Home > Financial Services Information Security Tips > Security Architecture Insider > Global authentication policies made easy
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY ARCHITECTURE INSIDER

Global authentication policies made easy


Joel Dubin, Contributor
05.07.2008
Rating: --- (out of 5)


Security technology news and tips for financial services pros
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Setting up a global authentication policy isn't as challenging as it sounds. User IDs and passwords may come from different languages, but, in the end, they're still different flavors of the same authentication credentials.

The problem with unifying authentication policies around the globe is more of an infrastructure and architecture issue than one of authentication systems. Enterprise authentication systems, by and large, are pretty much the same everywhere, and can scale up to hundreds of thousands of users. In addition, many have support for internationalization and can handle everything from Roman characters for English and European languages to Middle Eastern languages like Hebrew and Arabic -- which are read from right to left -- to Asian languages made up of thousands of characters. Unicode, a universal coding system to uniquely represent any letter or character in any language, makes it possible.

Unicode is an industry standard accepted by the major manufacturers of IT products, such as Microsoft, Sun, Apple, Hewlett Packard and Oracle, and is a part of most key programming languages underpinning authentication systems, such as Java and .NET. The two main authentication directory services -- Active Directory (AD) and lightweight directory access protocol (LDAP) -- both work with Unicode.

Authentication systems using Unicode can adapt login screens and management consoles immediately to the locale of the user. The logon screen will translate and display perfectly with all letters, characters and other diacritical marks in the local language.

The prob


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Security Architecture Insider
Winning the war: Personal information protection
Why financials must implement Web application security best practices
Identity management for financial firms in turbulent times
Identity management for financial firms in turbulent times
How to use data loss prevention tools to stop data exfiltration
Security questions to ask SaaS vendors when outsourcing services
Book chapter: Remote deposit capture risks
How to communicate the value of security controls for online transactions
How to perform a network device audit
Emerging themes in identity access management

Authentication methods for financial services
BITS releases guide for implementing email authentication protocols
Banks, e-commerce sites use device identification to stop fraud
Evolving authentication methods in the financial industry
Identity management for financial firms in turbulent times
Biometrics project studies ways to combat bank fraud
Consumer authentication in the financial industry
Emerging themes in identity access management
Security on the street with SearchFinancialSecurity.com: Mobile banking
Privileged password management steps to success
The evolving value proposition and impact of identity management

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
mutual authentication  (SearchFinancialSecurity.com)
Real ID  (SearchFinancialSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


lem is knitting together different authentication systems -- sometimes at different levels of technology -- on different platforms.

Here are some best practices to integrate authentication policies around the globe:

Where things gets sticky is in secondary authentication systems used to beef up user IDs and passwords. An example is security questions used to reset passwords. The classic mother's maiden name question doesn't work in Latin America or the Middle East, where many people have two or more last names. The question about the user's high school can be confusing in China and Europe, where the secondary school system is different than its U.S. counterpart. And questions about pet names mystify people in countries where animals are only used for farming and aren't allowed in the house.

If adopting a global set of security questions is a problem, either don't use them, or let each country or region choose its own. This issue aside, with built in internationalization support in existing directory services, your global authentication policy enforcement can parallel your domestic policy.

About the author:
Joel Dubin, CISSP, is an independent computer security consultant and speaks six languages, including two with non-Western alphabets (Hebrew and Arabic). He is a Microsoft MVP, specializing in Web and application security, and is the author of The Little Black Book of Computer Security, available from Amazon.com. He has a regular radio show on computer security on WIIT in Chicago and runs The IT Security Guy blog at www.theitsecurityguy.com.


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts