enterprisesecuritymag

OCTOBER 2020ENTERPRISE SECURITY| | 9DESIGNING BIOMETRICS FOR HUMANSData breaches continue to make the news and dominate boardroom conversations on cyber riskOr worse, you risk fines from regulators. The use of Biometric data is highly controlled in Europe and universally protected around the world. The Dutch Data Protection Authority recently issued a 725,000 fine against a company for mandating a fingerprint time and attendance system claiming it to be overkill.How do you fix it?Consent! Make sure people can opt-in and can opt-out, and make sure they are aware when their identity is being activated. Second, use regulations to guide you. The principles of the General Data Protection Regulation (the "GDPR") focuses on aspects such as transparency, security, and purposefulness, which are considered important in the context of European cultures. Regulation is fiercely and continuously debated and can save you the effort of doing the same.2. The Convenience FactorUnless you have a unicorn approving your budget, you are unlikely to win approval just because the technology you're pitching is sexy. Convenience is probably the strongest motivation for business. But if your feature is being implemented primarily for convenience, it is essential to take some time to understand your end user.What can go wrong?If you are relying on biometrics for authentication, accuracy becomes the pivot. An overly sensitive biometric gatekeeper will destroy your solution, but after relaxing the rules, you ended up with the security equivalent of a "beware of the dog" sign on the fence of a sleeping Labrador puppy.Then there are some other human factors. Some generations resist technology replacing the comfort of human interaction. Some more glamorous users sporting long nails will find fingerprint recognition terribly inconvenient.How do you fix it?Design to your demographic. Always offer an alternative option and position it according to your target audience. Provide the opt-out early if many of your users will need it or at the end of the prompt if the majority prefer automation.Biometric authentication works best in Multifactor authentication model. Consider your second factor carefully to hack the user experience. Linking a device to a user provides seamless, implicit authentication ormultimodal biometrics could provide a second data point to improve recognition accuracy. 3. The Security FactorImproving recognition accuracy provides a good Segway into the third factor ­ Security. Improving the accuracy of the authentication is an important first step, but it is also crucial to keep in mind the security of the solution itself.What can go wrong?The good news is that technology is getting smarter. A NIST study on facial recognition in 2018 found that success rate had improved 20% from the initial study in 2014. The bad news is that cyber criminals are also getting smarter. New technologies such as DeepFake use artificial intelligence to mimic biometric qualities. Data breaches continue to make the news and dominate boardroom conversations on cyber risk.We can't ignore the responsibility of protecting the personal information used by the solution. Misappropriation or misuse of intimate biometric data can give way to discrimination, for example classification based on a person's health status or ethnicity. Decisions to use and protect that data must be taken very seriously.How do you fix it?With brains and eyeballs. Whenever you are venturing into volatile data territory, it is crucial to pay attention to your design team. Architects, developers, and designers with strong Security training will save you a lot of pain in the long run.Authentication within the information system itself is often one of the first barriers to protection. The robustness of this mechanism is therefore crucial. When choosing an authentication module, consider its robustness and vulnerability factors.Biometric data is powerful, but it needs to be protected. A person can change their password if it has been leaked but biometric characteristics are a bit more difficult (and perhaps more painful!) to alter. A well-designed biometric solution can provide an impressive and convenient solution to the right audience. If the technology provides a good solution to your challenge, simply try to make biometric voluntary, pay attention to regulation, and work with trusted partners and an expert teamto embed Security by design. ES
< Page 8 | Page 10 >