Integration Ingenuity

Providing access control across different systems is imperative to meet compliance, regulations

IN a typical IT environment, heterogeneity is the standard -- in server operating systems, in database platforms and in software applications running on those servers. Mixed Windows®, Mac and UNIX/Linux environments, and all of the complications that come from supporting them, are a fact of life for almost all IT organizations. This situation will prevail as both Linux and Windows grow in the data center and more Java- and Web-based enterprise applications are deployed.

Organizations want heterogeneous servers and applications to be plug-and-play, so that IT does not have to spend time acting as a systems integrator or having to manually -- and expensively -- administer an ever-growing number of systems and applications individually.

Not surprisingly, achieving interoperability among the system and application platforms complicates life for IT managers. Organizations want heterogeneous servers and applications to be plug-and-play, so that IT does not have to spend time acting as a systems integrator or having to manually -- and expensively -- administer an ever-growing number of systems and applications individually. In addition, organizations want to leverage existing investments to get economies of scale, as budgets force the companies to do more with less. But most system and application vendors spend very little research and development efforts trying to make solutions play nicely with other, often competing, products.

The companies instead invest in an arms race by adding unique and differentiating features, and IT organization are left trying to manage islands of non-integrated computing infrastructures.

Leaving Systems As Is
Until recently, organizations dealt with the lack of cross-platform interoperability by leaving the islands of infrastructure as is and paying the overhead to administer systems in a separate and decentralized manner. Not only does the approach impact IT productivity, but it often forces end users to have multiple usernames and passwords for different applications, which can significantly impact the productivity and make the IT environment less secure, as passwords are often lost or stolen.

However, when it comes to managing and securing the heterogeneous and unintegrated environments, regulations, such as Sarbanes-Oxley, HIPAA and the payment card industry data security standard, call for standardized and centralized ways of controlling which users can access which systems, applications and data, and for auditing what those users did when they were granted that access.

Continuing to have separate and non-integrated mechanisms to centrally control access to key systems is no longer an option, as regulations clearly dictate that organizations should have a centralized mechanism to grant users appropriate access to corporate resources -- regardless of the platform that is being used. Some think only large, public companies need to meet the requirements. But, in fact, the requirements can be equally applicable to small retailers that accept credit cards comply with the payment card industry's data security requirements and that risk fines for failure to do so.

Different Paths
Faced with these issues -- compliance requirements; heterogeneous platforms; expensive, decentralized management; security vulnerabilities; multiple IDs and passwords per user; and pressure to reduce costs -- IT organizations have just a few paths to travel to reach a viable solution. Some of the paths include:

Do nothing and live with the balkanized environment. This short-term tactic is frequently accompanied by process or paper corrections. One company chose to solve the password change policy problem by having its administrators and developers sign an affidavit, asserting that they change their password on each system every 90 days. This hardly matches the intent of the law.

Many organizations feel forced into this situation while looking for a solution that fits a budget and doesn?t require intrusive changes to existing systems or business practices. The companies are willing to run the risk of being caught by regulators, or believe the money saved by delaying purchasing and implementing a solution will make up for any initial fines that may occur. Eventually, most organizations will have to understand potential fines will outweigh the savings from further delays and can cause negative publicity. Worse still is the security vulnerability the companies are exposing the organization to by not establishing the best practices prescribed by the regulations.

Try to implement an expensive and complex synchronization solution. Several existing identity management solutions leave existing systems in place and install solutions that map and synchronize user information and access rights between the various incompatible systems. There are a number of vendors to choose from in this category. But the approach has numerous problems

Extend an existing identity store to replace as many existing stores as possible. In this model, the goal is to select a central directory system that has a proven track record and a clearly defined future direction, and leverage that single identity system to replace and/or consolidate existing identity systems.

This option clearly makes the most business sense for solving the cross-platform identity management crisis. Consolidating and centralizing identity systems offers clear benefits in productivity, cost savings, security and reporting. The hard question to answer is: Which identity store has the potential to fill this need?

Active Identity
Given that active directory is an inseparable part of the Windows environment, and most organizations already have the system deployed, it is an ideal candidate for assuming the role as an organization's centralized identity system. Microsoft, however, focuses its efforts on the Windows platform and does not provide a comprehensive solution for embracing other platforms. This has led new identity management vendors, such as Centrify, to deliver solutions that extend active directory to platforms and applications that it does not natively support. Leveraging an existing active directory infrastructure also offers a cost-effective way to meet regulatory requirements within today's strained IT budgets.

IT organizations may be wary of leveraging a single directory for their enterprise access control needs, and it may be impractical to integrate a legacy identity system on a mainframe into a centralized environment. Still, a reduction in the islands of identity systems in the corporate network -- such as providing a single, integrated solution for Windows, UNIX, Linux and Mac -- can significantly improve end-user productivity, reduce operating costs, improve security and make it easier to meet regulatory requirements.

Regardless of whether you adopt synchronization or a strategy of embracing and extending an existing directory across the enterprise, it is essential to better integrate access control across heterogeneous systems to meet regulatory and compliance requirements. Regulations dictate organizations have a centralized mechanism to grant users appropriate access to corporate resources -- regardless of the platform that is being used. The security of organizations depend on it.

This article originally appeared in the November 2006 issue of Security Products, pg. 34.

Featured

  • 2025 Security LeadHER Conference Program Announced

    ASIS International and the Security Industry Association (SIA) – the leading membership associations for the security industry – have announced details for the 2025 Security LeadHER conference, a special event dedicated to advancing, connecting and empowering women in the security profession. The third annual Security LeadHER conference will be held Monday, June 9 – Tuesday, June 10, 2025, at the Detroit Marriott Renaissance Center in Detroit, Michigan. This carefully crafted program represents a comprehensive professional development opportunity for women in security this year. To view the full lineup at this year’s event, please visit securityleadher.org. Read Now

    • Industry Events
  • Report: 82 Percent of Phishing Emails Used AI

    KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today launched its Phishing Threat Trend Report, detailing key trends, new data, and threat intelligence insights surrounding phishing threats targeting organizations at the start of 2025. Read Now

  • NRF Supports Federal Bill to Thwart Retail Crime

    The National Retail Federation recently announced its support for the Combating Organized Retail Crime Act of 2025. The act was introduced by Chairman Chuck Grassley, R-Iowa, Senator Catherine Cortez Masto, D-Nev., and Representative Dave Joyce, R-Ohio. Read Now

  • ISC West 2025 Brings Almost 29,000 Industry Professionals to Las Vegas

    ISC West 2025, organized by RX and in collaboration with the Security Industry Association, concluded at the Venetian Expo in Las Vegas last week. The nation’s leading comprehensive and converged security event attracted nearly 29,000 industry professionals and left a lasting impression on the global security community. Over five action-packed days, ISC West welcomed more than 19,000 attendees and featured 750 exhibiting brands. Read Now

    • Industry Events
    • ISC West
  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West

New Products

  • QCS7230 System-on-Chip (SoC)

    QCS7230 System-on-Chip (SoC)

    The latest Qualcomm® Vision Intelligence Platform offers next-generation smart camera IoT solutions to improve safety and security across enterprises, cities and spaces. The Vision Intelligence Platform was expanded in March 2022 with the introduction of the QCS7230 System-on-Chip (SoC), which delivers superior artificial intelligence (AI) inferencing at the edge.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.