Picture of access denied error message
Software access control is vital for security

Identity crisis

Problems with employee access and identity management continue to plague IT departments

Written by Linda More

Businesses are becoming increasingly aware of the importance and value of maintaining their employee’s identities and controlling who can access confidential business information.

However, given the steady increase in identity theft and the misuse of confidential business data, some are clearly not managing their employees’ identities and access as well as they should. Such issues are affecting the ability of organisations to comply with regulations, as well as having a financial and confidence impact when sensitive information is leaked.

Donal Casey, security adviser with business consultancy Morse, says this is not an easy problem to fix.

‘Modern business environments are as intricate and complex as spiders’ webs, comprising a multitude of applications, diverse information points and varying types of users,’ he says. ‘This makes it difficult to determine and control how information is accessed and used.’

Without the correct security measures in place to determine who can access information, users may be able to retrieve any confidential information they want, with potentially disastrous consequences for the business. Providing legitimate network access, while retaining control over hackers and unscrupulous employees, has become a delicate balancing act.

The biggest challenge to corporate security today is the human factor – be it a disgruntled or careless employee or a sophisticated professional hacker.

According to research published last year by YouGov, almost a third of UK company directors take confidential corporate information with them when they change jobs.

Digital security has to involve the whole organisation, rather than individual departments or applications.

Mike Neuenschwander, research director at analyst Burton Group, says that identity-based access systems are becoming essential for enterprise infrastructure. ‘Large-scale issues ranging from identity theft and public safety to business trust and corporate accountability are symptomatic of an infrastructure pushed beyond its design parameters,’ he says.

While risk frequently drives identity and access management projects, large organisations are also struggling to meet compliance requirements.

‘As organisations tighten control over information systems to meet security and regulatory goals, managing access to applications and data is becoming the core ingredient in compliance solutions,’ says Neuenschwander.

A poor understanding of information value results in persistent business exposure to risk. Ian McGurk, head of security at consultancy Plan-Net, says that organisations are ignoring the security of sensitive information.

‘Without a robust understanding of the value of business-critical information, including anything from personnel records to client lists, organisations can have little confidence that employees will behave appropriately,’ he says.

It is the lack of awareness among staff of the need for information security that creates problems, resulting in passwords being written down in plain view, giving unauthorised individuals with access to systems.

It can also result in foolish behaviour such as leaving PCs unlocked and open to anyone while away from the desk, or leaving laptops on the back seat of cars rather than locked in the boot. Safeguarding company information depends as much on the people as on the technology.

Kiran Sandford, partner and IT legal expert at law firm Mishcon de Reya, says that from the legal point of view, one of the things that is critical in user identity is education.

‘The majority of users are honest, but there are fraudsters around,’ she says. ‘When users find themselves confronted with a number of different passwords, they get into the yellow sticker syndrome. Education is about users understanding that if they reveal their password it will cause problems to the business, and why.’

See next page for what the experts say about indentity security

  • Have your say
  • Send to a friend
  • Print this
  • Share

reader comments

related articles

Picture of student with books

Students sign on for identity management

Single sign-on for 30,000 students at Anglia Ruskin University 22 Mar 2007

 

Aberdeen signs on for single identity

New identity management software keeps track of 14,000 staff 13 Mar 2007

Case study: Tayside

Tayside Fire and Rescue has seen a dramatic increase in its IT use and needs to address issues of access control and management 29 Mar 2007

Case study: GOSH

Great Ormond Street Hospital is upgrading its various IT systems to be accessible for all 29 Mar 2007

related whitepapers

today's top stories

Telepresence: coming to a screen near you?

Telepresence systems enable organisations to hold boardroom-style meetings with far-flung participants without the hassle and expense of arranging travel and accommodation. But while the technology is impressive, it does not come cheap, as Martin Courtney discovered when he sat in on a virtual meeting with executives from Philips 10 Mar 2010

Users give their verdict on Azure

Some of the first wave of UK adopters met in London recently to air their views on Microsoft’s cloud computing platform. Dave Bailey listened in 10 Mar 2010

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

Publishing special - Publishers innovate to survive

1) IT could hold the key to the future of publishing 2) Case Study: The Guardian harnesses social and mobile apps 3) How publishers are reacting to the iPad 02 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

NHS centralised data

NHS centralised data

Do you think the NHS can be trusted to safely look after personal data electronically?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

Martin CaveComment

Lessons to be learned from cricket's internet outing

Imagine the scene. It’s the final of one of the most popular sporting events in the Indian subcontinent and millions of people are glued to their laptops and PCs in anticipation of the four runs required off the last ball of the match. Suddenly the connection jitters and 20 seconds later you see the jubilant crowd flooding onto the field of play… 12 Mar 2010

Wayne GibbonsComment

Social networks are key to cracking China

Business social media can unlock the door to the world’s second-largest economy 10 Mar 2010

Primary Navigation