As the cloud continues to expand within the commercial world and cloud services such as Google Apps, GoToMeeting, and Office 365 being widely deployed, working with cloud applications have user and access management consequences that need to be addressed.
Controlling who has access to specific applications and the corresponding data is even more complicated with cloud applications than with a typical office intranet. Providers of cloud solutions give little priority to developing better management of user accounts and access rights in their applications; they are more occupied with developing new, business-oriented features.
Consequently, user and access management in cloud applications entails a number of challenges such as:
1. Single Authentication
Active Directory is the central link in the chain for user access to applications and systems. The traditional LAN-based applications often have specific integration, such as LDAP, with the central user account directory. Working with cloud applications means more authentication sources. In addition to the corporate Active Directory network log-in, users also need to remember their credentials for each cloud application utilized.
There are only a few possibilities for synchronizing user accounts between both authentication sources, (like AD Federation Services from Microsoft and the SAML standard). In this manner, end-users can log in transparently to the cloud applications. However, Federation is not a replacement for provisioning and basic user account management. Maintaining roles within a cloud application and linking accounts to central authentication remains an important task with which access to specific data is regulated.
A single-sign-on (SSO) solution for the cloud would help in this situation. Vendors that offer SSO for cloud base the credentials on those that already exist in Active Directory. This allows the user to log in to all of their cloud applications with just their AD credentials.
2. Manual Actions
Providers who do not support Federation, such as many providers of e-learning environments and HR systems, frequently offer a web-browser that managers can use to control access to the cloud application directly. However, there is no automatic provisioning and this necessitates a sequence of manual operations. This process is time consuming and error prone. Also, when it’s possible to import a basic CSV file into the cloud application, it still requires manual intervention by the application manager. This can result in a lot of unnecessary work.
For example, consider the procedure required when an employee leaves the organization. This procedure often occurs in phases: first the user log-in is removed, then the account is removed, data transferred to a different user, and, finally, an email notification is sent to the manager. All these phases require a separate manual operation for user management in the cloud application. In this case, an automated account management solution would assist in the process. A solution such as this would synchronize user accounts via the HR system, so that any changes made in HR, such as disabling a user would automatically be synchronized to all connected accounts in all applications.
3. Naming and Password Conventions
Conventions governing naming standards and passwords are often inconsistent between network and cloud applications. In the network, a user ID might be based on the log-in name, and in the cloud it might be the email address. This complicates exchanging user account details between the environments, and, in many cases, differences also apply to password conventions.
When extremely complex passwords are required in the corporate network, cloud applications might not be able to handle this type of password. The possibility also exists that the cloud application requires a different duration for password expiration than within the corporate network. Synchronizing passwords between the network and cloud applications can be exceedingly difficult. In this case, automated solutions can be helpful as they can enforce a standard naming convention across all applications while allowing for uniqueness when more than one employee has the same name.
An enterprise SSO solution can mitigate the password complexity issues by “remembering” the user’s password and providing it automatically each time the user logs into the application. Further, an SSO application can also routinely reset the password in the background, or prompt the user to do so, when expiration occurs.
4. Organizational Structure
The reporting hierarchy structure within an organization is often utilized to assign authorizations to employees based on their role or position, commonly referred to as role-based access control (RBAC). Within the corporate network, this structure is contained in an HR system or within Active Directory.
Cloud applications normally cannot translate this organizational structure, and the web-based provisioning functionality they offer does not offer a robust method for incorporating this level of detail. Naturally, it is possible to transfer the entire organizational structure to the cloud application, but this requires an enormous volume of management activity when something in the hierarchy changes.
RBAC in an automated account management solution can assist with this issue. It allows access to various components of the cloud applications to be based on the end user’s organizational role. In this way access will be controlled on the basis of the department or title in the HR system.
5. Bulk actions
Performing bulk actions in cloud applications is occasionally rejected by the application. Consider, for example, schools that want to create a thousand user accounts for students in a cloud application, such as an e-learning system. Some cloud applications that impose restrictions on the number of actions that can be carried out in one pass or require that no management activities are undertaken during working hours to prevent overloads on their network.
A robust provisioning application can adhere to the processing rules imposed by cloud applications by breaking up the number of requests to be processed in one connection and/or limiting the execution to specific time-frames.
Working with cloud applications generally means that organizations no longer have user and access management in their own hands, and that the rules and service level agreements of the cloud applications apply. User and access management are of secondary importance to business requirements. If it is requisite for an organization to have control of user and access management, there are third-party developers that provide software solutions to ease the transition to cloud-based applications.
For more information, please visit our website.
Friday, January 31, 2014
Friday, January 24, 2014
HR’s Role in Identity and Access Management
In today’s complex business environment, one task that can seem more elusive to automate than it actually is the granting of access to employees of the company’s network, email system and other applications.
In most organizations, paper forms or emails are sent from hiring managers to members of HR or IT departments to initiate this process, resulting in manual entry into the requisite applications for on-boarding employees and time delays of a few hours to several days or weeks before an employee is actually fully able to receive access to all systems and maneuver the organizations internal systems.
In the meantime, newly hired employees never reach productivity levels that could be had their rights been established properly from the beginning. The result is often waned enthusiasm of employees for their new job because they’ve become mired in the system.
A similar scenario often unfolds when an employee leaves the organization. Phone calls and emails start the process of deactivating the access rights, but delays and lapses are inevitable and can lead to a huge security risk as employees remain active for a period of time long enough for the departing employee to access private organizational information.
Solving the New Hire Access Dilemma
In the vast majority of cases, members of the HR department are the first or second to know when an employee is to be hired. The department’s employees typically enter the new hire’s profile into the HR department’s corresponding system with all appropriate data -- department, employee number, manager, etc. – and in some cases they send an email to the IT department letting them know a network access account and email need to be created. The IT department may need to go back to the hiring manager for approvals and any special access instructions that must be met.
An automated process can set off a simple entry process of the new employee record in the HR system to create the account in Active Directory and the email application. Further, a workflow process can be started whereby a hiring manager receives the employee’s log in credentials and a link to an internal website where special access can be requested. Once the manager completes the form, a further workflow can be sent if additional approval levels are required with the final step being a notification for IT to finish the provisioning.
For example, Lifestyle Hearing, a Hawkesbury, Ontario-based, company with 70 locations throughout Canada, automated this very process. The company rapidly expanded to more than 130 employees, which created many complications for the IT group. New departments and roles also needed to be created and formed on a regular basis. Since it started as a small company, many employees had responsibilities that included several roles requiring definition as the company grew.
This meant that user accounts needed to be created in multiple systems and tighter controls needed to be put in place. The task took about 30 minutes per employee, but only if all the correct information was provided from the beginning. If not, the employee needed to be tracked down in an attempt to get the information, and wait for a response, which could take an unlimited amount of time.
Lifestyle Hearing administrators knew it was critical to ensure all information was correct, but the process took too much time from too many people for it to be productive or worthwhile and had become a major drain on the organization.
Prior to putting an automated system in place, IT was a bottleneck because of the fact that employees in the department often had to handle other important tasks and they were not able to create accounts quickly for new employees. By automating their account management processes, HR now has controlled access through a web-based form to create an account that allows the IT department to easily enter the employee’s information, define user profiles and determine which systems they need access to.
Lifestyle Hearing previously had a four- to five-day window for employee account creation, but by automating, employees are now able to have their accounts before their first day and start working on day one.
Expediting Employee Access Termination
As equally important as providing new employees with prompt network access is ensuring that employees leaving an organization have their access to network accounts, email and other applications revoked in a timely fashion. While most employees leave on good terms, an upset or contentious employee can potentially cause damage to data or perform a mass emailing to clients, among other malicious attacks.
By automating, a manager can visit a web page and immediately revoke network and email account access of all terminated employees, as well as can put a terminate date in the HR system and have an automated process kick off on the appropriate date.
It is critical to the organization that departing employees have their access rights terminated in a timely fashion. To ensure this process runs smoothly, managers can access forms that allow them to search for an employee and revoke rights on demand. Another process runs once this action occurs to ensure emails are forwarded to the correct manager and any files left on the network are shared appropriately for review. This ensures continuity for any clients or projects the terminated employee may have been working with.
As the HR department is always involved with employee hiring and terminations, it makes sense to have them involved with the process of granting and revoking network and email access. Available systems make the impact negligible as to not occupy more the HR professional’s valuable time.
For ore information, please visit our website.
In most organizations, paper forms or emails are sent from hiring managers to members of HR or IT departments to initiate this process, resulting in manual entry into the requisite applications for on-boarding employees and time delays of a few hours to several days or weeks before an employee is actually fully able to receive access to all systems and maneuver the organizations internal systems.
In the meantime, newly hired employees never reach productivity levels that could be had their rights been established properly from the beginning. The result is often waned enthusiasm of employees for their new job because they’ve become mired in the system.
A similar scenario often unfolds when an employee leaves the organization. Phone calls and emails start the process of deactivating the access rights, but delays and lapses are inevitable and can lead to a huge security risk as employees remain active for a period of time long enough for the departing employee to access private organizational information.
Solving the New Hire Access Dilemma
In the vast majority of cases, members of the HR department are the first or second to know when an employee is to be hired. The department’s employees typically enter the new hire’s profile into the HR department’s corresponding system with all appropriate data -- department, employee number, manager, etc. – and in some cases they send an email to the IT department letting them know a network access account and email need to be created. The IT department may need to go back to the hiring manager for approvals and any special access instructions that must be met.
An automated process can set off a simple entry process of the new employee record in the HR system to create the account in Active Directory and the email application. Further, a workflow process can be started whereby a hiring manager receives the employee’s log in credentials and a link to an internal website where special access can be requested. Once the manager completes the form, a further workflow can be sent if additional approval levels are required with the final step being a notification for IT to finish the provisioning.
For example, Lifestyle Hearing, a Hawkesbury, Ontario-based, company with 70 locations throughout Canada, automated this very process. The company rapidly expanded to more than 130 employees, which created many complications for the IT group. New departments and roles also needed to be created and formed on a regular basis. Since it started as a small company, many employees had responsibilities that included several roles requiring definition as the company grew.
This meant that user accounts needed to be created in multiple systems and tighter controls needed to be put in place. The task took about 30 minutes per employee, but only if all the correct information was provided from the beginning. If not, the employee needed to be tracked down in an attempt to get the information, and wait for a response, which could take an unlimited amount of time.
Lifestyle Hearing administrators knew it was critical to ensure all information was correct, but the process took too much time from too many people for it to be productive or worthwhile and had become a major drain on the organization.
