{"id":786,"date":"2015-11-09T16:00:12","date_gmt":"2015-11-09T20:00:12","guid":{"rendered":"https:\/\/solutionsreview.com\/identity-management\/?p=786"},"modified":"2015-11-09T15:26:18","modified_gmt":"2015-11-09T19:26:18","slug":"improve-security-and-avoid-breaches-by-avoiding-access-creep","status":"publish","type":"post","link":"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/","title":{"rendered":"Improve Security and Avoid Breaches by Avoiding Access Creep"},"content":{"rendered":"<div><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-560\" src=\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/06\/d.wiech_.jpg\" alt=\"d.wiech\" width=\"80\" height=\"80\" srcset=\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/06\/d.wiech_.jpg 80w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/06\/d.wiech_-70x70.jpg 70w, https:\/\/solutionsreview.com\/identity-management\/files\/2015\/06\/d.wiech_-60x60.jpg 60w\" sizes=\"(max-width: 80px) 100vw, 80px\" \/>By Dean Wiech<\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><b>\u00a0<\/b><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">Is there anything more difficult to manage or overwhelming to overcome than organizational security issues? Perhaps only managing a company\u2019s most important resources, its people. Security breaches continue to shed light on just how easily hackers can access complex systems and steal important information from organizations and their customers. While this is scary for customers, it is equally devastating to the organizations and those affected. This type of news shocks and scares organizational leaders as they realize that their organizations and their data are not safe, and perhaps that their security measures are not as strong as they may think.<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">\u00a0<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">Leaders need to ensure that their client information is truly secure and that employees and contractors only have the access to the information that they are permitted to access. Data is your most important asset. Even if you think you have nothing to protect or worry about, be careful. Perhaps you collect customer information like addresses, names of their businesses, credit cards, etc. as part of client profiles &#8212; all valuable assets for those in the data piracy business.<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">\u00a0<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">In many cases, breaches are inside jobs. Either because of holes in access rights or because employees and contractors purposefully target your company\u2019s information for their own profit. According to\u00a0<a href=\"https:\/\/hbr.org\/2014\/09\/the-danger-from-within\" target=\"_blank\">Harvard Business Review<\/a>, the 2013 Target breach was a result of hackers gaining entry to the retail chain\u2019s systems by using the credentials of one of the company\u2019s refrigeration vendors. At least 80 million insider attacks occur in the United States each year, according to estimates, but the number may be much higher\u00a0because they often go unreported.<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">\u00a0<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">One breach of information can cause major damage to an organization, mostly related to the public\u2019s trust in an organization and public perception of you. Secure information can easily be accessed if the correct measures aren\u2019t in place. Leadership may feel that their network is secure, but many security measures can actually cause additional issues.<\/span><\/div>\n<div><\/div>\n<div>Breaches from insiders will continue to take place. Insider access means access to an organization&#8217;s most valued information and resources. However, some inside breaches occur as a result of employees having too much access who steal or misuse their access to information. Thus, access is the most common thread to many organizational issues, even if the breach is non-intentional.<\/div>\n<div><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">Security <i>and <\/i>access to systems and information by employees and insiders are equally important. We need to <span style=\"color: black\">have proper security settings in place to ensure only people who should have access do, but we also need access control to ensure that authorized people can only see data they need to do their jobs.<\/span><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><span style=\"color: black\">\u00a0<\/span><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><span style=\"color: black\">Aside from some of the obvious security protocols \u2013 auditing and reviewing security procedures \u2013 a number of policies must be looked at (many of which are often overlooked) to ensure security and access of employees to systems. One strategy is to evaluate the amount of access of employees have and ensure there is no \u201ccreep.\u201d For example, review whether or not employees have access to solutions that they no longer need or have had since they started with the organization but have no business having now? Have employees left the organization but their former accounts and access rights have not been terminated? There\u2019s a strong possibility this may be the case, and can lead to severe problems.<\/span><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><span style=\"color: black\">\u00a0<\/span><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><span style=\"color: black\">Even at organizations where all systems and access to those systems is tracked, where all access is stripped out when the employee leaves, de-commissioning employee\u2019s access is often a manual process. Unless policies are enforced, nothing gets changed and access remains. Ask your system admins what approach they prefer? Manual process for managing the access rights or push-of-the-button automation that can be used to power regular audits of the information in question.