Absolute security and confidentiality for HR services

10 March 2010
HR resource services companies offer a complete range of services and products relating to the employment of personnel. With payroll data increasingly being transferred over publicly accessible network as the Internet, many HR services companies are aware of the need for absolute security and confidentiality. Many organizations need to secure the exchange of confidential information over the Internet, so that their clients could use their payroll software packages without worrying about Internet crime

Typically, clients’ HR-staff provides HR resource services companies with necessary and confidential data, so they can do the payroll processing for them. But, because the software packages can be used over the Internet, HR services companies need to guarantee an absolutely secure and confidential way of exchanging this information. Besides that, they also need to ‘know' who sends them this information, in order to allow them to check whether this person is authorized to do so.

Obviously, it is essential that HR services companies find the ideal way to the secure the exchange of this data. The data which HR companies receive from their clients is very confidential and that is why they are also attractive for fraudsters. Strong authentication is the right security path for HR services companies to follow.

With strong authentication, the user has to authenticate themselves through two independent factors:
* Something you know (a password)
* Something you have (a physical device).

This contrasts with traditional password authentication, where the user only needs a static password to identify him self. In many cases, HR resource services companies have decided to work with VASCO’s DIGIPASS strong authentication and VACMAN Controller.

How does it work?

In theory, a Human Resource Services company assigns a DIGIPASS to everybody who is authorized to use or enter data into the software packages. To login to such a package, the user needs an Internet connection, a username, a PIN code and DIGIPASS. After entering the PIN code (first factor) on the keypad of DIGIPASS (second factor), the device/software generates a unique password. This password needs to be entered into an applet, together with the username, in order to get access to the payroll software.

With a unique password that is generated every 36 seconds, DIGIPASS puts fraudsters out of action. Even if fraudsters can retrieve the password someone used to login, the criminals won’t be able to re-use it, as DIGIPASS produces a new password for every login.

Two important factors why Human Resource Services companies opt for VASCO are VASCO’s proven track record in the financial world and the ease of use of DIGIPASS. A lot of banks used this security solution, HR resource services companies are reassured of the added value and security of DIGIPASS strong authentication. The easy use of DIGIPASS stimulates its adoption. No technical skills are required to use DIGIPASS. Therefore it is easy to distribute it to all kinds of users.

DIGIPASS secures multiple applications

HR Services companies can also use DIGIPASS not only to secure the input of data by clients, but also for a number of other critical applications. Internally, DIGIPASS can be used for remote access and to connect securely to the corporate network through a VPN connection. DIGIPASS can also be used to give employees secure access to their web mail.

Additionally, in keeping with Access to Work requirements and corporate social responsibilities, companies have to offer blind and visually impaired people the same job opportunities as everyone else. For these employees, companies can opt for VASCO’s DIGIPASS 300 Comfort Voice. This way, they can securely access the same applications as other employees can. To assist visually impaired people, DIGIPASS 300 Comfort Voice has extra large buttons and every key press is followed by an acoustic feedback. The calculated unique password is being read by DIGIPASS to the user through a built-in speaker or via a headset. That way the user can insert the password as he or she hears it.

While the secure exchange of confidential data remains a critical concern for HR resource services companies, they can now be assured that with DIGIPASS from VASCO, their clients’ confidential data will remain safe.

Vasco is exhibiting at Infosecurity Europe 2010, on 27th – 29th April in Earl’s Court, London, www.infosec.co.uk.


print versionPrint version | email this to a friendEmail to a friend | view other articles View other articles

Latest IT, computer and network security articles

 Google delivers twice the amount of malware than Twitter, Yahoo and Bing combined

 Rapport's financial malware disinfection removes malicious code that attempts to attack browser sessions

 Juniper Networks acquires SMobile to deliver a secure mobile Internet experience on any mobile smart device

 Bradford Networks' Adaptive Network Security platform secures wireless access throughout University of Westminster campus

 Active Dashboards software gives VSG a complete picture of key operational activities

 Cloudmark's Cloudfilter protects Digiweb's customers from spam

 Imperva partners with NEON to provide database activity monitoring for mainframe users

 Lanner releases FW-7535 network application platform for secure network communication applications

 Secure data management is the healthcare industry's most pressing issue

 Imperva's Hacker Intelligence Initiative provides deeper insight on how cybercriminals conduct large scale cyber attacks

...[view more IT, computer and network security articles]...

 

Security websites for specific products:

Security websites for specific markets:

IT Security links


directory of IT, computer and network security suppliers
Search directory Register your company
IT, computer and network security books:

SEARCH NEWS
DIRECTORY
Google