Prior to putting an automated system in place, IT was a bottleneck because of the fact that employees in the department often had to handle other important tasks and they were not able to create accounts quickly for new employees. By automating their account management processes, HR now has controlled access through a web-based form to create an account that allows the IT department to easily enter the employee’s information, define user profiles and determine which systems they need access to.
Lifestyle Hearing previously had a four- to five-day window for employee account creation, but by automating, employees are now able to have their accounts before their first day and start working on day one.
Expediting Employee Access Termination
As equally important as providing new employees with prompt network access is ensuring that employees leaving an organization have their access to network accounts, email and other applications revoked in a timely fashion. While most employees leave on good terms, an upset or contentious employee can potentially cause damage to data or perform a mass emailing to clients, among other malicious attacks.
By automating, a manager can visit a web page and immediately revoke network and email account access of all terminated employees, as well as can put a terminate date in the HR system and have an automated process kick off on the appropriate date.
It is critical to the organization that departing employees have their access rights terminated in a timely fashion. To ensure this process runs smoothly, managers can access forms that allow them to search for an employee and revoke rights on demand. Another process runs once this action occurs to ensure emails are forwarded to the correct manager and any files left on the network are shared appropriately for review. This ensures continuity for any clients or projects the terminated employee may have been working with.
As the HR department is always involved with employee hiring and terminations, it makes sense to have them involved with the process of granting and revoking network and email access. Available systems make the impact negligible as to not occupy more the HR professional’s valuable time.
For ore information, please visit our website.
Friday, January 17, 2014
Connecting National Geogrphic Employees Gloablly
National Geographic, the 125-year-old worldwide non-profit, has more than 1,400 full- and part-time employees, and hundreds of contractors working at its headquarters in Washington, DC and in remote offices throughout the world. However, the company faced the very real problem of coordinating all their employees. This is how the solved their dilemma…
Nat Geo’s employees must access several cloud applications, each with different credentials, to perform their daily duties. In addition, because of the hundreds of contractors the company employs, the IT department has to deal with high turnover rate of user accounts and manually ensure access is revoked once an employee moves on.
The situation was so out of hand that IT administrators were manually creating 10 new accounts for employees each day and deleting five others at the same time. The process was overwhelmingly time-consuming and inefficient, especially for such a geographically diverse organization.
“Since each of the organization's different locations publishes the content in their own language, our employees need to have access to the work resources,” said Dan Backer, director of campus technology at National Geographic.
Such a task was a tall order, especially since most of the IT administration and help desk-related tasks were taking place in Washington, DC.
This is a situation taking place at a variety of companies around the world
Like the thousands of other organizations with employees at various locations throughout the world, National Geographic faced a variety of issues when employees lost access to their accounts, either because they were locked out or because they forgot them.
When employees were unable to take corrective actions to get themselves back to work because the help desk was closed or unreachable as it was located in a different time zone, productivity was lost and other issues developed.
To ease any password-management issues National Geographic added to their technology repertoire
To use this new technology, employees simply answer predefined security questions that enable them to reset their passwords, even in the middle of the night, without contacting the helpdesk. This ensures that they are able make a simple change, regain access to their files and get back to work without having to sit around unproductively waiting for the helpdesk to unlock their accounts.
The benefits of using such a technology are obvious, but the company also added an automated account management solution that allows its administrators to connect the PeopleSoft HR system to Active Directory (AD) to read new data twice a day automatically and synchronise it to the directory and Google.
Now, when someone enters a new personnel request, the account management solution automatically creates a new:
The automated account management solution also assists with automatically deactivating accounts. Once an employee account is disabled in PeopleSoft, the solution automatically disables the AD and Google accounts to ensure the employee no longer has access to any internal accounts, records or information.
The organization also set its solution up to transfer that employee’s personal drive information to the manager, as well as ownership of all of the employee’s work-related Google documents. For organizations with high turnover and those with remote environments, implementing such a tool ensures that any projects that are in process are not lost forever.
According to National Geographic’s Dan Backer, the identity and access management solutions allow the company to serve employees worldwide better and help them address the high turnover of contract employees in a way that is simple and cost effective.
For more information, please visit our website .
Nat Geo’s employees must access several cloud applications, each with different credentials, to perform their daily duties. In addition, because of the hundreds of contractors the company employs, the IT department has to deal with high turnover rate of user accounts and manually ensure access is revoked once an employee moves on.
The situation was so out of hand that IT administrators were manually creating 10 new accounts for employees each day and deleting five others at the same time. The process was overwhelmingly time-consuming and inefficient, especially for such a geographically diverse organization.
“Since each of the organization's different locations publishes the content in their own language, our employees need to have access to the work resources,” said Dan Backer, director of campus technology at National Geographic.
Such a task was a tall order, especially since most of the IT administration and help desk-related tasks were taking place in Washington, DC.
This is a situation taking place at a variety of companies around the world
Like the thousands of other organizations with employees at various locations throughout the world, National Geographic faced a variety of issues when employees lost access to their accounts, either because they were locked out or because they forgot them.
When employees were unable to take corrective actions to get themselves back to work because the help desk was closed or unreachable as it was located in a different time zone, productivity was lost and other issues developed.
To ease any password-management issues National Geographic added to their technology repertoire
To use this new technology, employees simply answer predefined security questions that enable them to reset their passwords, even in the middle of the night, without contacting the helpdesk. This ensures that they are able make a simple change, regain access to their files and get back to work without having to sit around unproductively waiting for the helpdesk to unlock their accounts.
The benefits of using such a technology are obvious, but the company also added an automated account management solution that allows its administrators to connect the PeopleSoft HR system to Active Directory (AD) to read new data twice a day automatically and synchronise it to the directory and Google.
Now, when someone enters a new personnel request, the account management solution automatically creates a new:
- Google Apps account,
- AD account,
- Share drive and personal drive access, and
- Profile.
The automated account management solution also assists with automatically deactivating accounts. Once an employee account is disabled in PeopleSoft, the solution automatically disables the AD and Google accounts to ensure the employee no longer has access to any internal accounts, records or information.
The organization also set its solution up to transfer that employee’s personal drive information to the manager, as well as ownership of all of the employee’s work-related Google documents. For organizations with high turnover and those with remote environments, implementing such a tool ensures that any projects that are in process are not lost forever.
According to National Geographic’s Dan Backer, the identity and access management solutions allow the company to serve employees worldwide better and help them address the high turnover of contract employees in a way that is simple and cost effective.
For more information, please visit our website .
Friday, January 10, 2014
Preparing For A Software License Audit
For those anticipating a software license audit in the next year or so, the constant worry is certainly that the number of licenses purchased will deviate from the number of software applications actually used.
Without a solid overview of the relation between purchased licenses and those actually being used, an organization runs the risk of incurring a substantial fine from their software vendor. Added to which, software costs can turn out higher than necessary as some licenses may not be used at all.
This is a common problem for many organizations, and occurs when new employees enter service and the privileges of employees in similar functions are copied to their user accounts. This often includes rights to applications the employee may not actually need.
In other cases, temporary access rights to applications that employees require for a particular project are not revoked once the project has been completed. Or worse still, accounts by employees who have left employment are not terminated. As such, there are a number of reasons why the number of licenses used may not match the number of licenses purchased.
To solve this problem and mitigate management of license costs while preparing for software license audits, there are several easy and available options:
Employ Automated User Provisioning & Role-Based Access Control Tools
Using the human resources system as the source for creating, modifying and removing user accounts and authorizations, employees can be assigned temporary access to the network and the applications they need. In the licensing context, this ensures that the rights of former employees are revoked in a timely fashion.
Combined with role-based access control (RBAC) – a solution that lets administrators assign rights based on the role or title of employees – rights will only be assigned once consensus has been reached on the applications that employees actually require for their daily work.
Use Dashboards To Monitor Software Access & Activity
Provide IT managers, systems administrators and administrators with a dashboard that lists the number of times an application has been launched by an employee, the number of minutes the application has been used, as well as the idle time in minutes.
If an application remains unused for a long period, the application can be revoked or the user can be given a warning. The total license costs and the status of used applications can be mapped out using an interface with a facility management system or IT service management system.
Passive Auditing
Periodically communicate with managers and send them an overview of the rights and applications to which his or her team has access. This reporting can take place, for instance, once every three months, once a year, etc. (for the software license audit). Managers can thus conveniently check whether everything is in order and give their approval. They can also make changes, which will be implemented directly.
Making a long story short, when expecting a software license audit in the future and when needing to prevent fines or to cut license costs, make sure to take the right precautions, most of which are simple to implement and can save organizations a great deal of cash associated with software fines or for paying for unused licenses.
For more information on auditing solutions, please visit our website.
Without a solid overview of the relation between purchased licenses and those actually being used, an organization runs the risk of incurring a substantial fine from their software vendor. Added to which, software costs can turn out higher than necessary as some licenses may not be used at all.
This is a common problem for many organizations, and occurs when new employees enter service and the privileges of employees in similar functions are copied to their user accounts. This often includes rights to applications the employee may not actually need.
In other cases, temporary access rights to applications that employees require for a particular project are not revoked once the project has been completed. Or worse still, accounts by employees who have left employment are not terminated. As such, there are a number of reasons why the number of licenses used may not match the number of licenses purchased.
To solve this problem and mitigate management of license costs while preparing for software license audits, there are several easy and available options:
Employ Automated User Provisioning & Role-Based Access Control Tools
Using the human resources system as the source for creating, modifying and removing user accounts and authorizations, employees can be assigned temporary access to the network and the applications they need. In the licensing context, this ensures that the rights of former employees are revoked in a timely fashion.
Combined with role-based access control (RBAC) – a solution that lets administrators assign rights based on the role or title of employees – rights will only be assigned once consensus has been reached on the applications that employees actually require for their daily work.
Use Dashboards To Monitor Software Access & Activity
Provide IT managers, systems administrators and administrators with a dashboard that lists the number of times an application has been launched by an employee, the number of minutes the application has been used, as well as the idle time in minutes.
If an application remains unused for a long period, the application can be revoked or the user can be given a warning. The total license costs and the status of used applications can be mapped out using an interface with a facility management system or IT service management system.
Passive Auditing
Periodically communicate with managers and send them an overview of the rights and applications to which his or her team has access. This reporting can take place, for instance, once every three months, once a year, etc. (for the software license audit). Managers can thus conveniently check whether everything is in order and give their approval. They can also make changes, which will be implemented directly.
