Advertisement
Promo

Security management Toolkit

ID guide aims to prevent corporate IT break-ins

Nick Heath silicon.com

Published: 21 Jan 2009 09:37 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Shutting the door to IT systems after staff leave the business and allowing workers to safely log in from home can be major headaches for business.

In an identity-management guide published on Tuesday, the Corporate IT Forum (TiF) recommends using automation to smooth over some of the difficulties in keeping track of who is accessing what.

According to the guide, companies should approach identity management by asking the following questions for each member of staff: "Who are you?"; "What is your business here?"; and "What IT elements and data do you need?".

That information should be put into a Lightweight Directory Access Protocol, which sets and controls staff access to applications and services, and then governed by a set of variables: do staff have permission to create/modify/delete a data set, for example, and when do those access rights need to be withdrawn?

As well as helping out administrators, the system will allow staff to log in just once to use all the systems they have access to.

However, some business decisions should still be made by management and not the automated system, such as whether to grant access to business critical data to a temporary employee, the guide advises.

The report says this approach will save a business money and time, reduce the risk of human error, ease staff access to company systems and provide a clear audit trail.

Read this

Leader
Leader: Learning from the UN's security failure

The UN has found massive flaws in its internal IT security, for reasons that may be all too familiar in the boardroom

Read more +

Head of research at TiF, Ollie Ross, said: "Proper identity management and role-based access gives a better handle on who in the business is accessing what, from what and for what purposes — from the desktop through to handhelds."

International information-management group Reed Elsevier helped produce the report and is itself wrestling with how to simplify controlling systems access among its 8,000 IT users.

Ruth Harris, head of project management office Europe for Reed Elsevier Technology Services, described the challenges posed by controlling staff access.

She said: "We have users all over the world using a number of different applications with different IDs and passwords. When those staff leave, you have to go through each application they have access to, both centrally and locally, and then disable that access.

"We are looking into how to make this process simpler by having a system that allows you to only have to tap in once that this person is leaving and it will disable their access to all applications."

To find out more about the TiF guide, visit TiF's website.

Credit: Stopping corporate IT break-ins from silicon.com

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a Teufel Cinebar 50 system

Win a Teufel Cinebar 50 system

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters