Home > Security All-in-One Guides > Compliance > Technology > Access control > 2006 Products of the Year: Identity and access management
All-in-One Guides: Compliance:
EMAIL THIS
 START   SOX SCHOOL   INFOSEC-RELATED REGS   STANDARDS   PROCESS IMPROVEMENT   PEOPLE & POLICY   TECHNOLOGY   AUDITS   
Technology


Access control
<< PREVIOUS | NEXT >>
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

2006 Products of the Year: Identity and access management


Staff
02.01.2006
Rating: --- (out of 5)


Network Security Tactics
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RSA ClearTrust
RSA Security, www.rsasecurity.com

"The struggle between security and usability is no greater anywhere than in health care," says Chris Gervais, senior research analyst/technologist for Partners Healthcare. Partners' challenge was to give community-based medical and administrative personnel easy, secure access to patient records throughout its extensive Massachusetts network of hospitals and clinics.

The solution, RSA Security's RSA ClearTrust, provided the convenient Web portal Partners needed, with the security that management -- and HIPAA requirements -- demanded. It's the kind of experience that spurred voters to make ClearTrust the gold-medal winner for identity and access management.

In the past, Partners' highly mobile employees had to rely on VPN access -- which meant using digital certificates, sending out installation CDs and giving direct network access to laptops vulnerable to spyware and other malicious code. This was both a management burden and an impediment to adoption.
More information on access management

Learn everything you need to know about access management in Lesson 2 of our Training for CISSP Certification.

Visit our resource center for tips and expert advice on access management.

 

"Clinicians and admins use ClearTrust to arrange care; largely, it's made it invisible," says Gervais. "They know they log in to a secure site with strong credentials."

Partners had a history with RSA, using RSA SecurID for strong authentication. But what sold Gervais -- and the organization's steering committee -- on ClearTrust over other Web-based access management products was confidence that RSA would provide more functionality out of the box and could get up and running quickly.

"We had an aggressive timeline. Time to market was important," Gervais says. "RSA brought the necessary resources to bear."

Readers gave ClearTrust some of the highest grades across the board in our Products of the Year survey, with particular emphasis on security and performance.

ClearTrust provides Web-based single sign-on capability with highly granular and flexible access control policies through what RSA calls Smart Rules technology. Smart Rules allows organizations to leverage existing data repositories to permit real-time authorization decisions and speed deployment. It supports a wide range of authentication options. Its comprehensive auditing and reporting features were a powerful persuader for Partners.

"Obviously, we have to comply with HIPAA, and we have to go through a bunch of audits," Gervais says. "With ClearTrust, our information security office sets up procedures; inside the application, we have clinical security policies down to the patient level. We can audit changes in patient records going back two years. It's nice, finely grained audit data."




Novell eDirectory
Novell, www.novell.com

At the heart of Novell's identity and access management offerings beats eDirectory, a mature and very solid directory product that draws reader praise for overall quality and security.










Sun Java System Directory Server Enterprise Edition
Sun Microsystems, www.sun.com

Sun's respected directory shines brightly, drawing reader kudos for performance and overall quality, with a strong vote for security.






Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Enterprise Single Sign-On (SSO),   User Authentication Services,   Enterprise Identity and Access Management,   PKI and Digital Certificates,   Technology,   Access control,   Compliance,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


<< PREVIOUS | NEXT >>
VIEW ALL IN THIS CATEGORY

RELATED CONTENT
Network Security Tactics
Screencast: Find rogue wireless acess points with Vistumbler
How to prepare for a secure network hardware upgrade
Preventing SQL injection attacks: A network admin's perspective
Screencast: How to launch an OpenVAS scan
Wireless network guidelines for PCI DSS compliance
Aligning network security with business priorities
Scanning with N-Stalker offers basic Web application security assessment
Lifecycle of a network security vulnerability
Screencast: BackTrack 4 offers an arsenal of penetration testing tools
Network access control technology: Over-hyped or underused?

Enterprise Single Sign-On (SSO)
How to log in to multiple servers with federated single sign-on (SSO)
Security on a budget: How to make the most of authentication tools
Best Identity and Access Management Products
Changing times for identity management
Kerberos configuration as an authentication system for single sign-on
How to use single sign-on for Web access control to prevent malware
Learn about enterprise strategy for server virtualization single sign-on
Enterprise single sign-on: Easing the authentication process
Exploring authentication methods: How to develop secure systems
User provisioning and SSO for PeopleSoft- and Unix-based products
Enterprise Single Sign-On (SSO) Research

PKI and Digital Certificates
Best Authentication Products
DoD urges less network anonymity, more PKI use
Researchers to demonstrate new EV SSL man-in-the-middle hacks
Portable security storage device could replace OTP devices
What is most misunderstood about EV SSL certificates?
VeriSign addresses MD5 flaw
Rogue digital certificates strike blow to Internet security
Can any firm or organization get a digital signature certificate?
How to obtain a digital certificate for a server
PKI and digital certificates: Security, authentication and implementation
PKI and Digital Certificates Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
onboarding and offboarding  (SearchSecurity.com)
single sign-on  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts