Trust but verify

Access & Identity Management Handbook 2014 Access Control & Identity Management

As both personal and corporate data and applications move to the cloud and mobile devices, the saying ‘trust but verify’ takes on new meaning. It captures the practical reality of a world in which so many of our interactions occur online. More than ever, we need mechanisms to verify the identity of the entities with whom we interact.

Among the most important best practices is authentication beyond simple passwords. Enterprises have typically focused on securing the network perimeter and relied on static passwords to authenticate users inside the firewall. This is insufficient given the multifarious nature of today’s Advanced Persistent Threats (APTs), ad hoc hacking, and internal risks associated with Bring Your Own Device (BYOD) adoption. Static passwords can be a recipe for disaster and must be extended with other authentication factors. Additionally, multi-factor authentication must be part of a multi-layered security strategy, including device authentication, browser protection, transaction authentication/pattern-based intelligence, and application security. This requires the use of an integrated multi-layered authentication and real-time threat detection platform.

Fraud detection technology has been used in on-line banking and e-commerce for quite some time. Significant changes in this landscape led the industry to institute stringent compliance and customer data protection requirements. Compliance requires the full gamut of authentication and fraud prevention strategies, as well as both on-line and mobile payment security. Solutions must also comply with multifactor authentication options including mobile One Time Password (OTP) soft tokens, transparent authentication, and Public Key Infrastructure (PKI) certificates, along with proactive fraud detection and tamper-evident audit reporting.

Fraud detection technology is expected to cross over into the corporate sector as a way to provide an additional layer of security for remote access use cases such as VPNs or virtual desktops. Meanwhile, two-factor authentication measures, which have typically been confined to OTP tokens, display cards and other physical devices, are now also being delivered through soft tokens that can be held on such user devices as mobile phones, tablets, and browser-based tokens. A phone app generates an OTP, or OTPs are sent to the phone via SMS. For greater security, the authentication credential is stored on the mobile device’s secure element or subscriber identity module (SIM) chip. Mobile tokens also can be combined with cloud app single-sign-on capabilities, blending classic two-factor authentication with streamlined access to multiple cloud apps on a single device.

As identity management moves to the cloud there are other critical considerations. Today, much of the security discussion is focused on securing the platform, but as enterprises continue to move applications into the cloud and take advantage of the Software as a Service (SaaS) model, it will be critical to resolve challenges around provisioning and revoking user identities across multiple cloud-based applications, while also enabling secure, frictionless user login to those applications.

In the BYOD environment, secure authentication becomes even more important, and several other security issues also emerge. IT departments won’t be managing these devices, so it won’t be possible to control other, potentially untrustworthy personal apps they may carry, or to load a standard image onto them with anti-virus and other protective software. Nor will organisations be able to retrieve devices when employees leave. We will need to find new and innovative ways to address these and other challenges

Notwithstanding the risks, the use of BYOD phones, tablets and laptops for access control opens opportunities for powerful new contactless authentication models, from tapping your corporate ID badge to a personal tablet for authenticating to a network, to using an NFC-enabled phone not only as your access credential but also the key for entering your building or apartment.

Source: https://www.hidglobal.com/blog/trust-verify

For more information contact HID Global, +27 (0)82 449 9398, rtruter@hidglobal.com, www.hidglobal.com



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
Paxton launches new phone-based security system: Solo
Paxton News & Events Access Control & Identity Management
Paxton has officially unveiled Solo, a phone-based, cloud-hosted access control system. As part of the launch, installers can claim a free Solo starter kit from Paxton, allowing them to trial the system and see how it can work for their business.

Read more...
Taking control of IAM in the AI era
Access Control & Identity Management AI & Data Analytics
AI and Shadow AI are proliferating, creating a series of new risks for organisations. To gain control over who and what has access to corporate data, organisations need unified control over their entire environment.

Read more...
Impro announces Primo update
News & Events Access Control & Identity Management Integrated Solutions
Impro Technologies recently held a launch event in which it introduced a series of new products, from new readers through to its updated Primo access management software.

Read more...
If you cannot prove identity, you cannot claim security
Access Control & Identity Management Information Security
Cybersecurity planning for 2026 is a structural change in how attacks are executed and how trust is exploited, demanding that companies stop layering tools on top of infrastructure and instead prioritise intelligence and identity.

Read more...
Paxton set to launch game-changing new system
Paxton Access Control & Identity Management News & Events
Access control is evolving fast. Installers and end users are looking for systems that are simple to install, easy to manage remotely, and flexible enough to scale. In response, Paxton is exploring how emerging technologies can reshape access control.

Read more...
NEC XON secures mobile provider’s hybrid identities
NEC XON Access Control & Identity Management Information Security Commercial (Industry)
For a leading South African telecommunications operator, identity protection has become a strategic priority as identity-centric attacks proliferate across the industry. The company faced mounting pressure to secure both human and non-human identities across complex hybrid environments.

Read more...
Cloud security in visitor management and access control
SA Technologies Access Control & Identity Management Infrastructure Residential Estate (Industry) Commercial (Industry)
Cloud has become the default platform for modern security operations, from visitor management portals and remote access control to incident logging, reporting, analytics, and integrations. But “in the cloud” does not mean “someone else is securing it for us”.

Read more...
Centurion raises the bar at HomeSec Expo
Centurion Systems News & Events Access Control & Identity Management Residential Estate (Industry) Smart Home Automation Commercial (Industry)
Centurion Systems unveiled its latest product lines at HomeSec Expo 2026, introducing SMART+, a simpler way for installers and end users to manage their Centurion installations - as well as a few new products.

Read more...
What’s in store for PAM and IAM?
Access Control & Identity Management Information Security
Leostream predicts changes in Identity and Access Management (IAM) and Privileged Access Management (PAM) in the coming year, driven by evolving cybersecurity realities, hybridisation, AI, and more.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.