Access can be further controlled by what type of device is being used to connect and where people authenticate themselves. For example, if a user connects to the network from a PC within the organisation’s premises then they can access all files and information needed to perform their duties. However, if they connect from a laptop from home, they may be restricted to just calendar information or basic applications. Taking it a step further, access can be further controlled by the day of the week and/or time of day that the person is accessing the network to determine what they can do and see.
While this might all sound extremely complex, fundamentally networkless connectively is far more flexible, with the underlying infrastructure easier to build and manage.
Historically, many access gateways required an individual to enter their username and password combination to authenticate themselves. While this may have been adequate for one organisation functioning from one location, as soon as you start co-locating, or even allowing remote access, single factor authentication is woefully inadequate and easily circumvented.
For this reason the introduction of two factor authentication (2FA) is increasingly being driven by legislation and/or the need to be more secure. 2FA fundamentally is the combination of two of three elements:
1. Something you know – a username or password, etc.
2. Something you have – an authentication device such as a smartcard, etc.
3. Something you are – referred to as biometrics it involves retina or fingerprint scanners etc.
Just so we’re all straight, a username and password combination is not 2FA as it is two variations of one element i.e. two things you know.
Now that we’ve established what 2FA is, it’s time to look at what the options are. Fundamentally there are two main forms of authentication device:
1. A physical token or smartcard
2. A virtual token – a mobile phone used to receive a passcode via SMS message or generate the code via an app.
Networkless connectivity combined with strong 2FA allows straightforward user access, without constraints, to deliver a completely dynamic set up at the time of connection. So, whether you’re merging, re-merging, de-merging or just looking to introduce a more flexible working practice, securely, make sure its future proof and cost-effective. Instead of getting physical, it’s time to start thinking outside the box, and even the building.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.