Friday, August 1, 2014

Continual IT Audits

Information audits are inconvenient, unpleasant and rarely fun. They are a headache because of the fact that when audit season comes around, they take resources away from several departments for extended periods of time while staff managing and leading them also must continue their other daily roles. Unfortunately, there is no getting around an audit, whether internal or external.

Several major compliance regulations in the United States including the Health Insurance Portability and Accountability Act (HIPAA), the Control Objectives for Information and Related Technology (COBIT) and Sarbanes Oxley Act (SOX) require businesses to ensure certain standards within their organizations, including protection of data and full disclosure. Organizations that do not comply face significant fines and potential punishment.

Since audits are mandatory, organizations need to instead find ways that make dealing with them simpler. This is why organizational leaders should instead focus on conducting continual audits or implementing solutions that can help them stay in line with their audit needs throughout the year. This allows them to perform the work for audits along the way instead of having to do it all at once.

Instead of an annual audit check followed by an extensive clean-up operation, several leading organizations are implementing solutions that allow them to exercise constant control over the identities in their networks, their lifecycles and their authorizations.

Continual Audits

To achieve continual audits, some organizations have utilized identity and access management solutions. An automated account management solution with role-based access control (RBAC) allows a manager to oversee and document exactly who has access to what, and any changes they are making. With RBAC in place, managers can easily see an overview of access and correct any issues that arise. This also makes it extremely easy to provide a list of employees who have access to critical data when it comes to audit time.

These same automated account management solutions allow for other tasks to be continually documented for audits in an organized manner. The system automatically logs which employee performs a particular management activity, as well as the time it occurred. Management reporting can be generated in a wide variety of formats meaning the organization always has an insight into the processes involved and whether they are in compliance with regulations.

Case In Point

The Salvation Army had relied on an inefficient paper system prior to its automated solution. The paper system was almost impossible to audit. The automated account management solution has completely resolved this issue and the organization can now easily meet requirements.

According to the Salvation Army’s Christian Cundall, head of messaging services, the organization needed to introduce a solution for user management and auditing for simple reasons. “We were experiencing 1,000 calls a month to our helpdesk for user account-related changes. Any change requests needed to be confirmed via fax, resulting in a large paper trail, which was impossible to audit. The faxes often contained errors and omissions, adding to the workload placed on our helpdesk; 90 percent of the work needed to be duplicated.”

“We were impressed by the ability to force users to comply with our naming conventions, and provide a full log on all actions for auditing purposes,” said Cundall.


For more information, please visit our website.

Friday, July 11, 2014

The Three Sides to Data Security

n today’s complex corporate and business network environments, controlling access to sensitive data is of utmost concern. The amount of security-related data stored across a network is immense for many organizations, and relating all this data to the user’s account information in Active Directory can be tricky and time consuming.

There are really three sides to proper data security.

The first step is ensuring that new employee accounts are created with the proper access rights when an employee joins the organization. The second is making sure those access rights remain accurate during the employee’s tenure. The third is revoking all access rights when the employee leaves.

Let’s take a more in-depth look at solutions for all three of these phases of data security.

Defining A Role

By using a role-based access control matrix in conjunction with an identity management solution, companies can ensure that accounts for new employees are always created with proper access rights.

The first step of this stage is to define the roles that employees should have in the organization. This is usually a combination of department, location, and job title.

While establishing the data access rights, group memberships, and application requirements for each role can be time consuming, the end result will allow a template for both new employee creation and an audit point in the future.

Software applications are available that will allow the linking of a human resource system to Active Directory for automatic account creation with all proper rights. Additionally, if there are special requirements, a workflow system can easily be established to allow manager and system owners to process approvals before access is granted.

Managing Access and Security

Access rights to data often tend to creep into multiple areas over an employees’ tenure with an organization.

For example, rights are assigned to one employee for special projects while one employee is covering for another on leave or when an employee changes departments and responsibilities. The revocation of these special or historical rights occurs infrequently at best.

Again, software solutions are available to analyze the rights of employees and make the information actionable. For the product to provide value, there are several items that should be considered as mandatory including the ability to detect:
  • Direct access to a file/directory rather than access through a group membership.
  • Access to a file/directory through multiple or nested group memberships.
  • Groups and user accounts that are no longer present in Active Directory.
  • Duplicate access privileges to a file/folder of a user or user group.
  • Access to files/directories through a local or file system user account.

Once an audit of access rights is performed, it can be compared against the baseline template for each employee role initially established. Any deltas can then be sent to managers and systems owners for verification or revocation of the rights.

Revoking Access

The final step in the data security process is one that is often overlooked or not performed in a timely fashion: the termination of access rights to the network, data and all applications, including cloud-based solutions, must be accomplished immediately upon an employee’s termination.

For example: a terminated sales rep had his network access revoked immediately upon departure, but the organization did not have a process in place to disable access in a timely manner to a cloud-based business intelligence application. The terminated employee realized the account was still live and proceeded to download more than 10,000 records over the course of the next 30 days at a cost to the company of more than $6,000.

The point of this story: imagine the costs if 20, 30, or 100 terminated employees did this very same thing in a short period of time.

When putting a process in place to handle terminated employees, the most common scenario is, once again, a link to the HR system.

When an employee is terminated, a synchronization process needs to be in place to handle the decommissioning of accounts in all internal and external systems. If feasible, using web services or application programming interfaces (API’s) to automate the process will save time and money in the long run. Where not feasible, an email workflow process should be established whereby system owners are notified to terminate the account and positive feedback required to establish the work has been completed.

It is imperative that organizations implement the necessary security measures to insure that access to data, groups and applications are right sized for an employee during their tenure. Equally critical is the revocation of all account access when they depart. Failure to meet these criteria can lead to theft of secure data and costly access to external applications.

For more information, please visit our website.

Friday, June 27, 2014

Single Sign-on: Regulating Access Cards

By now, many organizations and employees are aware of the advantages of single sign-on (SSO) solutions because they only have to remember a single password rather than dozens of complex passwords.

In essence, because of the technology, IT departments receive fewer password reset calls, while the organization also can use the solutions to meet its auditing requirements.

Typically, after the number of passwords has been reduced to a single complex password, organizations often replace its remaining password, too. SSO makes this possible by replacing the remaining username and password with an access card and a PIN code. Any type of user card can be used for this; for example, an ID or library card. Users will be logged in automatically by placing their card against, or on, a card reader. The card’s unique ID is then linked to the holder’s username and password. This is referred to as self-service enrollment.

It’s a user-friendly service for employees, but many organizations do not want employees using random card types. Instead, they only want to use cards issued by the organization itself. Because of this, certain cards can be excluded from self-service enrollment, so that physical access cards are only allowed if they are used internally.

Enterprise single sign-on solutions offers the ability to only allow active cards. When a card is issued (when a new employee enters service), it is activated. By setting up a link with the key card system, it’s possible to only accept cards that are used actively within the organization. The main advantage is that the existing and mature facility management process will govern both physical and logical access. When employees leave service, their access cards will be revoked and/or disabled, after which the card is also disabled in the enterprise single sign-on. The result is effectively disabling access to the network and any applications.

Additionally, organizations might go a step further and only accept cards of employees who are physically present within the premises. Another option is to link access cards to the HR system. When the HR system indicates that an employee has left service, that user card will be disabled so that it can no longer be presented to obtain physical or logical access.

Single sign-on combined with a user cards offers a variety of options for integration with other systems, increase security and further protect organizational data.

For more information on SSO, please visit our website.

Friday, June 13, 2014

IAM for Small Businesses - Why they need to focus on identity and access management issues

While often overlooked, small businesses — like large organizations — frequently have numerous identity and access management issues. These include ensuring security of systems and applications, as well as handling copious password issues. Unlike large organizations, though, small businesses often do not have the staff and resources readily available to easily handle these tasks so they either go unaddressed or require more time and money than is necessary.