Making a long story short, when expecting a software license audit in the future and when needing to prevent fines or to cut license costs, make sure to take the right precautions, most of which are simple to implement and can save organizations a great deal of cash associated with software fines or for paying for unused licenses.
For more information on auditing solutions, please visit our website.
Thursday, October 24, 2013
Death by Clicking
In emergency care settings, clinicians need to act quickly to treat their patients. However, the login processes at hospitals and healthcare organizations can often cause delays with the service that they need to provide their patients.
Many healthcare organizations want to ensure the security of their systems and applications, but this often has a negative impact on the care they give their patients and can also lead to “death by clicking,” where precious moments are lost because of inefficient login processes and procedures. Clinicians need to quickly access the patients’ medical records including their history, dosages, medications, etc. to properly treat the patient. Every second that is lost could have been used in caring for the patient.
Something as simple as logging in to the computer and applications can become an issue and a major consumption of time, especially when it needs to be done multiple times or into multiple applications. This situation can be made even worse if physicians, nurses and other caregivers forget their passwords since they often have to remember several sets of credentials, and become locked out of the network. Though health records need to be kept secure, patient care should not suffer in the process.
Simplifying access to important systems, like patient health records, can save anywhere from a few seconds to several minutes each day, which is time that could be spent caring for patients. Quick access to a patient’s health record allows caregivers to make decisions about what kind of treatment options and medications to pursue. Clinicians often have to check several different systems and records in multiple environments to make these decisions. With a single sign-on solution, employees not only improve their workflow, documentation and security is also improved since the software records all user activities. This allows the healthcare organization to easily see what each employee is doing on the network.
Healthcare organizations need to reduce the headache associated with password issues and increase efficiency for clinicians so that they can provide a better experience for their patients. Simple solutions, such as single sign-on software, can easily mitigate these issues and are a necessity for reducing the time wasted on the login process. By not implementing an SSO solution, healthcare organizations are knowingly wasting precious time which can easily be reduced.
A single sign-on solution allows clinicians to have a single set of credentials to log on to a computer or workstation. Once they log in one time, they are automatically signed into all authorized systems and applications when they are launched.
SSO eliminates major hassles for clinicians and allows them to focus on their key priority, the patients.
The Rivierenland Hospital was one such medical facility that improved its efficiency with an SSO solution. The hospital’s clinicians indicated their frustration at having to remember too many log-in credentials and the time that it took them to log in before assisting each patient. An SSO solution was implemented allowing clinicians to swipe their card near the card reader and enter a PIN to access all of the applications and systems they need without having to remember and enter long passwords.
The solution supports a variety of applications, such as the healthcare solutions Soarian (Siemens), X/Care (McKesson), Patient Data Management System (PDMS) and the Zamicom hospital pharmacy information system, so that separate passwords don’t have to be entered for each.
“We have received compliments from various departments, including the usually highly-critical Intensive Care department. This is an extremely user-friendly solution,” said Jos Meeuwsen, the hospital’s system administrator.
Healthcare organizations are sometimes hesitant to implement an SSO solution because of the misconceptions they have, believing that SSO can hinder security, or that an implementation will be expansive or drawn out.
IT managers assume that if an unauthorized person gets hold of that single log in credential, that person will have access to all the account’s associated applications. Though this does appear to constitute a risk, the log-in process is actually streamlined for the user. Having to remember just one password essentially does away with the risk that the users will scribble passwords on a piece of paper and squirrel them away under their keyboard. If they still feel strongly about it being a security risk, SSO can offer additional security with two-factor authentication. This allows clinicians to swipe or place their card on the card reader in addition to entering a unique PIN. This process ensures that the user needs something physical, the card, and something from memory, the PIN, to access the network. Additionally, a second pass of the card, or removal from the reader, closes all applications and logs the user of the computer.
In regard to the implementation being an expensive and a drawn-out process, the nice thing about an SSO solution is that it’s often not necessary to set it up for all the people in an organization. In a hospital, for instance, SSO is only needed for a select group of people. The advice here is to restrict SSO to the most critical applications and the people who have to log in to a variety of different applications or from multiple locations. The implementation will then be easy to control in terms of price and complexity. This offers an excellent springboard for any further growth and expansion in accordance with changing future needs.
In addition to reducing the amount of time it takes to log in, SSO also has additional benefits. It can easily assist with audits by providing a detailed log of each user who has logged in and what they did on the network. It can also help healthcare organizations easily switch from shared workstations to individual account logins, which is required by HIPPA. Instead of eliminating the shared workstations and giving clinician’s credentials to the systems and applications, SSO easily transitions them to their own single set of credentials. Additionally, many vendors offer a “follow me” feature. This option allows users who have opened applications on Citrix and/or Terminal Server to continue their work on another computer.
An SSO solution along with the many features offered can result in a drastic time savings, particularly in the case of specialists who make their rounds amongst several departments or floors.
Implementing SSO is an easy process, and the solution integrates with almost all applications, including cloud applications. Once up and running, SSO provides the healthcare organization long-lasting benefits including increasing the care that patients receive and eliminates a great deal of wasted time.
For more information, please visit our website.
Many healthcare organizations want to ensure the security of their systems and applications, but this often has a negative impact on the care they give their patients and can also lead to “death by clicking,” where precious moments are lost because of inefficient login processes and procedures. Clinicians need to quickly access the patients’ medical records including their history, dosages, medications, etc. to properly treat the patient. Every second that is lost could have been used in caring for the patient.
Something as simple as logging in to the computer and applications can become an issue and a major consumption of time, especially when it needs to be done multiple times or into multiple applications. This situation can be made even worse if physicians, nurses and other caregivers forget their passwords since they often have to remember several sets of credentials, and become locked out of the network. Though health records need to be kept secure, patient care should not suffer in the process.
Simplifying access to important systems, like patient health records, can save anywhere from a few seconds to several minutes each day, which is time that could be spent caring for patients. Quick access to a patient’s health record allows caregivers to make decisions about what kind of treatment options and medications to pursue. Clinicians often have to check several different systems and records in multiple environments to make these decisions. With a single sign-on solution, employees not only improve their workflow, documentation and security is also improved since the software records all user activities. This allows the healthcare organization to easily see what each employee is doing on the network.
Healthcare organizations need to reduce the headache associated with password issues and increase efficiency for clinicians so that they can provide a better experience for their patients. Simple solutions, such as single sign-on software, can easily mitigate these issues and are a necessity for reducing the time wasted on the login process. By not implementing an SSO solution, healthcare organizations are knowingly wasting precious time which can easily be reduced.
A single sign-on solution allows clinicians to have a single set of credentials to log on to a computer or workstation. Once they log in one time, they are automatically signed into all authorized systems and applications when they are launched.
SSO eliminates major hassles for clinicians and allows them to focus on their key priority, the patients.
The Rivierenland Hospital was one such medical facility that improved its efficiency with an SSO solution. The hospital’s clinicians indicated their frustration at having to remember too many log-in credentials and the time that it took them to log in before assisting each patient. An SSO solution was implemented allowing clinicians to swipe their card near the card reader and enter a PIN to access all of the applications and systems they need without having to remember and enter long passwords.
The solution supports a variety of applications, such as the healthcare solutions Soarian (Siemens), X/Care (McKesson), Patient Data Management System (PDMS) and the Zamicom hospital pharmacy information system, so that separate passwords don’t have to be entered for each.
“We have received compliments from various departments, including the usually highly-critical Intensive Care department. This is an extremely user-friendly solution,” said Jos Meeuwsen, the hospital’s system administrator.
Healthcare organizations are sometimes hesitant to implement an SSO solution because of the misconceptions they have, believing that SSO can hinder security, or that an implementation will be expansive or drawn out.
IT managers assume that if an unauthorized person gets hold of that single log in credential, that person will have access to all the account’s associated applications. Though this does appear to constitute a risk, the log-in process is actually streamlined for the user. Having to remember just one password essentially does away with the risk that the users will scribble passwords on a piece of paper and squirrel them away under their keyboard. If they still feel strongly about it being a security risk, SSO can offer additional security with two-factor authentication. This allows clinicians to swipe or place their card on the card reader in addition to entering a unique PIN. This process ensures that the user needs something physical, the card, and something from memory, the PIN, to access the network. Additionally, a second pass of the card, or removal from the reader, closes all applications and logs the user of the computer.
In regard to the implementation being an expensive and a drawn-out process, the nice thing about an SSO solution is that it’s often not necessary to set it up for all the people in an organization. In a hospital, for instance, SSO is only needed for a select group of people. The advice here is to restrict SSO to the most critical applications and the people who have to log in to a variety of different applications or from multiple locations. The implementation will then be easy to control in terms of price and complexity. This offers an excellent springboard for any further growth and expansion in accordance with changing future needs.
In addition to reducing the amount of time it takes to log in, SSO also has additional benefits. It can easily assist with audits by providing a detailed log of each user who has logged in and what they did on the network. It can also help healthcare organizations easily switch from shared workstations to individual account logins, which is required by HIPPA. Instead of eliminating the shared workstations and giving clinician’s credentials to the systems and applications, SSO easily transitions them to their own single set of credentials. Additionally, many vendors offer a “follow me” feature. This option allows users who have opened applications on Citrix and/or Terminal Server to continue their work on another computer.
An SSO solution along with the many features offered can result in a drastic time savings, particularly in the case of specialists who make their rounds amongst several departments or floors.
Implementing SSO is an easy process, and the solution integrates with almost all applications, including cloud applications. Once up and running, SSO provides the healthcare organization long-lasting benefits including increasing the care that patients receive and eliminates a great deal of wasted time.
For more information, please visit our website.
Thursday, October 17, 2013
A recent succes story in the banking industry.
Needham Bank, located in Massachusetts, is a private bank providing
high quality services through its five locations. The bank has had a
rich history within the area since 1892 and prides itself on
personalized service and deep community involvement.
Recently, Needham Bank began expanding and has grown to a staff of over 170. As the bank grew in size so did the issues that its employees were having with passwords. End users at the bank need access to several different systems and applications in order to properly assist customers. “End users became frustrated at the number of disparate passwords they had, and the frequency they would have to enter the user names and passwords,” commented James Gordon, First Vice President of Information Technology at Needham Bank. It was also frustrating when employees had to halt what they were doing and contact the help desk to reset their password if they were locked out.
Customers also became frustrated, as they had to wait for bank employees to sign into each application separately, which was time consuming. It also led to security issues due to employees keeping a ‘password sheet’ with each set of their credentials written down in order to remember them. Additionally, IT was frustrated at the amount of password reset calls they were receiving. On average they had to perform around 10-20 password resets a day, which became tedious and took time away from other projects they needed to focus on.
Due to the success experienced with SSRPM, Needham then decided to implement E-SSOM to further mitigate their password issues. “We had already used SSRPM and over the years it worked flawlessly. We expected the same from E-SSOM,” said Gordon.
E-SSOM now allows employees to log in with a single user name and password, and thereafter gain access to all systems and applications for which they have authorization, drastically reducing the login time.
Overall, E-SSOM and SSRPM have allowed employees at the bank to focus more on their customers and less on their password issues. “I now view E-SSOM and SSRPM an irreplaceable part of our network infrastructure and core to how the business will operate moving forward,” said Gordon.
For more information, please visit our website.
Recently, Needham Bank began expanding and has grown to a staff of over 170. As the bank grew in size so did the issues that its employees were having with passwords. End users at the bank need access to several different systems and applications in order to properly assist customers. “End users became frustrated at the number of disparate passwords they had, and the frequency they would have to enter the user names and passwords,” commented James Gordon, First Vice President of Information Technology at Needham Bank. It was also frustrating when employees had to halt what they were doing and contact the help desk to reset their password if they were locked out.
Customers also became frustrated, as they had to wait for bank employees to sign into each application separately, which was time consuming. It also led to security issues due to employees keeping a ‘password sheet’ with each set of their credentials written down in order to remember them. Additionally, IT was frustrated at the amount of password reset calls they were receiving. On average they had to perform around 10-20 password resets a day, which became tedious and took time away from other projects they needed to focus on.
Drastic Reduction in Password Related Issues
Needham first implemented Tools4ever’s Self Service Reset Password Management (SSRPM) to allow employees to reset their own passwords without having to contact the helpdesk. They simply answer several security questions, which they previously provided answers for during initial enrollment, and are able to securely reset their own passwords. This drastically reduced the amount of password related calls the help desk received and allowed employees to quickly complete the process and continue with their work.Due to the success experienced with SSRPM, Needham then decided to implement E-SSOM to further mitigate their password issues. “We had already used SSRPM and over the years it worked flawlessly. We expected the same from E-SSOM,” said Gordon.
Customization
During the implementation of E-SSOM, Tools4ever worked with Needham Bank to ensure that the solution worked with all of their unique applications. Many of the applications in place run on various codebases and include web applications, java-based applications, legacy Windows applications and many more. “Tools4ever was with us through the entire process, making sure to get it right, and tweaking E-SSOM along the way to fine tune it in our environment,” commented Gordon.E-SSOM now allows employees to log in with a single user name and password, and thereafter gain access to all systems and applications for which they have authorization, drastically reducing the login time.
Improvement in Customer Service
With a single set of credentials, employees no longer have to write down their passwords in order to remember them, which has resulted in greatly improved security. E-SSOM has also augmented customer service at Needham Bank, by allowing employees to avoid signing into multiple applications. In addition, if employees do need to reset their passwords, they are able to quickly do it themselves and continue assisting customers. “Employees are able to focus on the customer rather than on their computer,” said Gordon.Overall, E-SSOM and SSRPM have allowed employees at the bank to focus more on their customers and less on their password issues. “I now view E-SSOM and SSRPM an irreplaceable part of our network infrastructure and core to how the business will operate moving forward,” said Gordon.
For more information, please visit our website.
Thursday, October 10, 2013
Strengthen Organizational Security Without Breaking the Bank
As leaders within all types of organizations grow more concerned with the security of their networks, they increasingly turn to enhanced security and access processes over the “normal,” more traditional approaches to user name and password authentication methods.
Two-factor authentication (also known as TFA, T-FA or 2FA) is an approach to authentication that requires the presentation of at least two of the three main authentication factors. For example, a knowledge factor (something specific to the user, such as a password or childhood memory), a possession factor (something the user has, such as a scan card), and an inherence factor (something the user is, such as a type of employee) are all forms of authentication factors.
The banking industry, for example, has used this concept for years with the ATM card. To gain access to your cash, you must have a physical card in hand as well as a personal identification number (PIN) to access your account.
Another example of this is found on laptop computers that manufacturers have built fingerprint readers into. The only way to access the information on the machines is by scanning an approved user’s fingerprint. The application adds a great deal of security and is perfect for industries like finance, healthcare, and even education.
The question for organization leaders seeking stronger authentication processes is this: how can two-factor authentication provide extra security to an organization while not requiring a large capital outlay?
There are two options that are becoming commonplace and ever more affordable:
Password Resets
The concept of using challenge questions like “What’s your mother maiden name”, or “Where were you born?” has been around for many years. Banking websites are the most common example of this concept. If you forget your password and successfully answer the challenge questions to reset your password, you gain access to your cash.
With the advent of smart phones and text messaging, many companies have already added a second factor—a one-time use PIN code delivered via email or SMS must be provided in addition to answers to security questions.
The first iterations of these solutions exclusively relied on the challenge questions to allow password resets. As social engineering concerns have come in to play, vendors have been quick to add 2FA to these solutions. The delivery of a PIN via text messaging to the user’s cell phone number on file insures the reset is being performed by the actual user.
Another benefit of these challenge questions is that they can be utilized by the helpdesk to positively identify a caller. When an employee phones the helpdesk requesting access to a new application or to be added to a shared or distribution group, the helpdesk can access the questions and masked answers. For example, the answer to “What color is your car?” could display as “X_XX_” and the caller would be asked to provide the second and fifth characters. If the correct characters are provided, it insures the caller’s identity. By masking the answers, the helpdesk employees are never exposed to the confidential answers.
A second factor of authentication—delivering a PIN to an email or via SMS—can further enhance a system’s security. Also, the number of questions and answers to be provided to the user can be dictated by company policy, allowing for the greatest level of security for any given organization.
Single Sign-on with Strong Authentication
Many technology leaders acknowledge the benefits associated with a Single Sign-On (SSO) solution—productivity gains reducing the number of required credentials from many to one and reducing calls to the helpdesk for forgotten passwords.
SSO software enables end-users to log in to their systems just once after which access is granted automatically to all of their authorized network applications and resources. SSO also operates as an extra software layer intercepting all log-in processes and completing the details automatically.
A common concern here is that if the one set of credentials is hacked, then access to all systems can be exposed. In this case, two-factor authentication can eliminate this perceived risk.
In a two-factor authentication scenario, the end user presents his ID badge (“something the user has”) to a card reader attached to the machine he is attempting to access and enters his credentials (“something the user has”) then as an extra layer of protection, enters a PIN code when accessing highly sensitive systems.
It is also feasible that the ID badge replaces the credentials and the PIN becomes the second factor.
Two-factor authentication is catching on rapidly in the business to consumer arena as functionality, such as self-password reset was originally implemented to reduce call volume and security of this functionality, has been strengthened in response to identity theft and social engineering. Use of secondary identification methods are now widely available to businesses interested in providing the same secure functionality to employees, and are much more affordable than in the past.
For more information, please visit our website.
For a case study on a recent implementation, click here.
Two-factor authentication (also known as TFA, T-FA or 2FA) is an approach to authentication that requires the presentation of at least two of the three main authentication factors. For example, a knowledge factor (something specific to the user, such as a password or childhood memory), a possession factor (something the user has, such as a scan card), and an inherence factor (something the user is, such as a type of employee) are all forms of authentication factors.
The banking industry, for example, has used this concept for years with the ATM card. To gain access to your cash, you must have a physical card in hand as well as a personal identification number (PIN) to access your account.
Another example of this is found on laptop computers that manufacturers have built fingerprint readers into. The only way to access the information on the machines is by scanning an approved user’s fingerprint. The application adds a great deal of security and is perfect for industries like finance, healthcare, and even education.
The question for organization leaders seeking stronger authentication processes is this: how can two-factor authentication provide extra security to an organization while not requiring a large capital outlay?
There are two options that are becoming commonplace and ever more affordable:
Password Resets
The concept of using challenge questions like “What’s your mother maiden name”, or “Where were you born?” has been around for many years. Banking websites are the most common example of this concept. If you forget your password and successfully answer the challenge questions to reset your password, you gain access to your cash.
With the advent of smart phones and text messaging, many companies have already added a second factor—a one-time use PIN code delivered via email or SMS must be provided in addition to answers to security questions.
The first iterations of these solutions exclusively relied on the challenge questions to allow password resets. As social engineering concerns have come in to play, vendors have been quick to add 2FA to these solutions. The delivery of a PIN via text messaging to the user’s cell phone number on file insures the reset is being performed by the actual user.
Another benefit of these challenge questions is that they can be utilized by the helpdesk to positively identify a caller. When an employee phones the helpdesk requesting access to a new application or to be added to a shared or distribution group, the helpdesk can access the questions and masked answers. For example, the answer to “What color is your car?” could display as “X_XX_” and the caller would be asked to provide the second and fifth characters. If the correct characters are provided, it insures the caller’s identity. By masking the answers, the helpdesk employees are never exposed to the confidential answers.
A second factor of authentication—delivering a PIN to an email or via SMS—can further enhance a system’s security. Also, the number of questions and answers to be provided to the user can be dictated by company policy, allowing for the greatest level of security for any given organization.
Single Sign-on with Strong Authentication
Many technology leaders acknowledge the benefits associated with a Single Sign-On (SSO) solution—productivity gains reducing the number of required credentials from many to one and reducing calls to the helpdesk for forgotten passwords.
SSO software enables end-users to log in to their systems just once after which access is granted automatically to all of their authorized network applications and resources. SSO also operates as an extra software layer intercepting all log-in processes and completing the details automatically.
A common concern here is that if the one set of credentials is hacked, then access to all systems can be exposed. In this case, two-factor authentication can eliminate this perceived risk.
In a two-factor authentication scenario, the end user presents his ID badge (“something the user has”) to a card reader attached to the machine he is attempting to access and enters his credentials (“something the user has”) then as an extra layer of protection, enters a PIN code when accessing highly sensitive systems.
It is also feasible that the ID badge replaces the credentials and the PIN becomes the second factor.
Two-factor authentication is catching on rapidly in the business to consumer arena as functionality, such as self-password reset was originally implemented to reduce call volume and security of this functionality, has been strengthened in response to identity theft and social engineering. Use of secondary identification methods are now widely available to businesses interested in providing the same secure functionality to employees, and are much more affordable than in the past.
For more information, please visit our website.
For a case study on a recent implementation, click here.
Subscribe to:
Posts (Atom)