Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Role-based Access Control: Access, security, info tracking

by The Gurus
May 25, 2017
in This Week's Gurus
Share on FacebookShare on Twitter

Access to data is of the highest concern for leaders of the world’s most complex businesses. The amount of data stored on any network is typically immense. Relating this data to your user’s account information in Active Directory can be tricky and time consuming, yet there are security concerns that must be addressed. In this regard, proper data security includes three components: Ensuring new employee accounts are created properly when the employee is on boarded; ensuring those access rights remain accurate for each of the organization’s employee’s tenure; revoking access rights when an employee leaves the organization. The third step listed here is the most important of the three.
These security phases identified, a more in-depth look at solutions for all three of these phases of data security is required.
Access governance and the role of role-based access control
A profoundly effective solution to mitigate these security risks is role-based access control, which, in the real world starts with the creation of a matrix. Unlike the complexities of a dark computer otherworld ravage by a seeker named Neo, the kind of matrix referred to here is the development of a diagram that characterizes the rights of each employee with respect to every object or access they need in the system. Butler W. Lampson first introduced it in 1971. Lampson is an American computer scientist contributing to the development and implementation of distributed, personal computing, and a technical fellow at Microsoft and an adjunct professor at MIT
A role-based access control matrix along, with an identity management solution, allows you to account for the creation of new employees’ accounts and credentials generated with proper access rights. Thus, as first designated by Lampson (though it has evolved immensely) the first step of this matrix stage is to define the roles that each employee should have in every part of the organization. You can identify these roles using a combination of department, location and job title, for example. The end result of a somewhat tedious matrix-building process allows you to create a template for new employees and as an audit point of reference for use in the future.
Access rights of employees usually creeps into multiple areas over the course of an employees’ tenure. The longer an employee works with you, the more likely they are to gain access to systems they don’t necessarily need to perform their primary job. For example, rights might be assigned to one employee for special projects while one employee is covering for another on leave or when an employee changes departments and responsibilities. However, revocation of this access is infrequent at best. Automated solutions can analyze the rights of all employees at any given time and provide lists of actionable information.
RBAC and information audits
Performing information audits can be a challenge, no doubt, but you better get used to them. They are here to stay, and necessary. Once an audit of access rights is performed, it can be compared against the baseline template for each employee role initially established. Any issues can be verified or revoking of the rights can be administered automatically. That said, termination of rights must be done immediately when an employee leaves.
Here’s a real world example of a situation that might strike at the heart of current reality. In experience personally related to me by the manager of an organization I work with, a sales manager for a major corporation had terminated one of this sales reps. The organization did not have a process in place to disable access in a timely manner to a cloud-based business intelligence application used by the sales rep. At some point, the terminated employee realized the account was still “live” and he proceeded to download more than 10,000 records over the course of a month, which cost to the company more than $6,000 before they turned off the former employee’s access.
Perhaps that’s a small drop in the bucket, but imagine if these costs ballooned to 10, 20 or 30 times more. It happens, and like it or not, the majority of breaches are inside jobs. The organization simply left the side door wide open, no key required. When putting a process in place to handle terminated employees, link to your HR system. When an employee is terminated, a synchronization process can take place to decommission accounts in all internal and external systems. Ensure that proper access to data, groups and applications are right for each employee. Revoke accounts when an employee leaves. Failure to do so can be costly.
By Dean Wiech, Managing Director at Tools4ever US.

Tags: access controlCyberdatainfo trackingsecurity
ShareTweet
Previous Post

CIOs increasingly focus on innovation

Next Post

European businesses not seeking help from the security industry to comply with GDPR regulations

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol