Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - A World Without Access Management
Articles

A World Without Access Management

ISBuzz TeamBy ISBuzz TeamJuly 23, 2015Updated:July 23, 20155 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
World without access management
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

What would happen if access management disappeared overnight and we had to cope the next day without it? What impact would this have on an organization and its information systems? Let’s have a quick look at this scenario.

In its purest form, access management is about access. This could be both physical access (entry into premises or a specific area in a building) and logical access (access to systems, applications, printers, shares etc.). Access management is often named in combination with identity management, and these two concepts are closely interrelated.

Authentication

In identity management, the user proves that he is who he says he is. This is also called authentication. The most common means of authentication is to enter a username and password combination. Another type of authentication is the combination of “remembering something” with holding something physical, such as a user pass, mobile phone, token, fingerprint, etc. This is a strong type of authentication.

Authorization

Authorization plays a role alongside authentication. Authorization determines the content to which a user has access in the network. This content might be systems, applications, printers, shares, etc. Where authentication is still reasonably simple, authorization can often be a complicated business. Because depending on the user’s identity (function, role and location in an organization), the access rights – and thus also the content – should vary in the network. We call the relationship between the individual (the user) and the content, access management. This is because authentication determines the authorizations. Only this way can it be guaranteed that users don’t hold too many rights, and that they don’t get to information which is not intended to be visible to them.

Information security

It is directly apparent from this that a risk would arise if access management disappeared. This would mean that every user could access any content, which is highly undesirable from an information security aspect. For example, a hospital needs to be able to guarantee that patient details can only be accessed and changed by the relevant care providers. And in the financial world, having amounts known to all or letting everyone perform a transaction must be prevented. In the corporate market it’s not necessary for all users to be able to access everyone else’s HR details, and if this were allowed it would almost certainly breach data protection laws in many countries. If access management did not exist, none of the above could be guaranteed. Without access management there would also no longer be any control or oversight over just what access rights an employee holds, and whether these are actually appropriate for what was originally specified.

Physical access

As already mentioned, access management also covers physical access. If access management disappeared, there would also no longer be any control over physical access. For instance, everyone in an organization would have access to the server room, and all care providers would have access to all the areas in a hospital, even an operating theatre or the pharmacy. Naturally, this is an unreasonable situation.

Legislation and regulations

Access to the company network normally begins with entering a username and password, or scanning a user pass. If there were no longer any access management and it was no longer necessary to log-in with a personal network account, access to the company network could only be achieved with a generic account. That means one username and password used by all employees. To save valuable time this is how it sometimes worked in hospital outpatient departments in the recent past, but most hospitals want to move away from this system. Because with this method, exactly who performed what action in a patient file is not visible and cannot be discovered, contrary to a requirement laid down by legislation and regulations. But other sectors too must comply with legislation and regulations – think, for example, of Sarbanes-Oxley for the financial sector.

Licensing costs

If end-users had uncontrolled access to all resources, that would mean they also had access to all the applications used in an organization. This would put significant pressure on licensing costs. Licensing fees are made up of the relatively lower charges for bulk software, and the higher charges for software which is only used by a smaller group of employees in the organization, for example Microsoft Visio and Adobe. If all end-users in an organisation could use all applications without the approval of a (licensing) manager, the costs for unnecessary licences would quickly escalate. Just try doing a quick calculation for your organisation.

Commercial interests

There are commercial organizations that have a great deal of interest in authenticating users, for example publishers or a company like LinkedIn. These organizations may offer some of their content free of charge, but for a far larger part of their content the user must be able to authenticate themselves and pay. If there was no access management, there would no longer be any ability to draw a distinction between free and paid content.

These are a few examples of the issues which might arise in a world without access management. And, of course, any number of other scenarios could be devised. A world without access management would certainly be a world with a lot of concerns.[su_box title=”About Robert Doswell” style=”noise” box_color=”#336588″]Robert-DoswellRobert has been working with Tools4ever solutions for over 10 years, founding Tools4ever Limited in 2002. Since then, Robert has grown the UK and Irish markets significantly year on year. In addition to conducting direct sales, he is responsible for the telesales team, field sales representatives, and professional services team.Robert has been involved in Business to Business sales since completing his education at the University of Wales. Specializing on Windows administration solutions for medium to large networks since 1996 allows Robert a deep understanding of our client requirements and configuring solution for a perfect match.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}