Home > Midmarket IT Security Tips > > IAM best practices for employees with varying degrees of access to the same computer
Midmarket IT Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


IAM best practices for employees with varying degrees of access to the same computer


Joel Dubin
02.05.2009
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


In our organization, several users often have to share access to applications and resources on a single PC. However, we need to make sure passwords and files remain secure. What's the best way to implement access management among employees who need varying degrees of access to the same computer? Is it best to have a fingerprint scanner? Does another technology make more sense?

The answer to protecting access to a single PC with multiple users is a combination of both policy and technical controls. On the policy side, make sure each user having access to this particular PC -- and any other workstation or server -- has a unique user ID and password. This should be stated clearly in the corporate IT security policy.

The idea behind unique user IDs is to be able to keep track of not only user logins, but also all user activity on the PC. If there is an incident, or other security breach, access can be traced to an individual. Shared user IDs, even if only for a small group, make this impossible.

Both Windows and Unix, including Linux, allow multiple user accounts on a single local machine. Each user has an account, whose access and activity should always be logged. This, again, is for tracking who might have accessed the machine in the case of malicious access.

As for technical controls, such as fingerprint scanners or smart cards, this should be driven by the risk level of the data being accessed and an organization's specific business needs and requirements. Business risk should drive enterprise security controls, not the other way around.

Do a thorough risk analysis of the data being accessed on the PC. Is it sensitive customer information or proprietary company data? Or is it demographics for marketing purposes that can't be tied back to individual customers? The first is of higher risk and should be protected with stronger controls, and the second is lower risk that doesn't require such tight controls.

It also seems like this PC isn't connected to the network, meaning it can't really be controlled through any domain-level controls, such as those in Active Directory or LDAP. With that in mind, you'll have to rely on local controls on the PC itself and base access on the risk level of the files and data it holds.

Also, make sure that no one on the workstation has administrative access. Otherwise, each of the multiple users could have access to each other's files, defeating the purpose of having separate accounts on the PC.


Rate this Tip
To rate tips, you must be a member of SearchMidmarketSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Microsoft identity and access management
Understand the pros and cons of Microsoft Windows 7 DirectAccess
Microsoft SharePoint security hinges on authorization, external user management
Poor Microsoft SharePoint security permissions policies can derail deployments
How to use Kerberos and Credential manager for Windows single sign-on
Three ways to prioritize endpoint security over perimeter defenses
Microsoft Windows RMS enables granular access control over sensitive data
Microsoft Stirling Beta 2 release includes Exchange SaaS offering
Demystifying identity management
Five key challenges in managing identities
Quiz: Building an identity and access management architecture

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts