On September 12, System and Security Manager Lars Thore Hertzenberg presented this case at the Buypass user forum. The background for the project is that a self-assessment revealed areas for improvement in the storage of sensitive personal information.
The technology is based on solutions from the Norwegian company Buypass, allowing the IT department in the county municipality to issue and distribute security cards to employees. The smart cards come with a chip and function as access control, along with a PIN code. When the dentists insert the smart card into the PC/terminal, their private user session is available within seconds and automatically closes when they take the card and leave the screen. The smart card has a level 4 certificate.
– The smart card will replace both door keys, passwords, and usernames to access the IT systems. This is for 300 users at 22 dental clinics in the county, says Hertzenberg, noting that employees will save several minutes each time they log into the systems.
The following goals for the work were defined:
Modernize application delivery, making it simpler and more secure for users and the IT section
Upgrade existing infrastructure to the latest versions
Adapt the solution to offer access to a secure zone from the internet
Adapt the solution with a view to expansion to Viken (merger)
Expand the solution to offer access to a secure zone beyond the dental health service, such as the education section for storing sensitive information about students
The professional application is delivered through Citrix Virtual Apps and Desktop. Several actors have contributed to building the solution. At Sicra, we were particularly pleased to be mentioned as one of the “success drivers.” Our contribution has been to assist with specialist expertise around certificate management and the interaction between the various components of the solution. Kai Thorsrud has been our consultant in the work.
We have managed to combine user-friendliness and security, which is a rare achievement. We have eliminated unlocked workstations. Through good user training, users are left with enhanced competence related to ID and risk thinking.