Showing posts with label biometric authentication. Show all posts
Showing posts with label biometric authentication. Show all posts

Sunday, 3 May 2009

Five Tips For Securing Information and Mitigating Risk

Adopt Single Sign On: Connecting people to resources and allowing access to authorised data is one of the main issues facing the IT department, and one that has the biggest security implications. Single sign on uses strong authentication measures such as biometrics to ensure the identity of the person connecting to central services and accessing corporate data.



Use Encryption: Rather than fire fighting to keep the perimeter safe, organisations are increasingly looking to secure data where it resides through encryption. However, to do this successfully, companies will need to understand the value and sensitivity of data it holds in order to apply the appropriate levels of protection.



Deploy Multiple Virus Checkers: Viruses, trojans, malware and spyware will never go away, so constant vigilance is a must. Invest in market leading security software applications to ensure risk is significantly reduced.



Develop a Security Culture: Social networking has the potential to become one of the greatest threats to enterprise security. Any technology that allows employees to mix their work and personal life could be dangerous if not carefully managed. However, many companies are employing people for their social networking skills and contacts, so this is an area that needs to be addressed rather than feared. Using education to establish security as an integral parts of the corporate culture is the easiest way to minimise risk and make everybody aware of the level of security required.



Audit Information Assets: Organisations have to define what constitutes an information asset in terms that reflect its value to the business. The only people who can do this are the creators and owners of the data, the IT department does not have the ability to fully comprehend the commercial value of the corporate data it looks after, but it can advise on the best way to keep it safe and secure.

BIOTECNIX LIMITED'S 10 Top Tips For Avoiding Data Loss within Today’s Corporate Environment

Implement a strong employee joining and exit process: Revoke email and network access quickly when an employee leaves. Give new members of staff access only to the resources they need.

Educate staff: Ensure data is only accessible to staff on a need-to-know basis or push data to relevant people.

Avoid remedial action: Don’t plug holes with a point security product – implement systematic controls between the data not on the network or gateway.

Identify assets and information flows: Map intellectual property and the way it is accessed to help identify and prioritise your security approach.

Restrict the manipulation of data: Plan who needs access, print authorisation, data alteration and export rights to email, online messaging or removable devices. Apply restrictions to specific documents or content by time and location.

Watch the gatekeepers: Subject system administrators and privileged users to change management and critical server file integrity checks.

Don’t overlook the obvious: Block data export on removable data storage/transfer devices and scan outgoing email for confidential attachments. Restrict copy and paste for instant messaging and other social networking media.

Use encryption: Where you permit data export to removable media, ensure it is encrypted.

Use multi factor authentication: Always combine a password with secondary method of authentication, such as biometric readers.

Combine your security arsenal: Integrate physical biometric access systems, CCTV and even RFID, with virtual data network security systems to provide more effective evidence and protection against security breaches.