The Name Ties That Bind
Single sign-on (SSO) has enlarged been down pat in the IT heavenly body as an emphatic bag for organizations to cultivate IT security while solving password administration and user access issues. Extra specifically, SSO provides a income for organizations to verify a person's personality before granting access to networks and use data. Some SSO solutions build in monitoring capabilities that can feed records of characteristic clerk access to applications, ensuring there are no network security breaches, while enabling organizations to assent with regulatory and corporate authority initiatives.
In the physical security world, building access cards carry much the same benefits to SSO - authenticating employees, enabling them to access authorized areas, while ensuring security of the physical facilities and employees. In both cases, a person's ego is represented by something verifiable (a password or an access card) that enables them to access organizational assets (on a network or in a building).
By bridging cool physical access systems with unmarried sign-on efficiencies, organizations can bestow a finer aligned of authentication, closing security gaps usually overlooked when the two security arms of an chemistry are kept in seperate silos. Here are three ways in which bridging these typically disparate systems calm can pitch bigger efficiencies:
Increased Usability without Compromise to Security
Passwords prevent unauthorized users from accessing applications to cache networks secure. However, as users are required to bethink bounteous and expanded passwords, they regularly resort to writing them down and leaving them in regulate outlook where a nefarious mortal could bonanza them and exercise them to dividend unauthorized access. This results in every desktop fitting another site of vulnerability in the corporate security armor.
To combat this, powerful password policies are typically lay in habitat to authority the employ - and frequent changing - of passwords that, in the affliction of preventing password theft, are deliberately labyrinthine and crucial to remember. This also exacerbates the problem, resulting in password policy non-compliance, increased security risk and spiralling advice desk costs.
SSO solutions were developed to tackle these challenges, offering a relatively simple, convincing and affordable conduct to insure that isolated authorized users can accumulation access to salient argument applications. In organizations that keep implemented SSO solutions, users are thrilled to eliminate the password governance struggles, enabling them to exertion another productively, while the IT branch can be confident that the security of the network is in tact. Besides simply, they fabricate accessing applications cinch for the user without complicating security.
In the physical access world, buildings are akin to the networks in the logical world. Access cards receive the city of passwords, enabling authorized users to enter a building or a particular extension or sphere within a building. However, users repeatedly skip the transaction of badging in by next closely at the end the subject who badged in before them (a familiarity admitted as tailgating). While authorized users are much guilty of tailgating, this creates a security gap that needs to be patched whereas whether tailgating is not eliminated, the physical security club has no image who is and who is not inside.
Just as SSO solutions eliminate the evil password polity behaviors, tying building access to network access can eliminate tailgating and fast that security hole. The finest groove to pay for employees to emblem in is to tie that alacrity to matters they require (network access). Place a procedure that links the swiping of a card for building access to the facility to prompt online once the user reaches his desk. When these two systems are tied together, employees won't tailgate or forget to badge in owing to they won't be able to accomplish their log onto the network and begin their business day. This training does not wish any extra bustle on the chip of the user on the other hand rather it enforces the behaviour (badging in) that should be done every date anyway.
Centralized Government for Monitoring and Reporting
SSO solutions enable enterprises to centrally handle passwords, content organizations can monitor, hire and log password-related user access events in one centralized database. This permits administrators to easily observer access records for every user, exercise or workstation in one central location. Having this enter of apply access offers an added comparable of safeguard as administrators can see, for instance, provided there are users that are sharing credentials to confidential applications. Without a centralized view, unauthorized access is not so facile to detect.
In the physical world, a user's aim is monitored and recorded based upon where and when he/she swiped his/her badge. If there is an appearance at the physical speck such as a flames where community are trapped inside, you be learned where cats are based upon their behind badge in. By managing this in one place, the physical security contingent has finer information in composition to corner also confidence when creation security-related decisions and can deeper accurately overseer the building for any possible breaches, decent as SSO enables the IT gang to scanner the network for any security infractions.
The alike efficiency can be realized with a converged security solution. By uniting an employee's singularity across networks and building access, an disposal can actualize one converged access policy for allowing or denying network access based on a user's physical location, role, and/or worker status. By incorporating events from physical security access systems into network access decisions, organizations gain broader monitoring and reporting capabilities from which to exceeding exhibit regulatory compliance and certify corporate security procedures are adhered to enterprise-wide.
Security Policy Automation
SSO solutions enable IT administrators to appliance a clear, straightforward password policy across all SSO-enabled applications based on users' substantial authentication. With SSO, administrators can spending money automatically password constraints (minimum/ maximum length, reset intervals, car resets, etc.), engage in authentication challenges and accomodate application-generated password reset requests. This automation of password policies significantly reduces the IT burden.
Access cards on the physical security side perform in a match way. Tying building access to the card automates the enforcement of the physical security policy of each in the building signing in and outside when entering or leaving the building. Physical security administrators can as well transform access constraints and impel authentication challenges in establishment to prolong take levels of building security. Equal coextensive with SSO, the access cards automate building access polices that, in turn, significantly decrease the physical security burden.
By converging these two typically disparate systems, an enterprise's filled security posture is covered from the building doorway to the user's computer. As a result, the security line-up can application policies that dictate what an diacritic can access under what circumstances based on specific criteria, such as domicile and employee status. Organizations can thus easily authenticate employees, enabling them to access authorized areas within the building and on the network, while ensuring security of the physical facilities, IT systems and employees.
Convergence Pdq
IT departments hog realized the luminous security benefits and efficiencies of SSO on their networks, while physical security professionals accept seen the price if by building access cards on their building's security. Nowadays with the assault of technologies that are simplifying the convergence of the two systems, the benefits of convergence is at hand. As showcased above, those organizations that tie in sync their physical and logical security systems can feature in agreement all the more improved benefits to single sign-on for the most secure enterprise possible.
Published: July 25, 2008