You are here: silicon.com > Public Sector > News

Stopping corporate IT break-ins

How to lock the door behind ex-staff

Tags: tif

By Nick Heath

Published: 20 January 2009 16:53 GMT

Shutting the door to IT systems after staff leave the business and allowing workers to safely log in from home can be a major headache for business.

In an identity management guide published today, the Corporate IT Forum (TiF) recommends using automation to smooth over some of the difficulties in keeping track of who is accessing what.

According to the guide, companies should approach identity management by asking the following questions for each member of staff - "Who are you?", "What is your business here?" and then "What IT elements and data do you need?".

Security from A to Z

Click on the links below to find out more...

A is for Antivirus
B is for Botnets
C is for CMA
D is for DDoS
E is for Extradition
F is for Federated identity
G is for Google
H is for Hackers
I is for IM
J is for Jaschan (Sven)
K is for Kids
L is for Love Bug
M is for Microsoft
N is for Neologisms
O is for Orange
P is for Passwords
Q is for Questions
R is for Rootkits
S is for Spyware
T is for Two-factor authentication
U is for USB sticks/devices
V is for Virus variants
W is for Wi-fi
X is for OS X
Y is for You
Z is for Zero-day

That information should be put into a Lightweight Directory Access Protocol, which sets and controls staff access to applications and services, and then governed by a set of variables: have staff got permission to create/modify/delete a data set, for example, and when do those access rights need to be withdrawn?

As well as helping out administrators, the system will allow staff to log in just once to use all the systems they have access to.

However, some business decisions should still be made by management and not the automated system, such as whether to grant access to business critical data to a temporary employee, the guide advises.

The report says this approach will save a business money and time, reduce the risk of human error, ease staff access to company systems and provide a clear audit trail.

Head of research at TiF Ollie Ross said: "Proper identity management and role-based access gives a better handle on who in the business is accessing what, from what and for what purposes - from the desktop through to handhelds."

International information management group Reed Elsevier helped produce the report and is itself wrestling with how to simplify controlling systems access among its 8,000 IT users.

Ruth Harris, head of project management office Europe for Reed Elsevier Technology Services, described the challenges controlling staff access poses for the company.

She said: "We have users all over the world using a number of different applications with different IDs and passwords.

"When those staff leave, you have to go through each application they have access to, both centrally and locally, and then disable that access.

"We are looking into how to make this process simpler by having a system that allows you to only have to tap in once that this person is leaving and it will disable their access to all applications."

To find out more about the TiF guide, visit TiF's website www.tif.co.uk.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

silicon.com Public Sector
Get the latest public sector news straight to your inbox. Sign up for the PS newsletter today!


  • Jobs
IT Security Architect - SC Cleared

Network and Identity Management Security experience including; Anti-Virus, IDS/IPS, 2 Factor Authentication, PKI, Identity Management, Risk ...

Senior Technical Consultant

Knowledge of Windows/Unix environments Identity Management Active Directory configuration and design Messaging solutions, Exchange 2003/2007/2010 ...

Helpdesk Administrator - Surrey/West Sussex borders.

Log support calls and co-ordinate with third-parties to resolve support issues. Skills required: An IT related qualification or be qualified by ...

Nick Heath
Let's shine a light into the public sector IT money pit
With £16bn being spent, why is productivity still falling?

Tim Ferguson
BBC is taking tech seriously, so give it a break!
Auntie is the envy of the world but doesn't get the credit it deserves at home...

Peter Cochrane
Peter Cochrane's Blog: Open info for all?
Government stonewalling citizens

Nick Heath
Home Office CIO on taming tech and why ID cards are good news
Interview: Annette Vernon, Home Office CIO

Nick Heath
NHS records, Google and Microsoft: Where do you want your data?
Politicians: Heal thyself

Alan Hunt
NHS network: Time to get secure
Patient data in need of a check up

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.




Quick Sitemap Links: