Skip to content

estm computer information systems for business, Shropshire, West Midlands

IT Management, Infrastructure, Computer Network, Computer Support, Computer Repair, Information Security, Business Continuity, Backup, West Midlands and Shropshire

IT Management

Infrastructure, Network, Support, Security, Business Continuity, Disaster Recovery

Increase font size  Decrease font size  Default font size 
You are here:    Home arrow Blog arrow Who Goes There? - Identity Management
Who Goes There? - Identity Management
 

By Ian Edwards, on 29 Dec 2007

Views : 1296

Published in : Blog, IT Management

A conversation on Radio 4 the other day discussing the recent data protection (or should that be data loss) stories reminded me of the most important and fundamental principle of information security, that is controlling who has access to your data.  This is simply done by ensuring that every computer user in your organisation has their own unique identity. Users have their own log-on name and password and this gives them access to the data their role entitles them to access, and only that data. In practice this simple principle can fail badly for three reasons....

1) Users "help each other out" by sharing user names and passwords. This often happens when users go on holiday or are away and make their own arrangements for cover.

2) Poor or inefficient backend administration means that users don't have access to the resources they legitimately need in a timely manner so staff work around the issues.

3) Poor or inefficient backend administration that fails to properly associate data with roles and so inadvertently allows access to people who shouldn't have access.

There are technical solutions, such as tokens or biometrics, that allow greater security than can be afforded by a simple user-name and password but these are no defence unless the above points are dealt with. Good IT Management requires proper and timely administration of user identities with access to resources according to role, and proper computer use policies and training to ensure that systems are used as intended

   
Quote this article in website
Print
Send to friend
Related articles
Save this to del.icio.us

Users' Comments  RSS feed comment
 

Average user rating

 


Add your comment
Name
E-mail
Title  
Comment
 
Available characters: 800
   Notify me of follow-up comments
  This image contains a scrambled text, it is using a combination of colors, font size, background, angle in order to disallow computer to automate reading. You will have to reproduce it to post on my homepage
Enter what you see:

   
   

No comment posted



mXcomment 1.0.9 © 2007-2010 - visualclinic.fr
License Creative Commons - Some rights reserved