Why Auditable Access Controls Matter

by Jeff Edwards Posted on August 29, 2019

By now, you should know that controlling access to sensitive files, devices, tools, and network areas is of utmost importance in cybersecurity, but you should also know that it’s not enough to simply control how users access resources. It’s equally important to be able to track and audit access, so that you can see who’s logged on, when and where they did it, and the resources that they’ve accessed. That’s where auditable access controls come in handy.

 

What Regulators Want, Regulators Get

This is especially important in highly regulated industries, such as healthcare or banking, where regulators will occasionally need to perform audits to prove that only authorized users accessed sensitive data, that they only did so when necessary, and that access and transfer of sensitive data was performed in a secure and compliant manner.

Principle Six of the GDPR, for example, states that data must be "processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures."

Those "appropriate technical or organizational measures" are important, and you can bet that access controls are one of them, but if those access controls don’t leave an auditable log, you’ll have a hard time proving compliance to regulators.

Lacking that degree of visibility and logging required for compliance certification can result in major consequences. The logs should be tamper-evident and keep track of when a file was transferred, if the right party received it, and whether or not it was subsequently deleted.

Proper Tools Equal Proper Outcomes

 That may seem scary, but the solution to these potential problems isn’t very difficult: simply ditch outdated and insecure file transfer methods. Standing up FTP servers may have worked in the past, but it’s simply insufficient in the age of the GDPR. With a proper managed file transfer solution, you can easily get complete visibility and control over file transfer activities between partners, customers, users and systems. Secure files at rest and in transit and assure compliance with internal policies and regulatory mandates.

MOVEit, for example, boasts advanced security features including FIPS 140-2 validated AES-256 cryptography, users authorization / authentication, delivery confirmation, non-repudiation, and hardened platform configurations. MOVEit Transfer logs activities in a tamper-evident database to comply with ISO 27001, HIPAA, PCI, GDPR, SOX, BASEL I/II/III, FIPS, FISMA, GLBA, FFEIC, ITAR and data privacy laws. It also integrates with your existing DLP and anti-virus systems, identity systems through SAML 2.0, AD, LDAP services, and SIEMs. Additionally MOVEit offers API interfaces (including REST) for integration with other third-party applications.


Jeff Edwards
Jeff Edwards is a tech writer and analyst with three years of experience covering Information Security and IT. Jeff has written on all things cybersecurity, from APTs to zero-days, and previously worked as a reporter covering Boston City Hall.
More from the author

Related Tags

Related Articles

Securing your Email with ProtonMail
Sometimes private or sensitive data is sent over email without much thought towards who may be able to access that data other than the intended recipient.
Secure FTP Helps Financial Giant Adhere to SOX
For IT managers in regulated industries, audits are a way of life. Proactive record keeping will be critical for when those pesky auditors walk through the front door. This is where a secure FTP (sFTP) tool can play a big role. In a post-Enron world, transparency is key...
APIs Provide the Data Access Windows for Improving Healthcare
APIs are becoming a huge part of how healthcare organizations provide better care to patients. But what about the security concerns with APIs?
Why Balancing Access Controls for Managed File Transfer Matters
If you're using secure file transfer tools, chances are you're security conscious. Maybe you're working in a highly-regulated industry, or perhaps you don't want your company on the front page of the newspaper for getting hacked. Whatever the case, if you're securing...
How to Choose the Right Managed File Transfer Solution
For the purposes of this post, we are concerned with two relevant options, namely File Transfer Protocol (FTP) and Managed File Transfer (MFT). The second, being managed, obviously offers more features than a standard file transfer solution. But, which solution is best...
Prefooter Dots
Subscribe Icon

Latest Stories in Your Inbox

Subscribe to get all the news, info and tutorials you need to build better business apps and sites

Loading animation