Help with Security Project

ChantelleC

Member
Hi,

I am doing a project at work on how to verify a user when they call our Help Desk for password reset / unlock accounts.

Currently they call up, tell us their name and we just unlock their account or reset their password on request.

I need a handful of ideas on how we can verify that they are who they say they are and I'm wondering if anyone has any ideas or knows of anything?


The things we have come up with so far are:

- Send a text to their personal mobile/cell phone with their new password

- Get them to text us (from their number registered with us), as well as request it by phone for unlocking an account

- Getting them to verify personal information, only held by HR (we haven't put this idea passed HR yet, but might be unlikely they will let this happen)


Any further idea's would be much appreciated!

Thanks

Chantelle
 

johnb35

Administrator
Staff member
Credit card companies always ask for address, date of birth, last 4 of SS# before they will reset your password or login info. Also it might help to create a list of 3 security questions and they provide the answers to them. So later when they need help they need to provide the answers.
 
Top