May 2019ENTERPRISE SECURITY| | 9Traditional customs would suggest that the username and password are the defining elements of an identity. The problem with that logic is that this basic authentication method is compromised on a regular basis using simple social engineering attacks and data breaches. A layered approach should be used to ensure the credentials authenticated to your resources are being used by the appropriate individual. There are a variety of security technologies that will assist an organization in achieving this goal. Geolocation services are capable of establishing trusted and untrusted boundaries. These boundaries can be governed in a variety of ways such as building location, networks, country of origin or a combination of each. These services can be leveraged to layer multi-factor solutions and base the number or required factors on the location of the user. 802.1x security authentication can ensure that the appropriate devices are connected to the proper networks. As previously mentioned access needs to not only be provisioned but managed. Managing begins with creating a robust RBAC module. This foundational step allows you to appropriately provision the required accesses based on the functional purpose of the individual. As the person changes positions, their accesses are automatically adjusted to accommodate. Once RBAC has been established, then auto-provisioning can be implemented. Most large organizations leverage employee resource planning (ERP) solutions to manage their employee populations. An access management system could be configured to receive a feed from that system and automatically adjust changes to the user's permissions accordingly. Elevated access can be completely removed from the person's identity and proxied through a privileged access management system (PAM). Rather than granted elevated access directly to the individual, PAM would manage the elevated access and proxy the connection to the resource. Depending on the PAM solution, the session could be recorded and stored for further review or validation. The ideas presented in this article are easy to discuss but difficult to implement. It would first require the support of the organization. Multiple departments would have to collaboratively work on processes and workflows. Information Services would have to create new skill-sets to support the effort. Multiple communications would have to be distributed to the general population. All these things must happen because security inevitably sacrifices conveniences to a certain degree. Users must understand that while they may simply authenticate while working in a trusted low-security building, they may require a second factor in an untrusted environment. The IT professional accustomed to unfettered access with a single account should be made to understand the security risks and the reason for PAM.Traditional identity and access management is no longer a manageable approach to allowing the enterprise user to exist both within the wall of an enterprise and on the social networks that consume much of our interactions these days. It is time to start looking at identity in methods that complement our daily lives rather than impose unmanageable barriers. While this type of approach is not easy to implement, the benefits are immeasurable. ESTraditional identity and access management is no longer a manageable approach to allowing the enterprise user to exist both within the wall of an enterprise and on the social networks that consume much of our interactions these daysChristian Aboujaoude
<
Page 8 |
Page 10 >