From tokens to biometrics, there are many solutions to beef up user authentication. Value-added resellers (VARs) and systems integrators are in a position to help their customers carefully evaluate the choices. This article, reposted courtesy of Information Security magazine, introduces the technologies that can be used to create a two-factor authentication system.
Requires Membership to View
To gain access to this and all member only content, please provide the following information:
By submitting your registration information to SearchSecurityChannel.com you agree to receive email communications from the TechTarget network of sites, and/or third party content providers that have relationships with TechTarget, based on your topic interests and activity, including updates on new content, event notifications, new site launches and market research surveys. Please verify all information and selections above. You may unsubscribe at any time from one or more of the services you have selected by editing your profile, unsubscribing via email or by contacting us here
- Your use of SearchSecurityChannel.com is governed by our Terms of Use
- We designed our Privacy Policy to provide you with important disclosures about how we collect and use your registration and other information. We encourage you to read the Privacy Policy, and to use it to help make informed decisions.
- If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States.
|
||||
Christopher Paidhrin had no difficulty selling an enterprise single sign-on and fingerprint authentication solution to upper management at Southwest Washington Medical Center. Quite simply, it took out the hassle factor of HIPAA compliance.
"By implementing this solution we addressed eight principal requirements and 15 secondary requirements," says Paidhrin, senior security officer for ACS Healthcare Solutions, the IT outsourcing partner to the the hospital.
Regulatory requirements, like HIPAA and new regulations such as Federal Financial Institutions Examination Council (FFIEC) rules, are forcing organizations to scramble for authentication and identity management options. Meanwhile, the Homeland Security Presidential Directive 12 (HSPD 12) mandates that federal1 agencies must have a single ID card for physical and IT access by Oct. 27.
Because of these new and existing regulations, Information Security magazine and SearchSecurity.com readers rank strengthening authentication as their top ID and access management priority for this year.
In general, organizations should consider which regulations impact them and conduct a risk analysis of their systems. From there, they can decide the most appropriate way to apply strong authentication so that they're protecting systems with sensitive data and meeting regulatory requirements without going overboard.
Tokens, smart cards, biometrics and certificates all offer stronger ways of identifying users, customers and partners. Each has its strengths and weaknesses, and costs can be anywhere from $1 to $35 per user. As a result, companies must weigh their costs with the benefits and understand that each solution doesn't necessarily provide sure-fire security.
Learn more about each of these authentication options by clicking on the links below.
Two-factor
authentication options
Tokens
Smart cards
Biometrics
Certificates
Safe mode: Danger zone
About the author
Tom Bowers is the Security Director of Net4NZIX, an independent think tank and industry analyst
group, as well as a technical editor for Information Security magazine. Bowers, who holds
the CISSP, PMP and Certified Ethical Hacker certifications, is a well known expert on the topics of
data leakage prevention, global enterprise information security architecture and ethical hacking.
He is also the president of the Philadelphia chapter of Infragard, the second largest chapter in
the country with more than 600 members.
This was first published in November 2006