LAN security projects can be overwhelming. They can span multiple groups within an I.T. organization, including the teams responsible for desktops, servers, networks and security, as well as directories and applications. Business units outside I.T. also must be involved to determine the appropriate policies for who should be able to access which resources on the LAN.
Over the past four years, I’ve worked on such projects with hundreds of enterprises around the world. While they fall into a wide variety of vertical markets, and range in size from 500 to nearly 100,000 employees, they have several issues in common:
Dealing with the “insider threat” — For example, many enterprises depend on contractors. These folks must have access to the enterprise network, or they can’t perform the job functions they are hired to do. They need to run certain software, access certain files and reach specific servers, but they don’t need, and they shouldn’t be given, access to all networked resources.
Achieving regulatory compliance — Various government and industry regulations require documentation that companies have access control policies in place, that they’re applied universally, and that the controls are automatic (rather than manual). Automatic controls simplify the audit process because they only have to be tested one or two times, compared to manual processes, which have to be tested as many as 15 times.
Limiting user access to sensitive information — Companies increasingly want to identify users based on their various “roles” in the organization, and then assign appropriate access rights to those roles. For example, they want only finance department users to see financial records, or only customer service reps to be able to look up private customer data.
While everyone’s situation is unique, at least to some extent, these issues have been challenging enterprises for years. I hope that the following…