Managing Access in the Cloud and Your Pocket

Online Exclusive: Managing Access in the Cloud and Your Pocket

Enterprises see a growth in employee demand for mobile device use in the workplace (a trend known as “Bring Your Own Device” – or BYOD), both to enhance individual productivity and generate business value.

Online Exclusive: Managing Access in the Cloud and Your Pocket

It’s no secret that two hot topics greatly impacting enterprises today are mobile and cloud. With these trends comes a renewed focus on security, specifically with respect to user access management.

According to IMS Research, by 2020 there will be more than 22 billion web-connected devices that will generate more than 2.5 quintillion bytes of new data each and every day. This provides an immense opportunity for companies to reach customers in new and exciting ways. With this, enterprises also see a growth in employee demand for mobile device use in the workplace (a trend known as “Bring Your Own Device” – or BYOD), both to enhance individual productivity and generate business value.

Whether you’re managing a number of devices on a corporate network or pushing new mobile apps to enhance customer experiences, secure access to these resources is more than strongly suggested; it’s an absolute must.  Here are some tips on securing mobile access:

  • Be sure to authenticate both the device and user before granting access. Mobile devices are often shared and could hold more sensitive information than just new baby photos or a high Angry Birds score.
  • Effective session management is key to lessening the risk of man-in-the-middle attacks. Make sure time limits and auto-locks are put in place to control this issue.
  • Take into account the context of your user with details like time, network, location, device characteristics and role, so that appropriate counter measures can be taken if a threat arises. Calculating this risk can help select the appropriate action for authentication, identify corresponding authorization policies to deploy and provide the user with best security practices for future use. To protect against mobile rooted attacks, access management threat protection needs to actively be addressed and countered.

Recently, companies have seen an increase in the cost saving benefits of sourcing technology services – like software, platforms and infrastructure – from cloud-based providers.

Using cloud technologies to deliver new services or content helps organizations save both valuable time and money. As more and more businesses launch new cloud offerings or deploy cloud-based solutions, secure access must be factored into the equation.

First, develop a robust single sign-on solution that can securely group identities across networks to improve user experience. The use of third-party identity providers like Google, Facebook or LinkedIn to authenticate the user is a growing trend among organizations. 

Next, a cloud access management solution needs be intelligent enough to assess the risk of a specific access attempt based on previous attempts by the user. To manage costs and compliance, organizations can enforce a flexible management policy for authorizing access.

IBM is a prime example of a business that has recognized these trends and embraced them. We continue to address changing requirements with the IBM Security Access Manager (ISAM) solution for cloud and mobile. To help businesses assess risk and adapt accordingly, ISAM now enables context-aware access control.

With 91% of people keeping their mobile device within arm's reach 100% of the time, the need for securely controlling access through mobile devices is no longer “a nice to have” it’s “a need to have.”   

About the Author

Dr. Nataraj (Raj) Nagaratnam is an IBM Distinguished Engineer and Chief Technology Officer for Security Solutions in IBM Security Systems. In this role, Raj leads cross IBM technical strategy for security solutions including mobile security, and cloud security; drives integration and innovation projects.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3