ACCESS CONTROL Articles
Leverage government innovation to reduce the risks of Web 2.0 identity management
Government innovation? Yes: ICAM, NIST and NSTIC offer ideas for improving online identity assurance
Financial services firms get enhanced authentication guidance
This month's update is designed to reinforce risk-based authentication for customers and covers layered security and other controls designed to mitigate transaction risk. Expert reaction to the guidance's efficacy is mixed.
LulzSec Calls it Quits After 50 Days of 'mayhem'
The computer hacking group LulzSec said Saturday it had ended its campaign of cyberassaults on government and corporate websites and that it was time for it to "sail into the distance."
Password management systems: How to compare and use them
Whether standalone or integrated into IAM suites, password management tools aim to provide both security and convenience
Dropbox Left Document Storage Accounts Open for Four Hours
Online storage service Dropbox accidentally turned off password authentication for its 25 million users for four hours on Monday -- although "much less than 1 percent" of those accounts were accessed during the period, the company said. It is still investigating whether any of those accounts were improperly accessed.
Putting a Finger on Compliance Control
Last year, administrators in the City of Winter Park, Fla., realized they had a serious compliance risk in their police department. The FBI's Criminal Justice Information Services Division has regulations that call for tight access controls for records. However, many officers share workstations and, therefore, also share passwords. The solution, they realized, was to deploy fingerprint scanners that would enable individual authentication.
Facebook tightens log-in verification
To help its hundreds of millions of users prevent unauthorized access to their accounts, Facebook has added an optional verification step to its log-in process.
The 3 types of insider threat
While the motivations are usually the same, there are three distinct, but different, types of insiders that can pose a threat to your organization's security. Jeffrey Jones and Ryan Averbeck detail what to look for to avoid unpleasant surprises
How DTCC achieved ID management
A look at why DTCC deployed identity and access management software from Hitachi ID Systems to automate its password management processes.
Man-in-the-browser attacks target the enterprise
With firewalls, antivirus and other security mechanisms protecting corporate networks, how do attackers manage to penetrate enterprise computer systems? Simply by exploiting the weakest link in the security chain.
