Friday, January 25, 2013

Are you prepared for a software license audit?

Are you expecting a software license audit in the coming year? Are you concerned that the number of licenses you have purchased deviates greatly from the number of software applications actually used? If you do not have a good overview of the correlation between purchased and actually used licenses, your organization runs the risk of incurring a substantial fine. Added to which, your software costs may turn out higher than necessary because of some licenses not being used at all.

The latter is a common problem for many companies, and occurs when new employees enter service and the privileges of employees in similar functions are copied to their user accounts. This often includes rights to applications the employee may not actually require. In other cases, temporary access rights to applications that employees require for a particular project are not revoked once the project has been completed. Even worse, accounts by employees who have left the organization are not terminated. As you can see, there are plenty of reasons why the number of licenses actually used might not match the number of purchased licenses.

So how can you solve this problem and manage your license costs more effectively to be better prepared for future software license audits? Tools4ever offers various options:

  • Automated user provisioning & role-based access control: Using the HR system as the source system for creating, modifying and removing user accounts and authorizations, employees can be assigned temporary access to the network and the applications they need. In the licensing context, this also ensures that the rights of former employees are revoked in a timely fashion. Combined with Role Based Access Control (RBAC) – a solution that lets you assign rights based on the role or title of employees – rights will only be assigned once a consensus has been reached on the applications that employees actually require for their daily work.
  • Real Use Dashboard: Tools4ever provides IT managers, systems administrators and application administrators with a dashboard that lists the number of times an application has been launched by an employee, the number of minutes the application has been used as well as the idle time in minutes. If an application remains unused for a long period, the application can be revoked or the user can be given a warning. The total license costs and the status of used applications can be mapped out using an interface with a facility management system or IT service management system.
  • Passive auditing: UMRA offers an option to periodically send managers an overview of the rights and applications to which the manager´s team have access. This reporting can take place, for instance, once a quarter or once a year for the software license audit. Managers can conveniently check whether everything is in order and give their approval. They can also make changes that will be implemented automatically.
To make a long story short, if you are expecting a license cost audit in the near future and want to prevent fines or to cut your license costs, make sure to take the correct precautions. For more information, please visit our website.

Friday, January 18, 2013

Bring Your Own Device and Security

As the trend of bring your own device (BYOD) continues to gain traction in the corporate world, the education arena, colleges and universities especially, have been dealing with this concept for years. Their experiences can certainly lend ideas to the business world in securing the devices and the network.
  • The following are some ideas and suggestions to insure a safe BYOD environment:
  • Limit the types of devices allowed. Instead of trying to have the IT group support everything under the sun, provide guideless to employees on the types of devices that will be supported under a BYOD policy.
  • Register the devices MAC address and/or NetBIOS name.  Instead of making this a burden on the IT staff, put up a website on the intranet with very detailed instructions and require end users to register and secure their devices.  
  • Require up to date virus protection software. Most companies purchase bulk licenses for anti-virus programs and requiring end users to have the latest versions on their devices is an important aspect of security.  
  • Require users to set passwords / lock screens or hard drive encryption, if applicable, on devices to insure that a lost or stolen machine will not result in the access of potentially secure data. 
  • Shut access off immediately upon termination. Make sure that when an employee leaves, their network accounts are disabled and email accounts are locked immediately. Removing the device profile is also important to prevent access to company wireless networks.
The reasons for getting in on the BYOD trend are numerous and provide a definite benefit to the company, including:
  • Lowering hardware costs. Employees bring their device and are responsible for any upgrades or maintenance on their devices.
  • Lower software costs. Corporations are no longer on the hook for massively time consuming and expensive OS rollouts. 
  • Encourages work after hours.  Employees are more likely to check email or perform other work if the ability to access the information available on their personal devices.
In general, the BYOD trend is here to stay and will likely escalate as tablets, smartphones and other devices perform more like the desktops of old. For more information on setting up a system to ease the transfer from corporate devices to company owned, please visit our website
.

Friday, January 11, 2013

Two Proven Methods to Increase Network Security and Productivity

In today’s healthcare environment, two of the primary technology focuses are on increasing network security by restricting access to data and applications, as well as increasing employee productivity by deploying user friendly solutions. Several technologies are rapidly being adopted by healthcare providers to assist in these arenas.

In reference to the security component, employees need to be given the correct security permissions based on their job roles. Ensuring that employees have the proper access rights greatly improves security, though doing so requires setting controls that can take the IT department months to implement.

Consider using a role based access control (RBAC) solution to assist with this process. The RBAC matrix is populated with departments, titles, locations and other pertinent information. This allows for a proven methodology to define which employee should have access to what applications and data.

In many cases it is feasible to populate much of the required data by taking an extract from the HR application. Additional extracts from Active Directory, Lightweight Directory Access Protocol (LDAP) and other healthcare systems can provide a snapshot of the way access is currently configured. Reviewing this data and finding employees with appropriate access, in each role, can be the basis for propagating that access to other employees in that role. An access request system can insure that any deviations from the norm are approved by the appropriate managers and system owners.

As a predecessor to an RBAC implementation, it is critical that each user have an individual network account. A common practice in healthcare is the use of shared accounts – nurses or clinicians log into a shared workstation with a generic account and access any number of applications. Occasionally, these applications, such as EHRs, will require a second set of credentials, but employees often use a shared account for access, as well.

This makes it difficult to determine who viewed what data and when. An identity management solution, often linked with the HR system, provides an easy answer to creating individual user accounts and can insure they are kept up to date with any changes in titles and departments, for example, thus insuring access is modified when appropriate. Employee departures, also reflected in the HR systems, can easily be detected to insure all network and application access is revoked in a timely fashion.

One downside of switching to individual accounts is that employees will now need to remember credentials – user names and passwords – for a multitude of systems. A recent survey found that the average clinician spends nearly 10 minutes a day logging in and out of applications. When coupled with the need to remember six or eight sets of credentials, tremendous productivity gains can be accomplished by reducing or eliminating these factors. Implementing a Single Sign On (SSO) application in conjunction with Fast User Switching is a cost effective approach to resolve this potential downside.

Single sign on allows users to login once to the network and all of their authorized application credentials are cached and provided on an as needed basis. While on the surface this seems to present a security risk, a concept known as strong authentication – for example, providing a piece of information you know, like a PIN code, and using something you have, like possessing a card to scan -- can mitigate the risk. By using an access card – likely the same one in used for time and attendance or security -- users can log into computers with this card and by entering a PIN code, much like going to an ATM. Removal of the card can force an immediate log out of all applications and closes the network account.

Fast user switching takes this concept one step further. Imagine a resident making rounds, logging into several computers, usually the closest one to a patient’s room. Fast user switching allows the resident to utilize her access card and PIN code to access the machine and any open applications previously used are immediately available to her, at the same point as when closing out of the last machine. A similar solution is available for the Citrix and Microsoft terminal services environment and is commonly referred to as “Follow Me.”

In summary, using individual network accounts and defining access to systems and data using an RBAC matrix increases the overall security of the hospital information systems, while using an SSO solution allows users to painlessly access the network and have more productive time for patient care.

For ore information, please visit our website.

Friday, January 4, 2013

Auditing of the Network in the Education Environment

In today’s electronic learning environment, access to appropriate systems and data are of the utmost importance to students, and the faculty and staff. Having the incorrect access to the school’s internal systems could mean a teacher is unable to access an online learning system or a student is not able to submit coursework projects to an online folder.

Equally important, though, for the security of the system is ensuring that individual access rights are updated and removed when appropriate for all users of the system.

The educational market certainly faces unique challenges in this arena. A typical k-12 system will provide individual access account to students once they reach 4th grade, meaning the turnover approaches 15% per year. Students transferring from one district to another, or to another school within the district, add to the daily challenges of accurate account management.

One recent example that shows how important it is for educational entities to purge their internal systems follows: A Pennsylvania school district was recently was preparing for a migration from an in-house Exchange email system to Google Apps. While Google does not charge schools for student accounts, the goal of the school was to go into the new system with data that was a clean as possible. During the migration it was discovered that graduating students had not been removed from Active Directory for the last 3 school years. This meant about 6,000 records needed to be purged from AD. The school also made a decision to leave email accounts active for matriculated students but remove them from the Active Directory.

Granting Access Rights: Determining who gets access to What and When
The first step in the process is to determine a baseline of necessary access rights needed and currently allowed by type of user. Numerous products are commercially available to allow a thorough scan of the network and applications to retrieve information on access rights. This information can then be compiled against user profiles -- department, location, titles, majors -- to establish a foundation of who needs to access what and when according to permissions granted currently in your system.

Once this initial review is completed, you are ready to create the “ideal” access for each type of user in the organization. This is a process that typically can be loaded into a Role Based Access Control matrix to insure that new users are created appropriately. Inevitably, though, some of the users will need access that differs from the norm so a procedure must be in place to allow end users to request access and managers to sign off on the enhanced rights. Again, numerous systems are available in the marketplace to allow this process to be handled electronically while providing a complete audit trail.

Equally as important as granting rights is insuring access rights are revoked when appropriate. With alarming regularity, faculty or staff members are transferred between departments and permissions to groups and applications become cumulative. While it may be necessary to allow a transferred user access to everything their previous role required during a transition period, it is imperative that a time limit be set for review and decommissioning of those rights be accomplished.

As free, cloud-based email systems have begun to proliferate in the educational space, one of the most important audit tasks facing educational institutions is to insure accounts are appropriately disabled and or deleted. Many of the cloud-based programs, like Google and Live@EDU, allow schools to maintain an “alumni” folder or domain separate from active accounts. By moving users to these folders when appropriate, the users can be deleted from the network, and all inherent access rights deleted as well, but their email accounts can remain active.

Conducting the Audit Cycle

The next step in the process is to perform an initial audit. You can be assured that new students and employees are being given correct access rights, but what about users that have been in the system for years. There is a good chance that several students and staff will have access to numerous departments or roles with access to more than one area.

By comparing their user type information and the access rights they currently have against the “ideal,” it is usually quite easy to determine the delta. At this stage in the process, every discrepancy must be accounted for. The user should be able to explain why he or she has access to systems outside the norm and the decision must be made to determine if the user may keep access to a system or if access rights should be removed. In most cases, as you’ll find several times during your first audit, that users often have access rights to areas they shouldn’t necessarily have because they served in previous roles and their rights were never terminated from previous access points.

As an ongoing process, regular audits are a necessity for any environment. In the very least, on a semester or quarter basis, managers and system owners should be asked to review access privileges and attest that the current rights meet established internal requirements. The ease of automated systems on the market can also allow for “on demand” audits. This allows the immediate creation of reports detailing accounts that are out of compliance. Some organizations also set up trigger events to allow a senior manager or IT person to review specific actions. For example, any time a user requests or is added to a certain application or group, a manual review of the reasons surrounding the request must be completed before permission can be granted.

An automated user provisioning application can also take data from a Human Resource application and/or a Student Information System to insure that students who graduate, do not return to the institution or are either moved to an alumni folder or removed entirely. This is a type of audit that can be performed on a daily basis without need for manual processing. The results of the daily process can easily be transmitted via email to the appropriate parties for review.

The fact that internal audits are conducted should be public knowledge, and no one should be “caught unaware” of the process. If users know their actions in the systems are being monitored, they are more likely to control their own behavior when accessing the sensitive information that they view as part of their employment.

Summary
To insure access to applications and sensitive data is open enough to allow providers to perform their jobs and restrictive enough to avoid legal complications, it is important to set controls when users join the organization and regularly review any changes to their profiles. These two factors will allow for easy compliance reporting at audit time.

There are numerous vendors offering commercially available solutions for every aspect of a provisioning and audit solution. Some are complicated, expensive propositions that can take months or years to become fully operational. Others offer inexpensive, quick to implement, point solutions that can attend to specific areas of concern that need to be addressed immediately.



For more information on Tools4ever solutions for education, please visit our website.

Thursday, December 13, 2012

Volvo Cars Nederland Implements Tools4ever’s Enterprise Single Sign On Manager

Seeking a solution to streamline employee’s access to internal accounts, Volvo Cars of The Netherlands, sought a solution to reduce the number of login and access credentials required of employees to gain access to their (web) applications.

Employees at the dealership use 20 different applications a day, on average, each of which requires a different combination of user name and password. Through Tools4ever’s single sign on, a total of 35 generic web applications, including sales and inventory and workplace management suites, were made ready for single sign on with the help of Enterprise Single Sign On Manager (E-SSOM.) The software’s implementation was carried out in collaboration with Volvo Cars Nederland B.V.’s software and service provider, Beesd A2.

“When Tools4ever presented us with its solution, I was immediately impressed by the product’s ease of use and how fast Tools4ever was able to implement the solution,” Tjeu Bollen, the founder of Beesd A2. “During a pilot run of the program, Tools4ever was able to make 20 applications ready for single sign on in just one day. This pilot, and the relatively low costs of the solution, made our decision to select this suite very easy.”

The European dealer is not alone in its desire to streamline. Dealerships across the globe increasingly are forced to turn to web applications to process and sell automobiles. Typically, each of these web applications requires a different user name and password. As is often the case, employees write down passwords on sticky notes or file them in other non-secure manners in an attempt to remember them. However, a single sign on solution corals all systems together and allows a user to enter just one password or login credential to access them. 

The staff at Volvo Cars B.V., in particular, benefit from the software. They no longer have to enter credentials for each individual application, and spend considerably less time on the login process and are spared a lot of frustration.

During a successful pilot at one of the Volvo dealerships, the value of the Tools4ever single sign on software quickly became apparent to the employees, said Dean Wiech, managing director of Tools4ever. “Three salespeople and two receptionists tested the software on site over a period of two months. From the very first day, they were highly enthusiastic about the solution, as they no longer had to log in to each and every application. They realized the immediate efficiencies it created."

“When the two months had ended and the test license expired, they got on the phone and said that they absolutely needed the software.”

The dealership has since implemented Tools4ever’s E-SSOM across all of its 110 branches throughout the Netherlands.

For more about Tools4ever, E-SSOM and to read customer case studies, visit our website.

Friday, December 7, 2012

Managing Free Email Solutions for Education

 
When educational institutions first began providing student with email accounts, the options were limited – implement an in-house solution from Novell or Microsoft depending on your network infrastructure.  There were some also small players in the market that provided hosted solutions. The problems with these options were they were expensive, required resources to set-up and maintain and had an ongoing costs associated with them.

About 5 years ago, Google, as they so often do, upset the proverbial apple cart by giving free email accounts to the educational space. Not to be outdone, Microsoft soon followed up with Live@edu and then Office 365 for Education. Both of these offerings eliminated the requirement for schools and colleges to purchase and maintain hardware for email and also eliminated the need for licensing of Exchange or GroupWise.

 One of the initial shortfalls with these offerings was the common fact that there was not an easy way to manage accounts in bulk. They did provide an interface that allowed for “one off” account creation and management, but with the large influx and outflow of students that the typical school or college is faced with each semester, the task can be daunting at best. One recent college I spoke with shared that when they first deployed Google Apps, they spent nearly 300 man hours keying in data, and they only had about 5,000 student accounts to create. Extrapolating this out, they could anticipate spending 3.6 minutes per account, or 75 hours per year, managing email accounts - assuming 1/4th of their students matriculate annually.

Further complicating these deployments was the fact that there was no easy way to synchronize passwords between the network account and the emails account.  It was easy to set the initial password as identical but, as is often the case, the user is required to change the password upon initial login. This frequently resulted in 2 different passwords – one for the network and one for email – causing a large number of calls to the helpdesk for password resets in one or both systems.
Fortunately, vendors that specialize in Identity and Access Management stepped in quickly to fill the void. Software tools were made available to allow IT staff to extend their automated user account provisioning to include both the Google Apps and Office 365 environments.  By utilizing these connectors, the amount of time to manage an account went form 3.6 minutes to virtually zero.  As the solutions offered by Google and Microsoft provide email accounts “for life”, it is important to have procedures in place that insure the email accounts remain active, and possibly moved to an alumni folder, upon student graduation.  This needs to occur even when the network access account has been deleted.

