By Dirk Sweigart, CISSP, PMP, Cybersecurity Working Group Member
A key part of securing assets is establishing the identity of an individual who wishes to access that asset in some way. We need to be sure that the person who is making the request is who he or she claims to be. The asset can be a control system, a building, a VPN or an application, to name a few. Two-factor authentication is becoming relatively common as a method of confirming that identity.