Home > Security Channel Tips > Identity Management and Access Control > Two-factor authentication options
Security Channel Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

IDENTITY MANAGEMENT AND ACCESS CONTROL

Two-factor authentication options


Tom Bowers
11.06.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


From tokens to biometrics, there are many solutions to beef up user authentication. Value-added resellers (VARs) and systems integrators are in a position to help their customers carefully evaluate the choices. This article, reposted courtesy of Information Security magazine, introduces the technologies that can be used to create a two-factor authentication system.

Two-Factor Authentication Crash Course
Visit our Two-Factor Authentication Crash Course designed specifically for VARs and systems integrators to learn more about the FFIEC's mandate and the limitations of two-factor authentication.

Christopher Paidhrin had no difficulty selling an enterprise single sign-on and fingerprint authentication solution to upper management at Southwest Washington Medical Center. Quite simply, it took out the hassle factor of HIPAA compliance.

"By implementing this solution we addressed eight principal requirements and 15 secondary requirements," says Paidhrin, senior security officer for ACS Healthcare Solutions, the IT outsourcing partner to the the hospital.

Regulatory requirements, like HIPAA and new regulations such as Federal Financial Institutions Examination Council (FFIEC) rules, are forcing organizations to scramble for authentication and identity management options. Meanwhile, the Homeland Security Presidential Directive 12 (HSPD 12) mandates that federal1 agencies must have a single ID card for physical and IT access by Oct. 27.

Because of these new and existing regulations, Information Security magazine and SearchSecurity.com readers rank strengthening authentication as their top ID and access management priority for this year.

In general, organizations should consider which regulations impact them and conduct a risk analysis of their systems. From there, they can decide the most appropriate way to apply strong authentication so that they're protecting systems with sensitive data and meeting regulatory requirements without going overboard.

Tokens, smart cards, biometrics and certificates all offer stronger ways of identifying users, customers and partners. Each has its strengths and weaknesses, and costs can be anywhere from $1 to $35 per user. As a result, companies must weigh their costs with the benefits and understand that each solution doesn't necessarily provide sure-fire security.

Learn more about each of these authentication options by clicking on the links below.



Two-factor authentication options

  Tokens
  Smart cards
  Biometrics
  Certificates
  Safe mode: Danger zone

Tom Bowers

About the author
Tom Bowers is the Security Director of Net4NZIX, an independent think tank and industry analyst group, as well as a technical editor for
Information Security magazine. Bowers, who holds the CISSP, PMP and Certified Ethical Hacker certifications, is a well known expert on the topics of data leakage prevention, global enterprise information security architecture and ethical hacking. He is also the president of the Philadelphia chapter of Infragard, the second largest chapter in the country with more than 600 members.


Rate this Tip
To rate tips, you must be a member of SearchSecurityChannel.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Identity Management and Access Control
Configure IIS Web server permissions to protect customer data
Two-factor authentication for SMB customers
One-time password tokens and FFIEC compliance
Understanding two-factor authentication as mandated by the FFIEC
The drawbacks of two-factor authentication

Identity Management and Access Control
Top security tips for solutions providers
Check up on IT security services for your clients
FFIEC compliance and two-factor authentication: A crash course
Two-factor authentication for SMB customers
2007: Single sign-on and more secure passwords
Two-factor authentication and tokens
Two-factor authentication and smart cards
Two-factor authentication and biometrics
Safe mode: Two-factor authentication's danger zone
One-time password tokens and FFIEC compliance

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts