English   Deutsch

Martin Kuppinger: Saving with security

Saving with security
by Martin Kuppinger
mk@kuppingercole.com

Another area in which poor planning and lack of an overall strategy can prove painful are hardware-based authentication mechanisms like Smartcards, one-off password generators and other tokens. These are not just costly to implement, they are also expensive and difficult to run.

Recently the trend has been towards single-platform integration of various authentication mechanisms for different applications. Known as Versatile Authentication, this approach is aimed at making these mechanisms easier to use. It is in fact a very efficient strategy, and companies should ideally concentrate on a single, integrated card solution for both physical and logical security. Even better, they should include additional things like paying for coffee at the cafeteria. This will significantly lower logistical and management costs and at improve security at the same time.

Unfortunately, comprehensive solutions like these often get bogged down because of lack of cooperation between different departments or because someone already has a project running somewhere within the organization. Once again, blame can be laid on poor coordination. Shedding departmental blinkers and creating a comprehensive overview are the hallmarks of any good strategic planning.

The list goes on and on. IT security too often is hampered by problems brought on by a tactical versus a strategic approach to solution planning. Conflicting responsibilities are common root cause, as are excess complexity and lack of understanding. IT security, after all, can mean anything and everything from physical security to application security. Throw in the fact that employees are becoming more and more mobile and are using an ever-wider range of devices and it becomes evident that good-old perimeter defense simply won’t adequately protect your company any more.

It is exactly because the issue has become so complex that companies need to step back and look at the big picture; one that is unencumbered by siloed thinking within an organization. This is especially true for investment planning. As a rule, a limited number of well implemented and well managed security levels will beat a bunch of single solutions any day. Companies need to improve both their planning processes and their strategies if they want to make the most of increasingly restricted IT budgets. Short-term tactical investments are only good for filling holes, both real and imagined, in your security infrastructure.

Created: 26.06.09, modified: 01.07.09

Information
Newsletter
Kuppinger Cole Identity Management Newsletter
Services
KCP provides strategic consulting services for vendor and user companies covering all areas of identity & access management.
Reports
Use KCP as an independent, objective, and neutral authority on the Market for Identity Management products and solutions
Podcasts
Free audio and video presentations on important IAM-topics
Current surveys
IAM-Studie 2010
PARTICIPATE 
Virtualization Security Trends & Insights
PARTICIPATE 
Blogs
Tim Cole
28.08.2010 11:53
Not Just Any Port in a Storm
READ 
European Identity Conference Blog
27.08.2010 04:45
Google authentication support
READ 
Martin Kuppinger
12.08.2010 11:34
Diving down to the details of access controls
READ 
Sachar Paulus
11.08.2010 10:05
The GRC Marketplace is shaking up: SAP and CA partnering on GRC
READ 
Sebastian Rohr
04.08.2010 20:18
Your token to VISA…
READ 
Felix Gaehtgens
19.02.2010 17:40
Gerry Gebel joins Axiomatics
READ 
Joerg Resch
17.02.2010 11:15
Identity Management is key to Smart Grid Security
READ 
Links
 Kuppinger Cole News

 Kuppinger Cole Podcasts

 Kuppinger Cole on Facebook

 Kuppinger Cole on Twitter

 Visit us at Xing

 IAM-Wiki

 GenericIAM
Imprint Terms and conditions Privacy policy
© 2003-2010 Kuppinger Cole