Whether you should extend SSO outside your company is really a business decision you have to make. You need to...
ask yourself if there's a real business purpose for allowing a partner or vendor to have complete access to your system.
If the answer is yes, you need to perform two thorough risk analyses, one on your systems that will be accessed, and one on the outside party who will have SSO access to your system. If the risk analysis determines that the systems being accessed are low risk, meaning they don't have sensitive customer data or aren't used for financial transactions, then it may be worthwhile. For example, your company might be partnering with a marketing outfit that uses demographic data from your sales for market research. Such data usually can't be traced back to individual customers, where it could be used for draining accounts or stealing identities.
Make sure you perform a complete security review of any outside vendor you allow to access your system to verify that they meet your stringent security standards. The review should include tours of data centers for both physical and information security, whether employees go through background checks and if they have an information security policy or security awareness training program. Otherwise, they could be the weak link that allows malicious access to your system.
For More Information on SSO and authentication:
Dig Deeper on Single-sign on (SSO) and federated identity
Related Q&A from Joel Dubin
After a server room door has been compromised, finding a more secure solution is of utmost importance. Learn how to choose a server room door that ... Continue Reading
In the IAM world, what's the difference between access control and identity management. This IAM expert response explains how the two relate as well ... Continue Reading
When working with PeopleSoft and Unix, which single sign-on (SSO) vendors offer the most effective products? Learn how to choose an SSO product in ... Continue Reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.