Increased complexity complicates identity management

Access & Identity Management Handbook 2015 Access Control & Identity Management, Information Security

As the world has evolved to become increasingly digital and globally connected, ICT security has become correspondingly more complex. With digital pathways into and out of organisations expanding rapidly, businesses today have little visibility of their vulnerabilities and exposure. As a result, security solutions must be seamlessly integrated and work in harmony to provide an holistic view and remediation capability across the entire ICT landscape.

Rory Young, portfolio manager: support & enabling services at T-Systems South Africa.
Rory Young, portfolio manager: support & enabling services at T-Systems South Africa.

Identity and access management (IAM) is a fundamental and critical facet of a connected security ecosystem, as controlling the confidentiality, integrity and authorisation around data is key. There are, however, a number of challenges that exist around this, chiefly that many businesses do not know who is authorised to access what data, when, why and from where. As mobility becomes increasingly pervasive, mobile identity and access services are emerging as the ideal solution for a wide range of IAM challenges.

In the past, IAM was a far less complex task than it is today. Organisations only had to manage identity and access to a few internal business applications, the corporate intranet, and maybe an HR or finance system. It was well understood, contained and controlled, which in turn made for fairly simple management. Today, however, there has been an Internet revolution – a digital revolution (termed the third industrial revolution) – and with it the number of applications used is exploding. Organisations no longer have only a handful of applications and access to manage, but dozens, as digital business becomes everyday business.

Access and analytics

As businesses embrace cloud, Software as a Service (SaaS), mobility and modern collaboration in order to remain relevant and competitive, they add layers of complexity when it comes to managing and controlling identity and access. Traditional network and corporate boundaries no longer exist, physical boundaries are eroded, organisational structures and hierarchies are challenged. Keeping pace is a challenge, and organisations frequently struggle to control and manage access to the plethora of loosely coupled applications. Ultimately this exposes the business, its corporate IP and customer data to very real risk.

In order to mitigate this risk, remain compliant with regulations around confidentiality of data, access thereto and integrity thereof, organisations need greater control over who is accessing what, where and when across the now extended corporate boundary. In addition, existing domain IAM and security policies need to be extended into the SaaS cloud services as well as mobile devices and applications. They also need to be able to provide assurances that adequate security is provided, meets the needs of business, and can stand up to the scrutiny of any audit.

Organisations need solutions that not only provide identity and access controls but also rich analytics in order to better understand how data is being accessed and consumed by various roles across their organisation. This in turn allows for more informed and durable decisions to be made regarding IAM strategy, policy and target investment on an on-going basis. Given that the digital revolution is characterised by the proliferation of ubiquitous connectivity and computing that enables almost anyone to access information, systems and services from anywhere, any time and on any device, the digital business has become the norm. Mobile devices are everywhere, and thus offer the ideal platform for effective IAM in a digital, connected world.

Mobile identity and access

Mobile identity and access services can integrate the multiple forms of physical proof of identity we use today, from drivers’ licences and identity cards to passports, loyalty cards and more with online digital identities into a single mobile application or network. Identity document (ID) credentials and attributes are securely stored in a central location for various forms of interaction that require ID verification. These include visualisation and validation of ID, credentials, qualifications, licences and so on, system and application login, physical access control, document approval with trusted digital signatures and more.

Mobile identity and access services give organisations greater control and assurances over security and protection in multiple areas. In addition, centralising IAM provides organisations with a real-time global view of identity and access activity. Multi-factor authentication capability not only ensures enhanced security, but also allows for richer and deeper activity analysis. In addition, proactive alerts can be set, for example if a user appears in two locations at the same time or if there are consecutive uses where the locations are too far apart based on the access time recorded. Data can also be analysed to determine who is accessing what, where and when, which enables organisations to continually drive optimisation and efficiencies across the enterprise security landscape.

With more applications and forms of identity than ever before, consolidating and centralising this for enhanced security, convenience and analytical capability is essential. Mobile identity and access services provide the ideal platform to enhance security, provide effective IAM, and deliver advanced analytics that can be used to drive more intelligent business and security decisions.

For more information contact T-Systems South Africa, +27 (0)11 266 0266, lebohang.thokoane@t-systems.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

There is a SaaS for everything, but at what cost, especially to SMEs?
Editor's Choice Information Security Security Services & Risk Management
Relying on SaaS platforms presents significant cybersecurity risks as the number of providers in your landscape increases, expanding your attack surface. It is important to assess the strength of the SaaS providers in your chain.

Read more...
New State of Physical Access Control Report from HID
HID Global Editor's Choice Access Control & Identity Management News & Events
HID released the 2024 State of Physical Access Control Report, identifying five key trends shaping access control's future and painting a picture of an industry that has been undergoing considerable transformation.

Read more...
Addressing today’s mining challenges: cyber risks beyond IT
Editor's Choice Information Security Mining (Industry)
Despite the mining industry’s operational technology systems being vulnerable to cyberattacks, many decision-makers still see these threats as purely an IT issue, even though a breach could potentially disrupt mining operations.

Read more...
Smart intercoms are transforming access control
Access Control & Identity Management Products & Solutions
Smart intercoms have emerged as a pivotal tool in modern access control. They provide a seamless and secure way to manage entry points without the need for traditional security guards to validate visitors before granting them access.

Read more...
How to effectively share household devices
Smart Home Automation Information Security
Sharing electronic devices within a household is unavoidable. South African teens spend over eight hours per day online, making device sharing among family members commonplace. Fortunately, there are methods to guarantee safe usage for everyone.

Read more...
Fortinet establishes new point-of-presence in South Africa
News & Events Information Security
Fortinet has announced the launch of a new dedicated point-of-presence (POP) in Isando, Johannesburg, to expand the reach and availability of Fortinet Unified SASE for customers across South Africa and southern African countries.

Read more...
New tools for investigation and robust infrastructure security
News & Events Information Security
Cybereason continues to enhance its security platform, with recent updates introducing improvements in file search operations, investigation query results, and cloud workload protection, providing more granular data and faster key artefact identification.

Read more...
Easy, secure access for student apartments
Paxton Access Control & Identity Management Surveillance
Enhancing Security and Convenience at Beau Vie II Student Accommodation, a student apartment block located at Banghoek Road, Stellenbosch, with Paxton's access control and video management solution

Read more...
Invixium acquires Triax Technologies
News & Events Access Control & Identity Management
Invixium has announced it has acquired Triax Technologies to expand its biometric solutions with AI-based RTLS (Real-Time Location Systems) offering for improved safety and productivity at industrial sites and critical infrastructure.

Read more...
ControliD's iDFace receives ICASA certification
Impro Technologies News & Events Access Control & Identity Management
The introduction of Control iD's iDFace facial biometric reader, backed by mandatory ICASA certification, underscores the commitment to quality, compliance, and innovation.

Read more...