Protect your data with IAM

July 2012 Information Security, Access Control & Identity Management

Jaroslav Cerny
Jaroslav Cerny

If knowledge is power, then data is currency in today’s world. Cybercrime has become more lucrative than the drug trade, and businesses understand that security is of the utmost importance in protecting their data. However, protecting from external threat is no longer enough.

An increasing number of information crimes are being committed from within organisations, behind the firewall where the perpetrators are already inside the security systems. This makes protecting data from the inside, managing access and permissions and verifying the identity of those accessing data, a critical item on the corporate security agenda.

Impending legislation of the Protection of Personal Information (POPI) Bill means that information security is a topic of discussion and debate around boardroom tables throughout South Africa. At its most basic, POPI aims to regulate the privacy of client data. This Bill has been driven by the pressing need to prevent increasing numbers of cases of identity theft, which can have devastating impact on the lives of the people who fall victim to it.

One of the core principles of POPI requires that all personal information be kept secure against the risk of loss, unauthorised access, interference, modification, destruction or disclosure. Once POPI comes into effect, companies by law will have to ensure that client information is adequately protected. Identity and access management (IAM) has thus become critical in ensuring that unauthorised individuals cannot gain access to sensitive information, and that permission is granted to access data on a need-to-know basis.

However, the need for identity and access management to secure data is not only a matter of compliance, but a vital aspect of any comprehensive organisational security plan.

Database protection

Database security without permissions, access parameters and identity verification is vulnerable to exploitation internally. Even the most stringent external controls can be compromised by an individual inside the network who is able to access, copy and remove data that they should not have access to. As an example, not every employee needs to have access to the human resources or financial data of an organisation. In the same vein, not everyone who requires access to this data needs to be able to copy it onto an external device such as their laptop or a flash drive.

While IAM is the next step in protecting organisations from data breaches, leaks and compromised information, the concept is not new. It is well known that limiting the number of people who can access sensitive data and controlling permissions as to what they can do with this data based on identity management narrows the potential for this data to be leaked. This in turn lowers risk. However, the evolution of the Internet and the growth of the mobile workforce and mobile devices necessitate that systems be opened up to outside use.

Security is no longer a matter of locking out the outside world and providing a username and password. This means that identity management itself has evolved to include roles, rules and parameters for each individual. This in itself, however, is a delicate balancing act since permissions and roles that are too rigid can inhibit business productivity, and permissions and roles that are too lax can once again introduce risk.

No rules

Further complicating this matter is the fact that there are no hard and fast rules regarding the optimal balance. This differs entirely depending on the organisation, the industry it operates in and its internal culture, amongst other things. Security touches on every system, every process and every person in an organisation. Because of these complexities and because of the need for certain external controls and best practices, it is often a good idea to outsource certain aspects of security, including database security elements such as IAM.

While security can never be entirely outsourced, especially for control purposes, partnering with an outsourced provider offers a measure of continuity. If handled completely in-house, this can never be internally guaranteed, since employees may leave an organisation and take their knowledge with them. Outsourced providers often have far greater aggregated experience and specialised knowledge with implementing specialised database security solutions such as identity and access management.

The database is mission critical to the majority of organisations, and if security implementations are implemented incorrectly, they can wreak havoc and even shut down entire systems when they go live. Outsourced specialists bring the necessary experience, shorten implementation times, have a knowledge of best practices and can provide a practical road map of what needs to be done and when in order to reach security goals.

As the threat landscape has evolved, so too has security, but the fact remains that criminals will always single out the weakest targets. Without sophisticated tools such as IAM in place to protect databases, organisations are left vulnerable to fraud, compromised data and corporate espionage. Added to this, the impending passing of the POPI Bill into law means that security is no longer just a matter of good practice but of compliance as well. To remain competitive in an increasingly regulated, data driven and threat riddled market, databases need to be protected, inside and out.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
Empower individuals to control their biometric data
Information Security Access Control & Identity Management Security Services & Risk Management
What if your biometrics, now embedded in devices, workplaces, and airports, promising seamless access and enhanced security, was your greatest vulnerability in a cyberattack? Cybercriminals are focusing on knowing where biometric data is stored.

Read more...
Security industry embraces mobile credentials, biometrics and AI
AI & Data Analytics Access Control & Identity Management Integrated Solutions
As organisations navigate an increasingly complex threat landscape, security leaders are making strategic shifts toward unified platforms and emerging technologies, according to the newly released 2025 State of Security and Identity Report from HID.

Read more...
Strategies for combating insider threats
Information Security Security Services & Risk Management
In Africa, insider threats pose an increasingly significant risk to businesses, driven by economic uncertainty, labour disputes, and rapid digital transformation. These threats can arise from various sources, including disgruntled employees and compromised third-party service providers

Read more...
Nice launches DC Blue Astute garage door motor
Nice Group South Africa Technews Publishing News & Events Access Control & Identity Management Perimeter Security, Alarms & Intruder Detection
Nice Systems SA has launched the Nice DC Blue Astute, a garage door motor for the South African market featuring a pre-installed lithium-ion battery instead of traditional lead-acid batteries.

Read more...
Five tech trends shaping business in 2025
Information Security Infrastructure
From runaway IT costs to the urgent need for comprehensive AI strategies that drive sustainable business impact, executives must be prepared to navigate a complex and evolving technology environment to extract maximum value from their investments.

Read more...
Kaspersky’s predictions for 2025 APT landscape
Information Security
The 2025 advanced persistent threat (APT) includes the rise of hacktivist alliances, increased use of AI-powered tools by state-affiliated actors – often with embedded backdoor – more supply chain attacks on open-source projects.

Read more...
SecurityHQ certified B-BBEE Level 1: Delivering global services from a local entity
SecurityHQ Information Security
SecurityHQ, a global managed security services provider (MSSP) with an office in South Africa, has announced it can now offer local companies a complete managed cybersecurity service from a Level-1 B-BBEE accredited and 51% black-owned service provider.

Read more...
2024, the year of Fraud-as-a-Service
Information Security
A report from AU10TIX outlines how ‘the industry’s dark engine’ offers user-friendly fraud kits that enable amateurs to execute complex attacks against thousands of accounts in minutes.

Read more...
The future of endpoint security
Information Security
Endpoint security is a critical pillar of cybersecurity, especially for South African businesses, which are becoming prime targets for cybercriminals. Endpoint security involves safeguarding devices connected to a network from a range of cyberthreats.

Read more...