About
Subscribe
  • Home
  • /
  • Security
  • /
  • RSA access control, risk-based authentication integration enables cost-effective protection for Web portals

RSA access control, risk-based authentication integration enables cost-effective protection for Web portals

Johannesburg, 01 Dec 2006

SecureData, a member of the JSE-listed ERP.com Group and the distributor for RSA Security products in Sub-Saharan Africa, today announced the latter's integration of RSA Access Manager software and RSA Adaptive Authentication is enabling two leading financial institutions to help cost-effectively protect end-users and assets within consumer-facing Web portals.

RSA Access Manager software is designed to enable each financial institution to leverage policy-driven access controls to provide users with single sign on across authorised services offered within the portal.

In addition, the risk-based authentication module of RSA Adaptive Authentication is engineered to help customers cost-effectively assure the identities of portal users, and assess risk during their session.

This success builds on RSA's long history of enabling organisations to marry stronger forms of user authentication with robust access control. In recent years, companies, particularly those in the healthcare industry -- including Blue Cross and Blue Shield of Kansas City and Geisinger Health System -- have employed RSA SecurID one-time password technology to verify identities on the front end of a Web portal, while RSA Access Manager technology delivers fine-grained access control inside the application. RSA's risk-based authentication technology, which is designed to provide optimal balance between security and usability, provides an additional strong authentication option for further securing access control policies.

Risk-based authentication meets the growing need of organisations to protect Web portals with access control, and leverage an authentication mechanism that best suits the needs of the organisation and its customers.

"As Web portals containing protected data are rolled out to large user populations, authenticating users and controlling access becomes a core business requirement," commented Ray Wagner, managing vice-president at Gartner, Inc. "These types of deployments often have a spectrum of authentication requirements for different populations and applications. Deployers are thus interested in integrated solutions that can offer the type of authentication that makes sense in each case."

Customer use scenario

For end-users, the integrated RSA Access Manager and RSA Adaptive Authentication solution is engineered to provide a seamless experience, while also delivering much higher degrees of security:

* For consumers accessing the organisation's portal, RSA Adaptive Authentication leverages a range of parameters behind the scenes - including device and network forensics, behavioural analysis and the end-user's computer itself as a second authentication factor - to ascertain positive identification.
* Still behind the scenes, RSA Adaptive Authentication quickly and transparently scores transactions according to the perceived level of risk and automatically invokes additional security measures if needed, all with minimal impact to the customer.
* Once the identity of the user is verified, access to the Web portal is granted. Here, inside the portal, RSA Access Manager enables customers to ensure that users are only able to access their information, and only able to execute authorised transactions based on their permissions and profile in the system.

"As companies roll-out new and improved Web portals, which often serve very large user populations, effective access control and user authentication becomes a key concern," added Jim Melvin, vice-president of marketing at RSA. "By deploying RSA Access Manager with RSA Adaptive Authentication, we're empowering organisations to implement the authentication that best meets their needs, from both a cost and usability standpoint. It's encouraging to see that this combination makes sense to the market as well, with growing demand and two customers deploying it already."

For further information, please contact Andrew Ochse at telephone +27 11 790 2500; fax +27 11 790 2599; e-mail andrewo@securedata.co.za.

Share

RSA Security

RSA, the Security Division of EMC, is the expert in information-centric security, enabling the protection of information throughout its lifecycle. RSA enables customers to cost-effectively secure critical information assets and online identities wherever they live and at every step of the way, and manage security information and events to ease the burden of compliance.

RSA offers industry-leading solutions in identity assurance and access management, encryption, security information management and anti-fraud protection, bringing trust to millions of user identities, the transactions that they perform, and the data that is generated.

SecureData

SecureData, an ERP.com company, is Africa's premier value-added distributor & solution provider of perimeter, network and endpoint information security and risk management solutions. As well as being the sole distributor in Sub-Saharan Africa for Trend Micro, SecureData is the Sub-Saharan African distributor for AirDefense, Application Security, Check Point Software Technologies, Cibecs, eEye, Network Engines, Precise Biometrics, Rocket Software, RSA Security, SafeBoot, St Bernard Software, TippingPoint Technologies and Websense. For more information, visit SecureData at www.securedata.co.za.

ERP.com

ERP.com is a JSE-listed company focused on the implementation, integration and management of enterprise applications in an e-business environment. For more information, visit ERP.com at www.erpcom.co.za.

Editorial contacts

Paul Booth
Global Research Partners
(082) 568 1179
pabooth@mweb.co.za