Managing Access in the Cloud and Your Pocket

Online Exclusive: Managing Access in the Cloud and Your Pocket

Enterprises see a growth in employee demand for mobile device use in the workplace (a trend known as “Bring Your Own Device” – or BYOD), both to enhance individual productivity and generate business value.

Online Exclusive: Managing Access in the Cloud and Your Pocket

It’s no secret that two hot topics greatly impacting enterprises today are mobile and cloud. With these trends comes a renewed focus on security, specifically with respect to user access management.

According to IMS Research, by 2020 there will be more than 22 billion web-connected devices that will generate more than 2.5 quintillion bytes of new data each and every day. This provides an immense opportunity for companies to reach customers in new and exciting ways. With this, enterprises also see a growth in employee demand for mobile device use in the workplace (a trend known as “Bring Your Own Device” – or BYOD), both to enhance individual productivity and generate business value.

Whether you’re managing a number of devices on a corporate network or pushing new mobile apps to enhance customer experiences, secure access to these resources is more than strongly suggested; it’s an absolute must.  Here are some tips on securing mobile access:

  • Be sure to authenticate both the device and user before granting access. Mobile devices are often shared and could hold more sensitive information than just new baby photos or a high Angry Birds score.
  • Effective session management is key to lessening the risk of man-in-the-middle attacks. Make sure time limits and auto-locks are put in place to control this issue.
  • Take into account the context of your user with details like time, network, location, device characteristics and role, so that appropriate counter measures can be taken if a threat arises. Calculating this risk can help select the appropriate action for authentication, identify corresponding authorization policies to deploy and provide the user with best security practices for future use. To protect against mobile rooted attacks, access management threat protection needs to actively be addressed and countered.

Recently, companies have seen an increase in the cost saving benefits of sourcing technology services – like software, platforms and infrastructure – from cloud-based providers.

Using cloud technologies to deliver new services or content helps organizations save both valuable time and money. As more and more businesses launch new cloud offerings or deploy cloud-based solutions, secure access must be factored into the equation.

First, develop a robust single sign-on solution that can securely group identities across networks to improve user experience. The use of third-party identity providers like Google, Facebook or LinkedIn to authenticate the user is a growing trend among organizations. 

Next, a cloud access management solution needs be intelligent enough to assess the risk of a specific access attempt based on previous attempts by the user. To manage costs and compliance, organizations can enforce a flexible management policy for authorizing access.

IBM is a prime example of a business that has recognized these trends and embraced them. We continue to address changing requirements with the IBM Security Access Manager (ISAM) solution for cloud and mobile. To help businesses assess risk and adapt accordingly, ISAM now enables context-aware access control.

With 91% of people keeping their mobile device within arm's reach 100% of the time, the need for securely controlling access through mobile devices is no longer “a nice to have” it’s “a need to have.”   

About the Author

Dr. Nataraj (Raj) Nagaratnam is an IBM Distinguished Engineer and Chief Technology Officer for Security Solutions in IBM Security Systems. In this role, Raj leads cross IBM technical strategy for security solutions including mobile security, and cloud security; drives integration and innovation projects.

Featured

  • Personal Liability Concerns Impact 70% of Cybersecurity Leaders

    BlackFog, provider of ransomware prevention and anti data exfiltration (ADX), recently unveiled its research conducted with UK and US IT Security decision makers. The research revealed that the majority of respondents, 70%, felt that stories of CISOs being held personally liable for cybersecurity incidents has negatively affected their opinion of the role. Read Now

  • Security Industry Association Announces the 2025 Security Megatrends

    The Security Industry Association (SIA) has identified and forecasted the 2025 Security Megatrends, which form the basis of SIA’s signature annual Security Megatrends report defining the top 10 factors influencing both short- and long-term change in the global security industry. Read Now

  • Generative AI, Cybersecurity Among Top Risks for Healthcare Provider Organizations in 2025

    Overseeing the use of generative artificial intelligence, enhancing cybersecurity and ensuring compliance with a host of federal healthcare regulations headline the Top Risks health systems face in 2025, according to an annual study by Kodiak Solutions. Read Now

  • Wisconsin Shooting Likely a 'Combination of Factors'

    Following the deaths of a teacher and student at Abundant Life Christian School in, Madison, Wisc., police chief Shon Barnes indicated that the motive appears to be a “combination of factors” for a 15-year-old female student’s attack on a study hall. Read Now

    • Active Shooter
    • Incident Response

Featured Cybersecurity

Webinars

New Products

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction. 3

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • Compact IP Video Intercom

    Viking’s X-205 Series of intercoms provide HD IP video and two-way voice communication - all wrapped up in an attractive compact chassis. 3