<\/span><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">\u00a0<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><span style=\"color: black\">Organizational leaders should consider putting in place processes for information audits on a regular basis to ensure records and systems are free and clear of errant information and access rights. To ensure the greatest level of security and access rights, a member of the system admin team should be assigned to and regularly review Active Directory to eliminate or disable unnecessary accounts. This, of course, is an approach to take if the process remains manual. It can easily be automated, too.<\/span><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><span style=\"color: black\">\u00a0<\/span><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><span style=\"color: black\">Password managers and access management solutions are the simplest means available to mitigate this risk. Organizational leaders need to re-evaluate their security measures and consider if they truly are the best options available or if they are placing themselves in harm\u2019s way more than they are helping. If an organization is handling these things manually, they\u2019re likely to face a severe security risk in the near term, likely the result of an inside breach.<\/span><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><span style=\"color: black\">\u00a0<\/span><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><span style=\"color: black\">Other factors to consider include eliminating the need to write down access details, such as passwords. Even requiring frequent changes to passwords or mandating the use of complex passwords does not ensure security for the organization. The reasoning is simple: Th<\/span>ese passwords need to be changed on a regular basis. It is not feasible to think that employees are going to be able to remember several of these ever-changing complex passwords or their rules. This is where automated solutions play a valuable role improving security. Single sign-on, for example, gives the employee the ability to log in with a single set of credentials and thereafter be granted access to all the systems and applications in which they need to access. This single password can follow the organization\u2019s password conventions, but also means employees are less likely to write down credentials to remember them.<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><b>\u00a0<\/b><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">In regard to creep, organizations must monitor exactly who has access to what applications and systems. Employees join and leave the organization; employees lend their access information to each other on vacation, or borrow credentials, etc. This often leaves the team leaders with no clear idea of who has access to what and the types of changes they are making in their systems. Again, an automated user account management solution has the ability to allow system admins to see exactly who has access to what systems and applications\u00a0when those users are logging in and what types of changes they are making. Sure beats the manual approach.<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">\u00a0<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">These solutions also allow team leaders to easily make access changes if necessary and correct any issues before they lead to problems; this type of information is also extremely useful when it comes to audits.<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><b>\u00a0<\/b><\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">Another issue many organizations face is overlooking the disabling of accounts for employees who are no longer with the firm. This is an extremely common problem in regard to accounts for temporary or contract employees who only require access to systems for a short period of time. Since system admins have to manually disable an employee from all systems and applications, doing so can sometimes get overlooked or lost along the way.<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">\u00a0<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">This means that an employee who is no longer with the company can still access important information. Automated account management solutions allow for easy disabling of accounts with one click, which means a manager or team lead can easily make changes without having to contact a system admin. In addition, temporary employees\u2019 access can automatically be revoked after a specified period of time so that no manual action has to be taken at all.<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">\u00a0<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">Identity and access management solutions, such as the ones mentioned above, help ensure extra security of networks and can deter or prevent security breaches. They also help to create advanced levels of security while maintaining employee\u2019s ability to access information. Eliminating the chokehold some security protocols can have on an organization while protecting data and employees\u2019 access to it. Therefore, taking some time to evaluate current security measures can bring an organization\u2019s security protocols to the next level, but also keep working.<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\">\u00a0<\/span><\/div>\n<div><span style=\"font-family: Calibri, sans-serif;font-size: small\"><i>Dean Wiech is managing director of <\/i><a href=\"https:\/\/www.tools4ever.com\/\" target=\"_blank\"><i>Tools4ever<\/i><\/a><span style=\"color: #0563c1\"><i> US<\/i><\/span><i>, part of the global supplier of identity and access management solutions.<\/i><\/span><\/div>\n","protected":false},"excerpt":{"rendered":"<p>By Dean Wiech \u00a0 Is there anything more difficult to manage or overwhelming to overcome than organizational security issues? Perhaps only managing a company\u2019s most important resources, its people. Security breaches continue to shed light on just how easily hackers can access complex systems and steal important information from organizations and their customers. While this [&hellip;]<\/p>\n","protected":false},"author":24,"featured_media":592,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[112,189],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Improve Security and Avoid Breaches by Avoiding Access Creep<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jeff Edwards\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/\",\"name\":\"Improve Security and Avoid Breaches by Avoiding Access Creep\",\"isPartOf\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/07\/perimeter.jpg\",\"datePublished\":\"2015-11-09T20:00:12+00:00\",\"dateModified\":\"2015-11-09T19:26:18+00:00\",\"author\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\"},\"breadcrumb\":{\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/#primaryimage\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/07\/perimeter.jpg\",\"contentUrl\":\"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/07\/perimeter.jpg\",\"width\":600,\"height\":300,\"caption\":\"How to Deploy a Biometric Authentication Solution\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/solutionsreview.com\/identity-management\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Improve Security and Avoid Breaches by Avoiding Access Creep\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#website\",\"url\":\"https:\/\/solutionsreview.com\/identity-management\/\",\"name\":\"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services\",\"description\":\"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6\",\"name\":\"Jeff Edwards\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g\",\"caption\":\"Jeff Edwards\"},\"description\":\"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.\",\"sameAs\":[\"https:\/\/solutionsreview.com\",\"https:\/\/x.com\/InfoSec_Review\"],\"url\":\"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Improve Security and Avoid Breaches by Avoiding Access Creep","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/","twitter_misc":{"Written by":"Jeff Edwards","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/","url":"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/","name":"Improve Security and Avoid Breaches by Avoiding Access Creep","isPartOf":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#website"},"primaryImageOfPage":{"@id":"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/#primaryimage"},"image":{"@id":"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/#primaryimage"},"thumbnailUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/07\/perimeter.jpg","datePublished":"2015-11-09T20:00:12+00:00","dateModified":"2015-11-09T19:26:18+00:00","author":{"@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6"},"breadcrumb":{"@id":"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/#primaryimage","url":"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/07\/perimeter.jpg","contentUrl":"https:\/\/solutionsreview.com\/identity-management\/files\/2015\/07\/perimeter.jpg","width":600,"height":300,"caption":"How to Deploy a Biometric Authentication Solution"},{"@type":"BreadcrumbList","@id":"https:\/\/solutionsreview.com\/identity-management\/improve-security-and-avoid-breaches-by-avoiding-access-creep\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/solutionsreview.com\/identity-management\/"},{"@type":"ListItem","position":2,"name":"Improve Security and Avoid Breaches by Avoiding Access Creep"}]},{"@type":"WebSite","@id":"https:\/\/solutionsreview.com\/identity-management\/#website","url":"https:\/\/solutionsreview.com\/identity-management\/","name":"Best Identity Access Management (IAM) Software, Tools, Vendors, Solutions, &amp; Services","description":"Identity Access Management (IAM) News, Best Practices and Buyer&#039;s Guide","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/solutionsreview.com\/identity-management\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/3d31b4b6a777a91476a65c087be260e6","name":"Jeff Edwards","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/solutionsreview.com\/identity-management\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8471d2b63e0587b41d829ecc153ba8e7?s=96&d=mm&r=g","caption":"Jeff Edwards"},"description":"Jeff Edwards is an enterprise technology writer and analyst covering Identity Management, SIEM, Endpoint Protection, and Cybersecurity writ large. He holds a Bachelor of Arts Degree in Journalism from the University of Massachusetts Amherst, and previously worked as a reporter covering Boston City Hall.","sameAs":["https:\/\/solutionsreview.com","https:\/\/x.com\/InfoSec_Review"],"url":"https:\/\/solutionsreview.com\/identity-management\/author\/jedwards\/"}]}},"_links":{"self":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/786"}],"collection":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/users\/24"}],"replies":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/comments?post=786"}],"version-history":[{"count":0,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/posts\/786\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media\/592"}],"wp:attachment":[{"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/media?parent=786"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/categories?post=786"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/solutionsreview.com\/identity-management\/wp-json\/wp\/v2\/tags?post=786"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}