Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > What are the criteria for a strong authentication system?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What are the criteria for a strong authentication system?

Joel Dubin, past SearchSecurity.com expert EXPERT RESPONSE FROM: Joel Dubin, past SearchSecurity.com expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 10 November 2006
What are the components of a strong authentication system?

>
A "strong" authentication system can be defined in many ways, but the real answer to a solid authentication program lies in risk assessment. Before choosing any authentication system or its components, take a hard look at what you're trying to protect and the level of protection it demands.

Risk assessment is a vast topic and has been the subject of entire books. But the basic parts of a risk assessment include the following questions:

  • What type of data are you protecting? Is it sensitive customer information that, if stolen, could open your customers to identity theft? Is it confidential company plans? Or is it just promotional information freely available to the public in company brochures?
  • What types of systems are you trying to protect? Are they network resources that, if maliciously accessed, could shut down or cause financial damage to your company? Or are they smaller, isolated systems used for testing?
  • Who are your users? Are they strictly employees, or are they thousands of customers?
  • Does your company have a Web site? Is it used for transferring money, or just brochureware?

Once you've assessed the risk, you can then decide how strong your authentication tools need to be.

The bare minimum components of any access management system should include a user ID and password. Beyond that, the best approach is to enhance your security with additional layers of protection.

Additional layers of protection could include any of the following:

Again, there is no cut-and-dried formula. You can use one of the above devices or a combination of them. Pick and choose based on a thorough risk analysis of your systems and users.

More information:

  • Find out which authentication devices will enhance your laptop security.
  • Learn how to conduct a risk analysis.


  • BROWSE BY TAG
    Identity Management and Access Control,   Two-Factor and Multifactor Authentication Strategies,   Enterprise Identity and Access Management,   User Authentication Services,   Enterprise User Provisioning Tools,   Identity Management Technology and Strategy,   Expert Archive: Identity Management and Access Control,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Identity Management and Access Control
    How to find and remove keyloggers and prevent spyware installation
    How to encrypt passwords using network security certificates
    Prevent meet-in-the-middle attacks with TDES encryption
    How to use single sign-on (SSO) for a server configuration
    Choosing management for Active Directory user provisioning
    LDAP signing requirements for various directory configurations
    User account best practices for an investment management website
    How to determine password strength for a website
    The pros and cons of implementing smart cards
    Keep files from being deleted by assigning read and execute permission

    Two-Factor and Multifactor Authentication Strategies
    PhoneFactor bolsters authentication using voiceprint identification
    Risk-based multifactor authentication implementation best practices
    Two-factor authentication, vigilance foil password theft
    The pros and cons of implementing smart cards
    Security on a budget: How to make the most of authentication tools
    Best Authentication Products
    Best Identity and Access Management Products
    Are 'strong authentication' methods strong enough for compliance?
    PCI compliance requirement 7: Restrict access
    PCI compliance requirement 9: Physical access

    Enterprise User Provisioning Tools
    IAM trends: Rebuilding security with provisioning technologies
    Quiz: Compliance-driven role management
    Identity lifecycle management for security and compliance
    Choosing management for Active Directory user provisioning
    User account best practices for an investment management website
    Content-aware IAM: Uniting user access and data rights
    Keep files from being deleted by assigning read and execute permission
    Is Identity Management as a Service (IDaaS) a good idea?
    Top tactics for endpoint security
    How to edit group policy objects to give a user local admin rights

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    AAA server  (SearchSecurity.com)
    authentication  (SearchSecurity.com)
    authentication, authorization, and accounting  (SearchSecurity.com)
    federated identity management  (SearchSecurity.com)
    identity access management (IAM) system  (SearchSecurity.com)
    Kerberos  (SearchSecurity.com)
    password hardening  (SearchSecurity.com)
    typeprint analysis  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts