Home > Midmarket CIO Tips > Security for the midmarket > Implementing ID and access management (Part 2)
CIO Midmarket Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY FOR THE MIDMARKET

Implementing ID and access management (Part 2)


Joel Dubin, Contributor
03.16.2006
Rating: -3.80- (out of 5)


Technology news and tips for Midmarket CIOs
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


This is the second in a two-part series on identity and access management options for SMBs.

In the first part of this series, we reviewed the first three steps in setting up an access management system at a small or midsized business (SMB). The three steps are evaluation, planning, and implementation and provisioning.

Once the evaluation and planning phase is done, it's time to pick products and begin implementation.

For this tip, I've set up a fictitious SMB to illustrate the implementation phase.

More information

Setting up identity and access management for SMBs (Part 1)

 

IT Management Guide: Identity management in SMBs

The SMB has 800 employees spread among six offices. Four of the offices are in the U.S., one office is in London and another in Hong Kong. All the offices are wholly owned and operated by the company. There are no agents, subsidiaries or local joint ventures. This is an important point: If the offices are part of a single company, most likely they're on the same network. This simplifies your options.

Some offices handle only special functions. The office in Hong Kong oversees manufacturing in China. The London office handles sales that have just started to grow in Europe. The U.S. offices do everything.

The backbone of the SMB's network sits on Windows Server 2003. This includes all the file servers, database servers, the e-mail system and other network applications. The users have either desktops or laptops, not both. The desktops and laptops run Windows XP Professional. The laptops are used by the sales staff members, who are always on the road, a few executives and a handful of telecommuters.

The entire staff uses three or four different applications, including e-mail, depending on each employee's work. Each application requires its own unique user ID and password.

Finally, the overworked network staff members overseeing this far-flung operation double as your information security department. They already provision user IDs and passwords and have the skills and experience to implement and deploy access control systems.

What to look for:

Access management products should have the following features:

  • Can be handled by existing staff, no additional staff needed.
  • Scalable for future employee growth.
  • Flexible, allowing new authentication systems to be added.

Recommended plan for office-bound employees:

For office-bound employees doing routine office work, stick with Active Directory (AD), since the network is already running Windows Server 2003. It's already built-in, and it has been part of Windows servers from Windows 2000 onwards. AD is flexible for segmenting access among the different, and sometimes competing, user groups within your company. It is scalable up to millions of users, so it can meet future growth. It works well with other authentication systems you may consider adding in the future, such as smart cards or biometrics.

That leaves two pressure points: your remote users and the multiple user IDs and passwords your users need for access each time they log in.

For the remote users, consider using a Secure Sockets Layer virtual private network (SSL VPN). An SSL VPN allows a remote user to access your network from a simple Web browser. That means anywhere. Your road warriors can get in to do their work right from their laptops, whether in a hotel, at a customer site or waiting in an airport lounge. Other office-bound employees, who might travel occasionally, can also use the SSL VPN from any Web browser where they're stationed.

No tokens, or complex hardware, are required as in IPsec VPN installations, and the cost is substantially lower. Seattle-based Aventail Corp. has a popular SSL VPN product on the market. It consists of a single appliance installed in your network that acts as a secure SSL VPN Web server.

There's only one drawback. SSL VPNs are basically a Web application. That means they have the same strengths and weaknesses as any other Web application. They need to be properly secured and should time out if the user walks away from their laptop or terminal. This prevents a malicious user from casually entering your network through a still-open browser window to your SSL VPN.

To solve the multiple login problem, Imprivata offers a lightweight single sign-on (SSO) solution. Like Aventail, Lexington, Mass.-based Imprivata Inc.'s OneSign is a dedicated appliance installed on your network. It doesn't use complex scripts on already crowded servers, like other SSO solutions. It's aimed at midmarket companies because of its easy installation and low maintenance. It can be remotely managed and is scalable for new users and new authentication devices.

With these solutions, our SMB can implement a sound access management strategy for the different needs of all of its offices. And the information security staff, masquerading as the network department, can handle everything efficiently.

Joel Dubin, CISSP, is an independent computer security consultant in Chicago. His specialty is Web and application security and he's a Microsoft MVP in security. He is also the author of The Little Black Book of Computer Security, which has tips on setting up an access management system. The book is available from Amazon.com


Rate this Tip
To rate tips, you must be a member of SearchCIO-Midmarket.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Information security management for the midmarket
San Francisco network lockup justifies CIO fears
A cloud computing takeover? Google thinks so
An IT spring cleaning for CIOs
Single sign-on: Sensible security on scale
Spyware defense for the midmarket
Federal breach notification stuck in Congress
Anti-spam tricks for the midmarket toolbox (expert podcast)
Pre-emptive strategy best approach to breach notification
CIOs under fire and in front of the camera
Compliance-burdened CIOs turning to security management tools

Risk management for the midmarket
Legal Expert: MDM can advance compliance goals
Database security: Limiting access is key
San Francisco network lockup justifies CIO fears
Security monitoring tools: Better to buy than build?
Risk assessment frameworks easy to employ
Marquette CIO enhances student safety with virtual patrolling
Spyware defense for the midmarket
How to choose a DR service provider
Data destruction made simple and cheap
Spyware menace eludes SMBs

Security tools for the midmarket
Legal Expert: MDM can advance compliance goals
Database security: Limiting access is key
San Francisco network lockup justifies CIO fears
Security monitoring tools: Better to buy than build?
CIO Kathy Lang: Virtual patrolling center enhances campus safety
Marquette CIO enhances student safety with virtual patrolling
Spyware defense for the midmarket
Anti-spam tricks for the midmarket toolbox (expert podcast)
Compliance-burdened CIOs turning to security management tools
Information security requires organized teams

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2007 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts