Picture of access denied error message
Software access control is vital for security

Identity crisis

Problems with employee access and identity management continue to plague IT departments

Written by Linda More

Businesses are becoming increasingly aware of the importance and value of maintaining their employee’s identities and controlling who can access confidential business information.

However, given the steady increase in identity theft and the misuse of confidential business data, some are clearly not managing their employees’ identities and access as well as they should. Such issues are affecting the ability of organisations to comply with regulations, as well as having a financial and confidence impact when sensitive information is leaked.

Donal Casey, security adviser with business consultancy Morse, says this is not an easy problem to fix.

‘Modern business environments are as intricate and complex as spiders’ webs, comprising a multitude of applications, diverse information points and varying types of users,’ he says. ‘This makes it difficult to determine and control how information is accessed and used.’

Without the correct security measures in place to determine who can access information, users may be able to retrieve any confidential information they want, with potentially disastrous consequences for the business. Providing legitimate network access, while retaining control over hackers and unscrupulous employees, has become a delicate balancing act.

The biggest challenge to corporate security today is the human factor – be it a disgruntled or careless employee or a sophisticated professional hacker.

According to research published last year by YouGov, almost a third of UK company directors take confidential corporate information with them when they change jobs.

Digital security has to involve the whole organisation, rather than individual departments or applications.

Mike Neuenschwander, research director at analyst Burton Group, says that identity-based access systems are becoming essential for enterprise infrastructure. ‘Large-scale issues ranging from identity theft and public safety to business trust and corporate accountability are symptomatic of an infrastructure pushed beyond its design parameters,’ he says.

While risk frequently drives identity and access management projects, large organisations are also struggling to meet compliance requirements.

‘As organisations tighten control over information systems to meet security and regulatory goals, managing access to applications and data is becoming the core ingredient in compliance solutions,’ says Neuenschwander.

A poor understanding of information value results in persistent business exposure to risk. Ian McGurk, head of security at consultancy Plan-Net, says that organisations are ignoring the security of sensitive information.

‘Without a robust understanding of the value of business-critical information, including anything from personnel records to client lists, organisations can have little confidence that employees will behave appropriately,’ he says.

It is the lack of awareness among staff of the need for information security that creates problems, resulting in passwords being written down in plain view, giving unauthorised individuals with access to systems.

It can also result in foolish behaviour such as leaving PCs unlocked and open to anyone while away from the desk, or leaving laptops on the back seat of cars rather than locked in the boot. Safeguarding company information depends as much on the people as on the technology.

Kiran Sandford, partner and IT legal expert at law firm Mishcon de Reya, says that from the legal point of view, one of the things that is critical in user identity is education.

‘The majority of users are honest, but there are fraudsters around,’ she says. ‘When users find themselves confronted with a number of different passwords, they get into the yellow sticker syndrome. Education is about users understanding that if they reveal their password it will cause problems to the business, and why.’

See next page for what the experts say about indentity security

reader comments

related articles

Picture of student with books

Students sign on for identity management

Single sign-on for 30,000 students at Anglia Ruskin University 22 Mar 2007

 

Aberdeen signs on for single identity

New identity management software keeps track of 14,000 staff 13 Mar 2007

Case study: Tayside

Tayside Fire and Rescue has seen a dramatic increase in its IT use and needs to address issues of access control and management 29 Mar 2007

Case study: GOSH

Great Ormond Street Hospital is upgrading its various IT systems to be accessible for all 29 Mar 2007

related whitepapers

today's top stories

What does Windows 7 mean for Microsoft?

With the sting of Vista still fresh, Redmond has to make next Windows work 10 Jul 2009

A smarter way to use BI

Getting the most from business intelligence systems requires not only careful management on the part of IT leaders, but also the committed involvement of decision-makers across the organisation 08 Jul 2009

The truth behind the Google/Microsoft/NHS rumours

Before Monday 6 July, did you know that Google and Microsoft had services for storing health records? Thanks to an article in... 10 Jul 2009

Quenching a thirst for IT modernisation

A substantial restructure at soft drink supplier Nichols -­ purveyor of Vimto - ­led the company to update its software to Sage 1000 to replace its in-house application. This resulted in the streamlining of the IT department and an opportunity to customise the system 08 Jul 2009

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will Google Chrome OS be a genuine alternative to Windows?

Will Google Chrome OS be a genuine alternative to Windows?

Tell us your views on the new operating system rivalry

View poll results

Latest audio and video articles

network cablesVideo

How to maximise the value of your IT networking investment

A panel of experts discuss networking strategies that deliver real value to business 03 Jul 2009

green footprintsVideo

How to manage enterprise energy use - and the role IT can play

A panel of experts explore how firms can get to grips with their carbon footprint and make smarter use of energy 01 Jul 2009

Latest in-depth articles

Google ChromeAnalysis

Lack of enterprise appeal takes shine off Chrome OS

Enterprise buyers unlikely to ditch Windows for Chrome OS in the near term, say experts 09 Jul 2009

Satyam CEO CP GurnaniNews

How Satyam cleaned up its act

Chief executive CP Gurnani tells Angelica Mari why Tech Mahindra opted to keep the Satyam brand after it bought the scandal-hit services firm, and explains what the deal means for existing and prospective customers 09 Jul 2009

Advertisement

Primary Navigation