{"id":658,"date":"2015-08-28T11:02:18","date_gmt":"2015-08-28T15:02:18","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=658"},"modified":"2015-08-28T11:39:32","modified_gmt":"2015-08-28T15:39:32","slug":"a-world-without-access-management","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/","title":{"rendered":"A World Without Access Management"},"content":{"rendered":"<p>By Robert Doswell<img loading=\"lazy\" decoding=\"async\" class=\"alignright size-thumbnail wp-image-660\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/08\/RobD-150x150.jpg\" alt=\"RobD\" width=\"150\" height=\"150\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/08\/RobD-150x150.jpg 150w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/08\/RobD-70x70.jpg 70w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/08\/RobD-60x60.jpg 60w\" sizes=\"(max-width: 150px) 100vw, 150px\" \/><\/p>\n<p>What would happen if access management disappeared overnight and we had to cope without it? What impact would this have on an organization and its information systems? Let\u2019s have a quick look at this scenario.<\/p>\n<p>We\u2019ll begin by recapping on what exactly access management means in the modern world.<\/p>\n<p>There are three closely related terms that cover the aspects of \u201caccess management\u201d; \u201cauthentication\u201d, \u201cauthorization\u201d, and their control \u2013 access management.<\/p>\n<p>With authentication the user simply proves that they are who they say they are. This could be a simple log on to a home PC, a log on to a corporate network or even a log on to a till in store. The most common form of authentication in these situations is via a username and password, or maybe a username and a PIN in the till situation. A stronger form of authentication couples the username and password with something physical, such as a card swipe, token or some form of biometric scan.<\/p>\n<p>Authorization follows once the user has successfully authenticated themselves. Even on the home PC, authorization has a role. A parent will undoubtedly have more control over their home PC compared with a child. Web content should be restricted for the child, where it may be open for the parent and the child\u2019s account should be limited to prevent system setting changes.<\/p>\n<p>In the corporate world, things get much more complex. Depending on the user\u2019s function, role and location, access rights, home drive locations, printer settings, etc. all change. Even in an SME this can quickly become complex. In large organizations, specialist access and identity management products are required to successfully manage this access management. In a nutshell, your authentication validates your authorization. By successfully authenticating a user, it can be guaranteed that the individual does not have too many rights, and they do not gain access to information that is not pertinent to them.<\/p>\n<h4><strong>So what would happen if access management disappeared?<\/strong><\/h4>\n<p>Let\u2019s look at this from real world examples. We\u2019ll remove authentication and authorization from the picture completely and focus on situations where data has been compromised:<\/p>\n<p><strong>Sony PlayStation \u2013 April 2011<\/strong><\/p>\n<p>Following claims that hackers stole 2.2 million customer credit card details (including CVV\u2019s), Sony took the decision to take down the PlayStation network for more than a week.<\/p>\n<p><strong>eBay \u2013 May 2014<\/strong><\/p>\n<p>Online marketplace eBay forced users to change their passwords following a cyberattack that compromised its systems.<\/p>\n<p><strong>Ashley Madison \u2013 August 2015<\/strong><\/p>\n<p>The online adultery site suffered a huge data breach, with a list of their subscribers being leaked on the dark web. The media reported suicides as a consequence.<\/p>\n<h4><strong>How does this relate to access management?<\/strong><\/h4>\n<p>Although these firms suffered a compromise, the potential for data theft and its impact is identical if you remove access management. Users are privy to data they should not be. How many hospital workers have access to patient information? How many workers in financial markets have access to<\/p>\n<p>personal bank accounts or credit card details? If access management didn\u2019t exist, none of the above could be controlled. Data leaks and fraud would be uncontrollable, and untraceable.<\/p>\n<p><strong>Physical Access<\/strong><\/p>\n<p>Access management also covers physical access. In hospitals, users carry swipe cards to grant them access to specific areas of the hospital, again depending on their function, role and location. If access management disappeared, hospital workers, for example, would be free to roam wards, stock rooms, server rooms, etc. at will. There would be no control over drug access. No patient security.<\/p>\n<p><strong>Legislation and regulations<\/strong><\/p>\n<p>If users are able to use a network with no authentication, it becomes impossible to comply with any form of legislation or regulation. It is impossible to identify who read a file, who accessed a database or even who processed a credit card transaction. Try and answer the question \u201cwho did what, where, when, and why?\u201d Impossible.<\/p>\n<p><strong>Licence Control<\/strong><\/p>\n<p>In a modern Microsoft-centric network, access to applications is controlled via Group management; a simple way to control who has access to what. For example, a salesperson may be added to the group \u201csales.\u201d All members of the group \u201csales\u201d have access to Salesforce and the sales departmental share. As sales people come and go, by simply managing the sales group access to Salesforce is easily granted or revoked. However, without access management, users would individually need to request applications or all users could be given access to all applications. This either results in a situation that is unmanageable, or one that is extremely costly.<\/p>\n<p><strong>Commercial interests<\/strong><\/p>\n<p>There are commercial organizations that have a great deal of interest in authenticating users, for example, publishers or a company like LinkedIn. These organisations may offer some of their content free of charge, but for a far larger part of their content the user must be able to authenticate himself or herself, and of course pay. If there was no access management, there would no longer be any ability to draw a distinction between free and paid content.<\/p>\n<p>These are a few examples of the issues which might arise in a world without access management. And, of course, any number of other scenarios could be devised. A world without access management would certainly be a world with a lot of concerns.<\/p>\n<p><em>Robert Doswell is managing editor of <a href=\"https:\/\/www.tools4ever.co.uk\/\" target=\"_blank\">Tools4ever UK<\/a>, part of the global provider of identity and access management solutions.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Robert Doswell What would happen if access management disappeared overnight and we had to cope without it? What impact would this have on an organization and its information systems? Let\u2019s have a quick look at this scenario. We\u2019ll begin by recapping on what exactly access management means in the modern world. There are three [&hellip;]<\/p>\n","protected":false},"author":24,"featured_media":659,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[142,125,143,105],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>A World Without Access Management<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Edwards\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/\",\"name\":\"A World Without Access Management\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/08\/noaccess.jpg\",\"datePublished\":\"2015-08-28T15:02:18+00:00\",\"dateModified\":\"2015-08-28T15:39:32+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\"},\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/08\/noaccess.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/08\/noaccess.jpg\",\"width\":600,\"height\":300},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"A World Without Access Management\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\",\"name\":\"Jeff Edwards\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"caption\":\"Jeff Edwards\"},\"description\":\"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.\",\"sameAs\":[\"https:\/\/solutionsreview.com\",\"https:\/\/x.com\/InfoSec_Review\"],\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"A World Without Access Management","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/","twitter_misc":{"Written by":"Jeff Edwards","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/","url":"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/","name":"A World Without Access Management","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/08\/noaccess.jpg","datePublished":"2015-08-28T15:02:18+00:00","dateModified":"2015-08-28T15:39:32+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6"},"breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/08\/noaccess.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/08\/noaccess.jpg","width":600,"height":300},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/a-world-without-access-management\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"A World Without Access Management"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6","name":"Jeff Edwards","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","caption":"Jeff Edwards"},"description":"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.","sameAs":["https:\/\/solutionsreview.com","https:\/\/x.com\/InfoSec_Review"],"url":"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/658"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=658"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/658\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/659"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=658"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=658"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=658"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}