www.howbankswork.com  

History of IT Security During 2005 - Today

By Robert Tripp, July 2006

 


This brings us up to date and is illustrated in the diagram below.

In essence, most banks have bits of security processing from every generation of technology development. This means we are running a complicated mess with a desire to move more of the access control to Centralised Web Security technology as the applications move to become more web based. There is a recognition however that the non web based, mainly staff driven, ways will continue for a long time (many years, probably decades) before they get replaced with web based screens.

Even within the Centralised Web Security world there is a desire to improve things. This is because there is a design tension between whether to put detailed security controls in a central place (e.g. Centralised Web Security or RACF) or put them in specific applications. Central control runs the risk of admin overhead for all users increasing. Application specific control gives a different set of admin and flexibility issues (e.g. it is easier to introduce a new authentication technology such as smart cards or biometrics once centrally rather than in lots of different places).

There is also no economic justification for the enormous software development costs associated with ripping out the security processing from applications and centralising it in RACF or Centralised Web Security.

Back to Top

IT Security in:

Related Reports

This report should be read in conjunction with the following reports:

Likely Changes to IT Security in the next 2 years


Comments

If you would like to comment on any of the issues raised in this report or you would like to add your own views on this topic for others to see or you feel you could contribute an interesting report to Howbankswork.com then please contact us.


Further Information

If you would like a paper copy of this report please contact us including your full name and address in the email.


Copyright

The arguments and ideas in this report can be freely used as long as original authorship is acknowledged.