases the working life of staff. Additionally, the physical access system can be programmed to grant access to a PC only if the user has physically entered a specific room or operation work area.

Technology is available to help organisations face IT access management challenges head on. Providing a centralised tool for security staff to manage and provision IT access, integrated with better levels of authentication and user tracking, go a long way to improving access management.

Imprivata, Inc is exhibiting at Infosecurity Europe 2010, on 27th – 29th April, Earl’s Court, London - www.infosec.co.uk.

 

Latest public sector security articles

 Passwords are past their sell-by-date

 Misconfigured networks are the easiest IT resource hackers exploit

 The Return of Ransomware and Do-it-Yourself Botnets

 Hikvision mobile surveillance solution deployed on 3,600 buses in Ningbo, China

 Hikvision cameras keep watch on World Expo 2010 in Shanghai

 Data protection laws are too relaxed and require revision

 Northshore Utility District deploys IndigoVision's IP Video surveillance system to prevent terrorism and improve public and staff safety

 The challenge of protecting multiple and increasingly disparate end user environments

 The USA continues to be the number one spam polluter whle Europe becomes the most prolific continent for spamming

 New Mobile CCTV service for Northern Ireland

...[view more articles on public sector security]...

 

Other security websites:

Public Sector security links

Public sector banks need to hire more: BCG A report by The Boston Consulting Group notes the human resource challenge for public sector banks due to large-scale retirement.

Unions suspend public sector strike South African public sector workers suspended a pay strike yesterday as it entered its fourth week. The strike by 1.3 million workers has hit schools, state hospitals and the judiciary. Strikers have demanded a pay rise of 8.6 per cent, twice the inflation rate, and a R1,000 (£90) a month housing allowance.

South African public workers suspend 20-day strike South African public sector unions announced the suspension Monday of a three-week-old strike that has crippled the health service and forced widespread school closures.

S.African public sector strike suspended -unions S.African public sector strike suspended -unions

Labour focus shifts from private to public sector While the private sector bore the brunt of the economic downturn, union leaders are turning their attention to the public sector this Labour Day as deficit-obsessed governments put the squeeze on their workers.

Survey: IT job opportunities slump in UK public sector LONDON: Public sector job opportunities in IT in Britain have fallen markedly since the start of the year, a survey showed today, in a sign that the government's austerity drive is already affecting the labour market. Only four in every hundred new IT jobs are being created in the public sector, down from about 30 out of 100 at the start of the year, according to research by business and ...

Public workers given mental health training in Austin Public workers given mental health training in Austin

directory of Public Sector security suppliers
Search directory Register your company
Public Sector Security books:

SEARCH NEWS
DIRECTORY
Google