Another feature available from software vendors was a password synch tool. Anytime a user changed a password in their network account, the new entry was immediately passed to the mail account, insuring consistency and a significant reduction in calls to the helpdesk.  Extending this one step further is providing a self-service reset password application whereby the student can rest a forgotten password based on challenge questions.   This reset password can also be synched to the email solution, once again insuring consistency.

Summary
While the email offerings provided by Google and Microsoft are free, the time required to set-up and manage thousands of student and faculty accounts can be overwhelming and expensive. Fortunately, cost effective solutions are commercially available to reduce or eliminate the burden placed on the IT staff by automating the user and email account lifecycle.


For more information, please visit our website.

Friday, November 30, 2012

Healthcare provider saves Time and Money

Lifestyle Hearing is a healthcare provider of hearing solutions with over 50 clinics, as well as many independently owned network member locations throughout Canada. These clinics provide customers with a series of auditory services including testing patients for hearing, recommending and providing a  customized solution, as well as following up with ongoing visits and making sure everything is working properly. Recently the company has grown rapidly from just 2 employees to over 130 and continues to expand across Canada.

 This rapid growth of Lifestyle Hearing created many IT complications within the company such as departments and roles needing to be created and formed. Since they started as a small company, many employees had responsibilities which included several roles that needed to be clearly defined as the company grew. This meant that user accounts needed to be created in multiple systems and controls needed to be put in place. Franco Butera, IT Director at Lifestyle said, “This task took about half an hour for IT to complete, and that was only if we had all the correct information at the beginning.  If not, we had to track down the employees in an attempt to get the information, and wait for a response which could take up to an hour or more.” It is critical to unsure all information is correct such as credentials for doctors since they are operating in the healthcare arena. All of this work was taking valuable time away from the IT department, but could not be completed by department managers due to lack of technical knowhow.

Butera knew just how to solve these problems due to his positive experiences with Tools4ver’s User Management Resource Administrator (UMRA) at previous companies. He had come in contact with and used UMRA at both a larger telecommunications company in Canada and a higher education facility in Bermuda. Both projects had been extremely successful and had easily solved all of the organizations’ account management problems.

Completely controlled project
Tools4ever implemented UMRA at Lifestyle Hearing in a three phased approach. “The entire process was exceptional, from gathering the requirements, to deployment, to the types of resources Tools4ever provided.” Tools4ever was able to promptly implement the solution and get it up and running to start creating accounts in just the first phase. “The Project never slipped away, and was completely controlled. I was juggling many complex projects at the time, and Tools4ever’s UMRA was by far the easiest to work on.” Tools4ever was also even able to customize the solution to meet Lifestyle Hearings needs by building a connector to the company’s procurement resource system, Coupa.

No IT involvement
UMRA completely eliminated the account creation process from IT and is now handled entirely through the human resources department. Before UMRA, IT was the bottleneck due to the fact that they often had to handle other important tasks and were not able to create accounts quickly for new employees. HR now has controlled access through a web based form to create an account which allows them to easily enter the employee’s information, define their profiles and which systems they need accounts in. Lifestyle Hearing used to have a 4 to 5 day window for account creation, but with UMRA employees are now able to have their accounts created right away and start working the same day they are hired as needed.

Substantial savings
“Tools4ever’s UMRA saved our IT department a significant amount of time in the long run.” IT at Lifestyle Hearing no longer has to even hear about account creation and can focus on more important issues. Franco stated, “If you multiply how many long it took for IT to create an account by the number of accounts that we need created and edited, the savings is substantial.” UMRA is also able to track and audit Lifestyle Hearing so that it easily meets all audit requirements. “I have seen it manage thousands of accounts without any issues. It’s a must have application for companies of any size!”

For more information, please visit our website.