skip navigation










SSO and Strong Authentication: How OhioHealth Built a Paperless Hospital
In this case study presentation, Joe Greene, IT Security Director at OhioHealth, explains how he and his team approached employee access challenges when they laid the IT foundation at Dublin Methodist, a brand new paperless hospital. More than a year after the doors opened at Dublin, their project is a proven success and there are many best practices and lessons learned to be shared with viewers.  Download the webinar today!

Identity 360 - An Imprivata Blog

What NIST Missed: The value of password management + SSO + strong authentication

May 20, 2009 at 8:25 AM by David Ting

The National Institute of Standards and Technology (NIST) recently put out a draft “Guide to Enterprise Password Management” for public comment for feedback and improvement. While it gives a lesson in password management history, it doesn’t quite break new grounds on prescriptive opinion.

Dave Kearns provided useful analysis of the NIST paper in his recent Managing Passwords article on Network World, and a couple of nuggets of wisdom jumped out at me:

The only way to improve usability and security of password management today is to combine it with single sign-on and multi-factor authentication, as Dave stated in his piece. Dave’s article made me think a bit more about the NIST paper and the intersection of SSO and strong authentication, and here are some of my observations:

So the value of password management + SSO + strong authentication is increasing in acknowledgment. Among our customer base at Imprivata 75-80 percent of customers are using one or more form of strong authentication with SSO. We rarely encounter a new deal that does not include strong authentication, and many of our customers prefer to deploy a variety of modalities (finger biometrics, tokens, proximity cards) that they can tie to the security level of the data being accessed by a given user. In fact, now strong authentication is often the driver of a deal, and SSO is pulled through.

We’ve run a few surveys lately, one squarely on this topic of strong authentication and SSO that you may find worth checking out: /content27465
--Dave

Tagsuser_authentication strong_authentication Single_Sign-On

FACEBOOK

Comments


  


< back