Increased complexity complicates identity management

Access & Identity Management Handbook 2015 Access Control & Identity Management, Information Security

As the world has evolved to become increasingly digital and globally connected, ICT security has become correspondingly more complex. With digital pathways into and out of organisations expanding rapidly, businesses today have little visibility of their vulnerabilities and exposure. As a result, security solutions must be seamlessly integrated and work in harmony to provide an holistic view and remediation capability across the entire ICT landscape.

Rory Young, portfolio manager: support & enabling services at T-Systems South Africa.
Rory Young, portfolio manager: support & enabling services at T-Systems South Africa.

Identity and access management (IAM) is a fundamental and critical facet of a connected security ecosystem, as controlling the confidentiality, integrity and authorisation around data is key. There are, however, a number of challenges that exist around this, chiefly that many businesses do not know who is authorised to access what data, when, why and from where. As mobility becomes increasingly pervasive, mobile identity and access services are emerging as the ideal solution for a wide range of IAM challenges.

In the past, IAM was a far less complex task than it is today. Organisations only had to manage identity and access to a few internal business applications, the corporate intranet, and maybe an HR or finance system. It was well understood, contained and controlled, which in turn made for fairly simple management. Today, however, there has been an Internet revolution – a digital revolution (termed the third industrial revolution) – and with it the number of applications used is exploding. Organisations no longer have only a handful of applications and access to manage, but dozens, as digital business becomes everyday business.

Access and analytics

As businesses embrace cloud, Software as a Service (SaaS), mobility and modern collaboration in order to remain relevant and competitive, they add layers of complexity when it comes to managing and controlling identity and access. Traditional network and corporate boundaries no longer exist, physical boundaries are eroded, organisational structures and hierarchies are challenged. Keeping pace is a challenge, and organisations frequently struggle to control and manage access to the plethora of loosely coupled applications. Ultimately this exposes the business, its corporate IP and customer data to very real risk.

In order to mitigate this risk, remain compliant with regulations around confidentiality of data, access thereto and integrity thereof, organisations need greater control over who is accessing what, where and when across the now extended corporate boundary. In addition, existing domain IAM and security policies need to be extended into the SaaS cloud services as well as mobile devices and applications. They also need to be able to provide assurances that adequate security is provided, meets the needs of business, and can stand up to the scrutiny of any audit.

Organisations need solutions that not only provide identity and access controls but also rich analytics in order to better understand how data is being accessed and consumed by various roles across their organisation. This in turn allows for more informed and durable decisions to be made regarding IAM strategy, policy and target investment on an on-going basis. Given that the digital revolution is characterised by the proliferation of ubiquitous connectivity and computing that enables almost anyone to access information, systems and services from anywhere, any time and on any device, the digital business has become the norm. Mobile devices are everywhere, and thus offer the ideal platform for effective IAM in a digital, connected world.

Mobile identity and access

Mobile identity and access services can integrate the multiple forms of physical proof of identity we use today, from drivers’ licences and identity cards to passports, loyalty cards and more with online digital identities into a single mobile application or network. Identity document (ID) credentials and attributes are securely stored in a central location for various forms of interaction that require ID verification. These include visualisation and validation of ID, credentials, qualifications, licences and so on, system and application login, physical access control, document approval with trusted digital signatures and more.

Mobile identity and access services give organisations greater control and assurances over security and protection in multiple areas. In addition, centralising IAM provides organisations with a real-time global view of identity and access activity. Multi-factor authentication capability not only ensures enhanced security, but also allows for richer and deeper activity analysis. In addition, proactive alerts can be set, for example if a user appears in two locations at the same time or if there are consecutive uses where the locations are too far apart based on the access time recorded. Data can also be analysed to determine who is accessing what, where and when, which enables organisations to continually drive optimisation and efficiencies across the enterprise security landscape.

With more applications and forms of identity than ever before, consolidating and centralising this for enhanced security, convenience and analytical capability is essential. Mobile identity and access services provide the ideal platform to enhance security, provide effective IAM, and deliver advanced analytics that can be used to drive more intelligent business and security decisions.

For more information contact T-Systems South Africa, +27 (0)11 266 0266, lebohang.thokoane@t-systems.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Data security and privacy in global mobility
Security Services & Risk Management Information Security
Data security and privacy in today’s interconnected world is of paramount importance. In the realm of global mobility, where individuals and organisations traverse borders for various reasons, safeguarding sensitive information becomes an even more critical imperative.

Read more...
Sophos celebrates partners and cybersecurity innovation at annual conference
News & Events Information Security
[Sponsored] Sun City hosted Sophos' annual partner event this year, which took place from 12 to 14 March. Sophos’ South African cybersecurity distributors and resellers gathered for an engaging two-day conference.

Read more...
The CIPC hack has potentially serious consequences
Editor's Choice Information Security
A cyber breach at the South African Companies and Intellectual Property Commission (CIPC) has put millions of companies at risk. The organisation holds a vast database of registration details, including sensitive data like ID numbers, addresses, and contact information.

Read more...
AI augmentation in security software and the resistance to IT
Security Services & Risk Management Information Security
The integration of AI technology into security software has been met with resistance. In this, the first in a series of two articles, Paul Meyer explores the challenges and obstacles that must be overcome to empower AI-enabled, human-centric decision-making.

Read more...
Milestone Systems joins CVE programme
Milestone Systems News & Events Information Security
Milestone Systems has partnered with the Common Vulnerability and Exposures (CVE) Programme as a CVE Numbering Authority (CNA), to assist the programme to find, describe, and catalogue known cybersecurity issues.

Read more...
Defending against SIM swap fraud
Access Control & Identity Management
Mobile networks must not be complacent about SIM swap fraud, and they need to prioritise the protection of customers, according to Gur Geva, Founder and CEO of iiDENTIFii.

Read more...
Access Selection Guide 2024
Access Control & Identity Management
The Access Selection Guide 2024 includes a range of devices geared specifically for the access control and identity management market.

Read more...
Biometrics Selection Guide 2024
Access Control & Identity Management
The Biometrics Selection Guide 2024 incorporates a number of hardware and software biometric identification systems aimed at the access and identity management market of today.

Read more...
Smart intercoms for Sky House Projects
Nology Access Control & Identity Management Residential Estate (Industry)
DNAKE’s easy and smart intercom solution has everything in place for modern residential buildings. Hence, the developer selected DNAKE video intercoms to round out upmarket apartment complexes, supported by the mobile app.

Read more...
Authentic identity
HID Global Access Control & Identity Management
As the world has become global and digital, traditional means for confirming authentic identity, and understanding what is real and what is fake have become impractical.

Read more...