Home > Security Tips > IAM Insights > Identity and access management 2009: Staff cuts, insider threats
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

IAM INSIGHTS

Identity and access management 2009: Staff cuts, insider threats


David Griffeth, Contributor
01.13.2009
Rating: -3.00- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Spotlighting the hard work you do is not arrogant if it's based in fact, and more importantly, it may save someone's job.
What challenges will 2009 bring for identity and access management professionals? With the world economy in a state of turmoil, markets correcting themselves and employers reducing staff, the pull of illicit insider activity is stronger than ever.

Companies across all sectors have already begun to lay off staff. It may begin with the "dead wood," but inevitably some companies are going to have to lay off talented IT and information security professionals. Illegal activities that once seemed unpalatable to out-of-work technologists may seem better than starving: Just as liquor store break-ins and gas n' go crimes will increase, so will more sophisticated crimes, such as data theft and social engineering. While it may seem hard to imagine, criminal actions are often committed by former employees who rationalize the activity because they're upset about losing their jobs.

The challenge for identity and access management professionals will be securing data from former employees who know the system from the inside out.

Defense strategies: Proactive IAM processes
Locks keep honest people honest, or, in the case of identity and access management, account terminations keep honest people honest. Identity management and information security professionals will need to scrutinize their account-termination processes like never before, because leaving an unauthorized or former employee's account active and enabling access to sensitive or valuable data could be catastrophic. Make sure to have an updated roster of every account owned by every individual in the company so that all those accounts can be deleted or disabled if anyone is terminated.

Don't miss need-to-know info!

Security pros can't afford to be the last to know. Sign up for email updates from SearchSecurity.com and you'll never be behind the curve!
Now is the time to be proactive. Assess and refine existing processes. How long has it been since the company's entire account life cycle process was last evaluated? Are you confident in the integrity of that process, including the external data it depends on, such as HR feeds? Is the governance data for contractors sufficient and timely? Are there appropriate separations of duties, and are they adhered to? If the answers to these questions are unclear or unknown, alert management and start evaluations for process improvement.

IAM and budget cuts: Using frameworks and documentation
Another challenge in 2009 will be funding. Budget promises made in 2008 are sure to be forgotten as many companies adjust to the new economic reality. So how will enterprises properly secure data when the funding to do so may seem insufficient? Innovation. Set up a framework that is effective, even if manually intensive. An example of this may be an Excel- or Outlook-based quarterly report for system owners that details accounts with privileged access, identifys owners and partners, establishes roles, and archives emails on a secure file share. This will initiate an ongoing process that can be refined in the future, perhaps with more sophisticated technology, when finances are better.

There are a few other important strategies for making sure the security program doesn't suffer because of financial cuts. If you have documented what your people do on a day-to-day basis in detail, now is the time that information may pay off; it may allow you to not only justify exactly why each person is important, but also clearly demonstrate what the fall-out will be if the staff is reduced. Personnel reductions may still be mandated, but data can help you make those hard decisions in an unbiased way and set management expectations from the start about the consequences of staff reduction.

For more information
Learn more about enterprise security threats in 2009.

Get tips for increasing network security with a decreasing budget.
Important statistics to keep may include how many accounts are under management, turnaround time for account creation and removal, reporting demands from various departments, and objects under management such as mainframe profiles and Active Directory groups. If these statistics haven't been kept in the past, start keeping them now, then pick data that will help management see the security team in the most favorable light possible. Spotlighting the hard work you do is not arrogant if it's based in fact, and more importantly, it may save someone's job.

Conclusion
In such a troubled economy, external threats will increase as well. There will be plenty of talented developers out of work that may discover their skills make them excellent bot programmers or hackers. While these threats are too numerous to detail here, it's still essential to be on guard by making sure the controls for external risk mitigation are assessed as well.

It's clear that 2009 will be drastically different from 2008. Rely on what has been tried and true in the past, but be ready to innovate and improve quickly based on new threats and changing business needs.

About the author:
David Griffeth is the Vice President of Business Line Integration and Reporting at RBS Citizens Bank, a financial institution that is one of the 10 largest commercial banking companies in the United States ranked by assets and deposits. As part of his responsibilities, David manages the Enterprise Identity and Access Management group and is charged with supporting the bank's growth model while maintaining compliance with several regulatory bodies. Prior to his current position, David consulted on major information risk management projects with large companies such as Fidelity Investments and CIGNA. David earned a bachelor's degree in computer science from Framingham State College and holds several certifications including CISSP and CISA.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
IAM Insights,   Security Industry Market Trends, Predictions and Forecasts,   Information Security Management,   Enterprise User Provisioning Tools,   Enterprise Identity and Access Management,   Identity Management Technology and Strategy,   Password Management and Policy,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
IAM Insights
Content-aware IAM: Uniting user access and data rights
Security on a budget: How to make the most of authentication tools
Making the case for enterprise IAM centralized access control
Best practices for a privileged access policy to secure user accounts
Best practices: How to implement and maintain enterprise user roles
Kerberos configuration as an authentication system for single sign-on
How to use single sign-on for Web access control to prevent malware
Deleting user accounts: How to manage users during a layoff
The value of application whitelists
User provisioning: Emerging product features reveal market's future

Security Industry Market Trends, Predictions and Forecasts
Hackers to sharpen malware, malicious software in 2010
Part 1: Marcus Ranum on the state of information security
Part 2: Marcus Ranum on the state of information security
Part 4: Marcus Ranum on the state of information security
Part 3: Marcus Ranum on the state of information security
Part 5: Marcus Ranum on the state of information security
Layoffs prompt insider threat fears, cybersecurity survey finds
Healthcare security spending remains sluggish, report shows
How to use Internet security threat reports
M86 buys Web security gateway vendor Finjan
Security Industry Market Trends, Predictions and Forecasts Research

Enterprise User Provisioning Tools
Identity lifecycle management for security and compliance
Content-aware IAM: Uniting user access and data rights
Is Identity Management as a Service (IDaaS) a good idea?
Top tactics for endpoint security
How to edit group policy objects to give a user local admin rights
Privileged account management critical to data security
Making the case for enterprise IAM centralized access control
Lesson 3: How to implement secure access
Best practices for a privileged access policy to secure user accounts
Risk management must include physical-logical security convergence

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
backscatter body scanning  (SearchSecurity.com)
marketecture  (SearchSecurity.com)
NCSA  (SearchSecurity.com)
Palladium  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts