July 02, 2004

Best practices for unified security

When considering deployment of a converged physical and IT security system, enterprises should consider advice from industry experts

*Have a clear, strategic plan — including goals and expectations for deployment — developed with broad participation from multiple constituencies.

*Develop a clear set of corporate policies — monitoring, privacy, response, archiving, and so on — to guide your deployment.

*Have an enterprisewide process in place, not just the technology, to handle identity and credential management.

*Clearly define the process for how the IT security and physical security teams will work together on incident response.

*Make conscious trade-offs between user convenience and authentication strength, matching the level of security with the level of risk. Use multifactor authentication where possible.

*Use your chosen authentication methods, such as smart cards, across as many applications as possible to get the maximum cost leverage.

*Centralize credential management and identity provisioning. Link the identity management system to your HR systems.

*Make sure all new physical security infrastructure complies with standards and IP protocols.

*Build a long-term business case for deployment, and structure long-term vendor contracts, including maintenance and upgrades.

David L. Margulius runs The Collectors Weekly Web site.

Subscribe to the Security Central Newsletter

The one-stop resource center for IT professionals.

White Paper

CA Security Management Solutions

A comprehensive security management solution can help you streamline, as well as grow, your current or evolving business. In this way, a strategic security approach can help you increase your competitiveness in these challenging market conditions.

Download now! »

White paper

Beyond Compliance: The Significant Benefits of Log Management

Find out how you can effectively collect, normalize and archive enterprise-wide, security-related data that is invaluable for security investigation and compliance reporting.

Download now! »

Webcast

Integrated Identity Compliance: Enabling Cost-Effective Role-Based Compliance

This session focuses on the intersection of role management and identity compliance, and addresses the importance of identity compliance in enterprise governance and the challenges that organizations may face in achieving it.

View now! »
©1994-2009 Infoworld, Inc.