There are several solutions for small businesses, though, that easily mitigates these problems and save time and money in the long run. The following are common password management issues that small businesses have and how IAM solutions can easily solve them:

Easily Managing Passwords

Employees, no matter what the size of the organization, often have many sets of credentials they need to use when logging into their applications to perform their jobs. To remember multiple sets of credentials, they often write down their user names and passwords and store them somewhere near their desks. Doing so puts the organizations applications at risk and reduces the security.

An easy way for small business to reduce the headache of multiple passwords for their employees to manage, as well as to ensure the security of their systems, is with a single sign-on (SSO) application. With an SSO solution, employees only have to remember one set of credentials. These allow them to enter their single user name and password one time and, thereafter, are automatically signed into all applications and systems once they are opened.

It also ensures that employees will not use non-secure methods to remember their passwords.

Dealing with Sensitive Data

Like larger organizations, small businesses often deal with sensitive data and information that needs to be kept secure. They often need to ensure that this information cannot easily be accessed by just anyone in the organization.

Many small businesses have solved this issue by implementing a single sign-on solution in combination with two-factor authentication. This allows small businesses to add another layer of security to systems and applications. Two-factor authentication is used by requiring users to present a smart card, as well as a PIN code, to access certain systems. Two-factor authentication also can be customized to the needs of the organization such as having the computer remember the PIN for a defined period of time after it is entered or automatically closing all sessions on the computer after the smart card is removed. Each of these customizations adds additional security to the systems, as well as improving efficiency for the user.

Quickly Resetting Passwords

When an employee forgets his password, or is locked out of an application, he usually needs to go through the time-consuming process of resetting his passwords. In a small business, there may not be a 24×7 helpdesk to call to resolve this issue. If there is a helpdesk or IT department, focusing on password resets can take away from the department’s time of focusing on other issues.

The IAM solution that can easily help with this issue is a self-service reset password solution. This allows end users to easily and securely reset passwords themselves. Users simply register by providing answers to a few personal questions — much like a banking website — then when they need to reset their password they simply click the “forgot my password” button, provide the correct answers and are able to reset their password without having to contact anyone else at the company. This reduces the annoyance of password resets for both the IT department and the end user, and allows employees to both be productive and work on more important tasks.

Overall, small businesses have many of the same issues that larger organizations deal with but often do not have the budget to deal with them. By implementing one or all of the solutions they are able to reduce the amount of time the IT staff spends dealing with these issues, and not need to have an employee working full time to handle them, thus drastically reducing their own administrative costs.

For more information, please visit our website.

Friday, June 6, 2014

Security Solutions for Working Remotely

In the last six years working remotely grew a staggering 73 percent. One of four U.S. employees works remotely at least some of the time and that doesn’t include people who work remotely because they travel regularly. Richard Branson, founder of Virgin Group, blogged, “One day offices will be a thing of the past.” Until then, though, security issues with working remotely need to be ironed out.

Yet another major trend is universities and education entities creating online programs for students who live far from campus, prefer schooling from home or have less time to complete a program at traditional school times.

Though working from home, whether it’s for a company or for school, has many benefits, it causes significant issues for both the organization’s IT department and the end users.

Here are three major issues and solutions.

Issue #1: Managing accounts for remote employees

Correctly provisioning accounts for hundreds or thousands of users who are not physically working within the walls of an organization can be a major headache for IT. It also can be an issue for the end users as employees and students need their accounts quickly and correctly provisioned so that they can begin their work and have access to the systems and applications that they need.

In addition, ensuring that employees that are no longer with the company are correctly de-provisioned also needs to be done properly. A disgruntled employee that has access to the organization’s network can cause a great deal of havoc to its data.

Issue #2: Losing track of who has access to what

Amidst all of the account provisioning, granting access and revoking access to the many cloud applications, organizational IT leaders can easily lose track of exactly who has access to what. This can become not only a security issue but also a problem for licensing costs since the organizations do not know exactly how many licenses they need to buy or maintain.

In addition, this can be a problem when needing to audit systems since it is difficult for the organization to show and document who has access to what data.

Issue #3: Dealing with password issues

Like students or employees working on site, those working remotely tend to have difficulty remembering their credentials for the many different applications they need to access. Especially for employees who are on the go, contacting the IT department can be a major hassle. Needing to contact the help desk to have a password reset while working remotely is a huge annoyance, not only for the end user but also for the IT department since they get copious amounts of these types of calls.

So are these issues solved?

Leading businesses and several educational entities use identity and access management solutions for resolving these issues.

Managing accounts. An automated account management solution can allow the IT department at any organization to easily complete a form, check the boxes for which systems user accounts need to be created in and accounts are automatically provisioned. This task can even be delegated to less technical staff if needed, such as help desk employees.

When employee or student accounts need to be disabled, help desk employees can easily de-provision users without manually going into each system and application.

Additionally, the accounts also can be placed into a different category, such as “alumni,” where they have limited access to systems, but can still utilize their email account, for example.

Managing access. To keep track of exactly who has access to what, a centralized dashboard can be used to provide an overview of which users are deployed in each application. This allows the organization to know exactly who has access to what, and how many licenses they need for each application.

Managing passwords. A single sign-on solution helps with password issues. This allows users to log in once with a single set of credentials and thereafter gain access to all other applications for which they are authorized.

If a password needs to be reset, a self-service password reset software is a helpful solution for remote employees and students. This type of solution allows end users to reset their own passwords without having to contact the help desk. Users can answer security questions that they have previously provided answers to and quickly reset their passwords.

With all or some of these solutions, organizations and educational entities provide a better experience to their users that work remotely and also enable them to work more efficiently.


For more information, please visit our website.

Friday, May 30, 2014

Automating Schools' User Management Makes Dollars and Sense

For schools, budgets are always tight. Add to that strict regulations and reduced financial support from local and county government, and they are under enormous pressure to operate efficiently.

One solution many districts are using to reduce budgets and streamline efficiencies is automating user accounts of students and staff. Countless schools throughout the U.S. are using simple solutions to manage the thousands of user accounts they create at the beginning of each session and host throughout a term.

Hutto School District in Texas implemented a user management resource administrator (UMRA) system to automatically manage user accounts including password re-sets, saving the district an average of three hours for each help desk request generated by a user.

North Hunterdon-Voorhees School District in New Jersey uses a similar UMRA to automate the process of provisioning and de-provisioning student user accounts so that its internal IT department no longer spends countless hours performing password re-sets and managing the deluge of daily helpdesk tickets related to account access issues.

And Murray Independent School District in Kentucky uses an UMRA to maximize efficiency while receiving less funding, said Rusty Back, the school’s CIO.

“Before we used the user management resource administrator, I manually managed the creation and deletion of user accounts,” Back said. “These tasks took up most of my time, and the demands placed on IT continued to increase. We needed processes that would allow me to perform other, more important IT duties.”

User management systems allow IT staffs the power to push password reset abilities and account modifications to the staff via a web portal. The web portal lets faculty and staff reset student passwords without having to wait for an IT staff member to fulfill the request. And because passwords can be reset by the faculty and staff, there is little to no down time for students.

Educators seeking alternatives to hiring additional staff to manage user accounts can find automated solution like UMRA to create, change and delete user accounts for both students and staff, replacing manual execution of account creation.

Travis Brown, Network Administrator for Hutto ISD said, "The user management resource administrator software saved our district considerable man hours and resources by automatically managing our user accounts in Active Directory. We began saving time and money immediately."

The systems automatically synchronize data between the student information system, the campus and Active Directory, eliminating the need for manual redundancies or needless hours spent managing user accounts by members of the helpdesk staff.

The software manages bulk user creation, modifications and deletions for the district. What was once a manual process can now be automated and run daily within a school environment. Data is pulled from the cloud and synced with the school’s Active Directory at each project run, ensuring user accounts are up to date and that Active Directory is clean, organized and has a consistent folder structure.

“The software saves us from having to do manual scripting and spending resources on tasks that can be automated,” said Brown. “Our team can now focus on high-impact projects that benefit the entire Hutto district.”

At Pinellas County School District, in Pinellas County, Florida, the district has 138 schools ranging from pre-K to 12th grade, as well as an adult school for community and work force education. With 103,000 students, 8,500 teachers and more than 200,000 parents, the IT staff spent an inordinate amount of time correcting account problems and the help desk received a large volume of calls about password issues.

One of the biggest problems for the district was addressing the needs of its teachers, who often had problems when they were off for summer break and either forgot their password or were locked out because of password expiration over this time period.

The school implemented an UMRA solution to automatically populate the parent portal, student information system and any other systems as required, eliminating a tedious and potentially error-prone manual process.

“Parents are very connected these days, so they need to have access to the parent portal to get an answer on any questions that they have,” said John Just, assistant superintendent at Pinellas County School District.

Within the first year of roll out, Pinellas enrolled more than 200,000 parents in both UMRA and a separate self service reset password manager (SSRPM) concurrently. SSRPM is a self-service application that allows end users to reset their Active Directory passwords. The number of password-related calls to the helpdesk has been reduced significantly, said Just.

As another school year opens, IT leaders within school settings have at least one option for cutting costs and trimming the number of man hours spent handling redundant tasks. Perhaps, doing so allows for much needed time and resources to be sent in more important places, like the classroom.

For more information, please visit our website.

Friday, May 23, 2014

Contract Employees and Account Management

If your company hires contract employees, outside workers, or employees who work for a limited amount of time, you know all too well that managing these types of accounts can be a headache! With these types of accounts, there is constant movement and employees of this type need to be quickly added but then also promptly removed when they are no longer working for your company.

In addition, since contract employees are often only working for a short period of time, they need to have their accounts quickly created so that they can start performing their jobs. Unlike other employees, they cannot be waiting around for days for all their accounts to be created and access appropriate applications. Employees who are brought in during the hectic holiday season especially need to have access quickly so they can begin working. The issue though, is that in a large organization this could process could take up to a few days.

Due to the high turnover rate of these types of employees, IT also needs to ensure that their accounts are properly disabled once they leave the company. More times than not this task is over looked since someone has to go into each application and manually disable the user, which is time consuming. This is an extreme security risk since these ex- employees will still have access to the company’s data and network. There have been many cases where disgruntled employees either reap havoc on their ex employers network, or steal important customer data. Dealing with the headache of contract employees accounts, is an issue that organizations of all sizes face.

Many leading organizations have solved this issue using Active Directory management software. The following is how they have used this type of solution to solve the account management issue of contract employees:

 Provisioning Accounts
An AD Management solution allows the organization to automate the account management process and not have to manually perform tasks such as creating and disabling accounts. By connecting with your company’s HR system, any change that is made in that system is automatically synchronized to all connected applications.

 So, when someone enters a new personnel request the solution can automatically create new accounts in any connected system or applications, create a share drive, personal drive, profile, set up a phone, or many other tasks for new hires. The manager in charge then receives an audit trail of all actions and can continue to request additional services needed, such as hardware or mobile devices. This allows contract employees to receive access to all of the resources they need quickly so that they can begin work on their first day of employment.

 Disabling Former Employees
To handle the issue of disabling former employees, an AD management solution can assist with automatically disabling accounts. Once an employee is disabled in the source system, the software automatically disables their AD and all connected accounts to ensure the employee no longer has access. It also has the ability to transfer that employee’s personal drive to their manager. This ensures that any projects that were in the works are not lost.

In addition, a set expiration can be placed on an account. This allows the organization to ensure that an account is automatically disabled on a certain day, so that no action has to be taken at all.

Many organizations around the world deal with managing accounts for contract employees. Often they do not realize that there is a simple solution which many of their counterpart’s use, which can reduce the headache, allow employees to be more productive, and increase overall security. “An AD account management solution has not only helped improve the security of access by terminating faster, it has also greatly improved our data security,” said Dan Backer, Director, Campus Technology, at National Geographic.


For more information, please visit our website.