Home > Security Tips > Web Security Advisor > 2006 Products of the Year: Authentication
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

2006 Products of the Year: Authentication


Staff
02.01.2006
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RSA SecurID
RSA Security, www.rsasecurity.com

With the threat of data theft and the demands of regulatory compliance, enterprises are clamoring for tools to ensure users accessing the network are indeed who they say they are.

Patrick A. CotÉ, information security officer for Houghton Mifflin Company, says RSA Security's RSA SecurID has proven itself as the best fit for his company. Others have reached the same conclusion, making it this year's gold-medal winner in authentication for the second straight year.

"With our prior system, you could really try to guess passwords," CotÉ says. "The whole password schema really wasn't very robust, so we looked for a two-factor authentication product."

His department rolled out SecurID tokens in May 2005; by late December, 2,500 accounts had been established in a Unix environment. So far, he says, "not a single person has had trouble authenticating."

The tokens are used strictly for remote access. "Once the PIN is set up, if the token is used correctly there's no downtime," CotÉ says. "It's very reliable. That was really why we chose RSA over the others. We needed that reliability."
More information on authentication

Find out who won our previous authentication Products of the Year.

Learn about the various forms of authentication with our Learning Guide.

Visit our resource center for news, tips and expert advice on authentication.

Check out the rest of our 2006 Product of the Year winners.

 

Users responding to the Products of the Year survey rate SecurID particularly high in the performance, vendor support/service, features and overall quality categories. One user SecurID calls it "the standard by which all others are judged." Another calls it a "first-rate and robust product." Others agreed with CotÉ that it is "very reliable."

Since 1986, SecurID has defined authentication, authorization and accounting, and still the SecurID system offers the application support, management/deployment capabilities, and a reputation for reliability and technical support that give it real-world utility in every type of enterprise.

While CotÉ has deployed it in a Unix environment, organizations can also deploy SecurID through a variety of hardware and software tokens for Windows workstations and assorted handheld devices and wireless phones.

SecurID's scalability is another critical factor, enabling large enterprises to deploy and manage authentication for millions of users and hundreds of apps through its Authentication and Deployment managers. The bundled Deployment Manager is automated, Web-based provisioning software that enables quick token deployment. Its self-service capability reduces the drain on IT staffs and help desks.

For SMBs, two-factor authentication is also available with the RSA SecurID Appliance, a hardened Windows box with embedded firewall functionality designed for easy management.




Steel-Belted Radius/Enterprise Edition
Funk Software (Juniper Networks), www.funk.com

Authentication is where the rubber hits the road, and this RADIUS/AAA server for wired and wireless networks helps keep enterprises running smoothly and securely.








VeriSign Managed PKI Services
Verisign, www.verisign.com

Trust is a cornerstone of security, and companies trust VeriSign, which won very strong survey approval for security, and good ratings for performance and overall quality for its range of PKI services.






Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Web Security Advisor
DNS rebinding defenses still necessary, thanks to Web 2.0
New defenses for automated SQL injection attacks
PCI compliance and Web applications: Code review or firewalls?
Worst practices: Bad security incidents to avoid
Web scanning and reporting best practices
Social networking Web site threats manageable with good enterprise policy
Enterprise security in 2008: Building trust into the application development process
PCI DSS Section 6: A plan for tackling application security
Making the case for Web application vulnerability scanners
Preparing for uniform resource identifier (URI) exploits

PKI and Digital Certificates
What is the best way to administer exams to students via computer?
Should computer exams be transmitted as PDF files or Word files?
Should PKI systems be used for laptop encryption?
Email authentication showdown: IP-based vs. signature-based
VeriSign to shed businesses, return to security roots
How do anonymous credentials and selective disclosure certificates affect enterprise IAM?
Choosing from the top PKI products and vendors
Can the symmetric encryption algorithm for S/MIME messages be changed?
Securing VoIP Networks: Threats, Vulnerabilities and Countermeasures
Creating a personal digital certificate
PKI and Digital Certificates Research

Enterprise Single Sign-On (SSO)
Sun launches open source OpenSSO for identity management
What are the pre-requisites for implementing single sign-on (SSO) in an organization?
Startup Symplified delivers SSO in the cloud
SaaS Offering Handles SSO
Kerberos security evolves for B2B, mobile tech
IBM acquires Encentuate for single sign-on software
Security360: Identity management market
Top 10 access-related controls for PCI compliance
What type of protections should security question and answer authentication credentials have?
Traditional single sign-on (SSO) products versus federated identities
Enterprise Single Sign-On (SSO) Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
authentication server  (SearchSecurity.com)
Certificate Revocation List  (SearchSecurity.com)
Digital Signature Standard  (SearchSecurity.com)
HDCP  (SearchSecurity.com)
MD2  (SearchSecurity.com)
MD4  (SearchSecurity.com)
MD5  (SearchSecurity.com)
nonrepudiation  (SearchSecurity.com)
PKI  (SearchSecurity.com)
public key  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts