Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > How to manage user permissions
Ask The Security Expert: Questions & Answers
EMAIL THIS

How to manage user permissions

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 27 April 2006
On a daily basis, I receive requests for service account passwords, local admin access, permissions for files and shares, and a host of other access-related topics. Is there a best practice for managing such requests? I usually have them substantiated with an e-mail, but is that enough? Should these requests be kept on a spreadsheet somewhere? Does every request have to come with a manager's approval?

>
EXPERT RESPONSE

Absolutely. And this is too sensitive an issue for you to take on single-handedly. A confirming e-mail and a spreadsheet with requests are a good start, but aren't enough. You need something more formalized and centralized. Why?

  1. You run the risk of losing track of access management requests due to poor organization.

  2. You could be liable if there is an intrusion and an investigation traces it back to a password you issued to a malicious user. And, if your organization is large enough to have auditors, they may wave Sarbanes-Oxley (SOX) in your face as they review your records.

  3. Not every request requires a manager's approval. Many will come directly from users themselves who legitimately lose or forget their passwords. It happens, especially after someone tries to access a system they haven't used in a while.

Here are some best practices based on the size of your organization.

If your organization is large enough to have a dedicated Help Desk, all access requests should go through them first, even if you are the person responsible for setting up or changing user accounts. They should keep a log of all requests, including details about the request itself (password reset, file share, administrative access, etc.), who made the request, the time and date of the request, and the reason for the request.

If you're the lone individual in a smaller organization who's in charge of the organization's access management needs, you'll need some sort of centralized reporting software to keep track of each request with the details just mentioned.

There are a number of companies offering affordable products for managing, logging and centralizing access management.

More Information

  • Learn tips and tricks for managing password requests and resets.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Identity Management and Access Control
    CardSpace vs. user IDs and passwords
    Biometrics vs. biostatistics
    What are the dangers of using radio frequency identification (RFID) tags?
    What are the risks of connecting a Web service to an external system via SSL?
    What should an internal support model for identity management look like?
    What precautions should be taken if biometric data is compromised?
    How to choose the right biometric security product
    How to prevent hackers from accessing your router security password
    How does identity propagation work?
    Is it secure to use .NET membership class for user authentication?

    Web Access Control
    Vista WIL: How to take control of data integrity levels
    Video: Changes ahead for MIT Kerberos Consortium
    Kerberos security evolves for B2B, mobile tech
    Kerberos: Authentication with some drawbacks
    Sun shifts strategy with GRC push
    CardSpace vs. user IDs and passwords
    What are the risks of connecting a Web service to an external system via SSL?
    Enterprise security in 2008: Assessing access management
    Survey: Security Pros Identify Priorities for 2008
    How does identity propagation work?

    User Provisioning
    Societe Generale bolsters internal controls, discovers second insider
    Identity Management Suites Enable Integration, Interoperability
    Former LendingTree employees pilfer firm's customer database
    Hitachi acquires M-Tech Systems for identity management
    Sun shifts strategy with GRC push
    CardSpace vs. user IDs and passwords
    Security360: Identity management market
    Survey finds access control problems at many firms
    Information protection: Using Windows Rights Management Services to secure data
    Partner access: Balancing security and availability

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    access log  (SearchSecurity.com)
    anonymous Web surfing  (SearchSecurity.com)
    authentication, authorization, and accounting  (SearchSecurity.com)
    identity chaos  (SearchSecurity.com)
    multifactor authentication (MFA)  (SearchSecurity.com)
    walled garden  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts