March 2019ENTERPRISE SECURITY| | 19Identity is the new security perimeter, and is a core component of a modern security program.Business, Community, and Governmentleaders envision the economic potential ofthe digitization of all aspects of our environment, business, and society operating at peak efficiency while optimizing risk and resources.This vision can only be fully realized if identity verification, validation, federation, Single-Sign-On (SSO), and multi-factor authentication(MFA) for human and machine identities are leveraged as a core security function.Federation, SSO, and MFA are foundational enablers of digitization.As we migrate our underlying system infrastructures from legacy on-premises solutions to hybrid SaaS, PaaS, and IaaS solutions, we can no longer hope to protect the fragmented data sets with traditional username/password combinations. While we have known this for many years, the need for real-time data integration while maintaining Confidentiality, Integrity, and Availability, has exposed the challenges of existing practices including but not limited to; timely user on-boarding and off-boarding, user access changes, user access validation, password management, orphaned accounts, account sharing, and credential theft. Each of these challenges contributes to business risk, and a potential impact to the bottom line.Regardless of your organization's position on identity verification and validation, which is a topic for another time, implementing Multi-Factor Authentication (MFA) with federation and Single-Sign-On (SSO) throughout the organization both internally and externally is an excellent way to mitigate risk, enable digitization, and increase productivity. While there will likely be organizational resistance to MFA, the benefits of federation and SSO to the end-user will outweigh the perceived extra authentication hurdle if packaged and delivered together with MFA. In order to deliver MFA with federation and SSO, conceptually bifurcatethe identity verification and validation process from the authentication process and address them with separate efforts.Identify the in-scope internal and external applications and services CXO INSIGHTSImplementing Multifactor Authentication A Required Enabler of DigitizationBy Stephan Hundley, Director Digital Risk, Governance and Security, TTX
<
Page 9 |
Page 11 >