Article content
In briefShow moreShow lessThe article describes the shift from traditional network perimeters to a focus on secure services, identities, access controls, and endpoints.
- The article describes the shift from traditional network perimeters to a focus on secure services, identities, access controls, and endpoints.
- Secure identities are the foundation of IT security, because misuse of user accounts can harm systems, customer relationships, finances, and reputation.
- ProsessPilotene automates hiring processes to reduce the workload and errors for HR and IT, while giving new employees a modern and professional experience.
- BankID is used in the processes to verify the identity of new employees and sign employment contracts.
- Permissions should be assigned through role-based groups, with regular membership reviews to improve oversight and reduce the risk of misuse.
By holding on to traditional IT and security models, you risk becoming outdated or compromised. So how can you implement modern IT systems that meet today’s requirements while protecting them effectively?
Shift the focus to secure services, identities, access controls, and endpoints
Traditionally, organizations tended to focus on protecting their offices from the dangers of the internet, much like old-fashioned fortresses with high walls and a moat. This worked at a time when all IT systems and endpoints were permanently located within the office walls. But now that most people need to be able to work from anywhere and access many different cloud services, this approach is no longer effective or appropriate.
By focusing on protecting services, identities, access controls, and endpoints, you can achieve a modern and secure IT environment that meets your needs. What does this mean in practice? This article is intended to provide inspiration and serve as a starting point for improving your IT systems and processes, as well as the security surrounding them.
Secure identities
When we talk about identities here, we are mainly referring to personal user accounts, such as accounts used to log in to PCs, email accounts, or other IT systems.
We begin by looking at identities, as they underpin the security of most of your IT systems. If you cannot trust who is using the different identities, you lose control over who has access to what and who has done what. In the worst case, an attacker could gain access to and misuse one of your employees' user accounts to harm your internal systems, customer relationships, finances, or reputation, without you knowing who was actually behind it. And if your identities have too many privileges, a hacker can cause more damage than if all identities only had the privileges they need to do what they are supposed to do.
Collaboration between HR and IT
Identities often have a lifecycle that begins when someone is about to be hired and ends when their employment comes to an end. A well-managed identity lifecycle actually begins before an employee starts work, through effective hiring and onboarding processes that ensure the person you are hiring is who you believe them to be. These processes also often shape some of a potential new hire’s first impressions of your organization, so there are many benefits to ensuring that they are well designed and effective.
Streamlining processes
At ProsessPilotene, we have experience in automating recruitment processes, giving prospective employees the impression that the organization is modern and professional, while significantly reducing the workload and risk of human error in the HR and IT departments. We also use BankID in these processes to verify the new employee's identity and sign employment contracts. We also streamline the selection and setup of PCs and mobile phones.
Further along in the lifecycle, an identity will typically need permissions to perform one or more tasks, ranging from logging on to a PC and working in a CRM system to sending an email. These permissions should primarily be assigned through group memberships rather than directly to each individual user. Why, you might ask? An identity's tasks are often modified or expanded throughout its lifecycle, and a common issue is that identities accumulate new permissions without the old ones being removed. This often leaves identities with excessive permissions, which in turn increases the risk of harm caused by human error or misuse.
Create groups with permissions
If you instead create groups for different job roles, such as “Salespeople,” “Customer Service Representatives,” and “Developers,” and grant the necessary permissions to these groups, you will have better visibility and control. Identities can then be assigned membership in a few groups based on their job roles, making it much easier to keep track of what each person has access to and to remove access they no longer need.
Establish procedures for reviewing the groups
These groups can be kept up to date by setting up automated, regular membership reviews. During these reviews, for example, the head of the sales department may be asked to review the “Salespeople” group and determine whether all current members still need to be members. These are the identities that hackers often try to gain access to, so it is important to protect them!
ProsessPilotene takes security seriously, both in its own operations and in the projects we deliver to our customers.
IT and Security Manager at ProsessPilotene, Bjørn V. Karlsen.
