Quiz Entry - updated: 2026.09.28
In the case of the web-based door opener, what is wrong and what should be done?
The administrator protected a "door open" web page only by putting it on an unusual network port, which is hiding, not security. Proper access protection (AAA) is needed, and the security-awareness gap calls for an information or training campaign.
The case: startup S moved into bigger offices with a general area and a restricted area for HR and the board. The secretariat opens the restricted door from inside for employees who need access, but it is now far from the door. So the IT administrator responsible for the door system published a web page with a "door open" link on the network, and to protect it from general access put it on an unusual port.
- Hiding the page provides no security: anyone who scans the network or learns the port can open the door to the HR and board area.
- Fix: set up access protection, meaning authentication and authorisation (AAA security).
- Root cause: a security-awareness deficit. An IT administrator should have basic cyber security knowledge, so an accompanying information or training campaign makes sense.