CIS502 discussion post responses.
Respond to the colleagues posts regarding:
Authentication Factors
The three primary factors of authentication are something you know, something you have, and something you are. Multifactor authentication uses more than one authentication factor and is stronger than using a single authentication factor. You are the security professional assigned to design the authentication process for your company. The goal is to secure very sensitive customer data. Thinking about what you know about factors of authentication, provide an example of the process you would implement for users to authenticate to the companys intranet. How might employee access differ from customer access? Be sure to fully explain your reasoning.
DPs post states the following:Top of Form
I would start the authentication process by asking questions for security parameters.
· Who are you?
· What is your title?
· Where are you located (GPS)?
Who you are is your user email and last name with the last for of your SSN.
What your title is, is your employee ID number and password.
Where you are located is tagged by the application you are logging into, to see if you have permissions to access company software off site.
A good reason for the location based services to be incorporated is to follow the rules of least privilege. You wouldn’t need an hourly based sales employee to access company software other that their schedule while they are off work. However, you may need a Salary based manager to access their employees time and attendance to approve payroll.
TSs post states the following:Top of Form
The three primary factors of authentication are something you know, something you have, and something you are. Multifactor authentication uses more than one authentication factor and is stronger than using a single authentication factor. You are the security professional assigned to design the authentication process for your company. The goal is to secure very sensitive customer data. Thinking about what you know about factors of authentication, provide an example of the process you would implement for users to authenticate to the companys intranet. How might employee access differ from customer access? Be sure to fully explain your reasoning. There are two discussions here that need to be responded to thoroughly. Responses must be on APA format 150+words 1-2 legitimate verifiable sources per response.








Recent Comments