BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

3 Ways to Remediate Misuse of Privilege

Posted January 20, 2011    Peter McCalister

In the event that someone in your organization does misuse privilege and causes harm (theft, damage or loss of data), you will have to immediately deal with the aftermath.  In today’s security conscious enterprise, there are three level of remediation to consider:

  1. Password Management:  In this situation you have eliminated users maintaining their own credentials and facilitate the access to information technology (IT) resources through a web-based Shared Account Password Management (SAPM) solution.  When the user desires access they go to a specific web screen which then logs the user into the requested resource based on some recognized stored policy.  The good news here is that in the event someone misuse that resource, you have a record of who was using it at the time of the breach.  This is the equivalent of know who did the damage but not what they did.
  2. Session Management:  In this situation, you are building on Password Management with the addition of automatic logging of every event (or keystroke) to another server of what was done once someone is granted access to the resource.  If harm does in occur in this situation then you not only know who did the harm but what they did, so you can “unwind” or fix what was done.
  3. Privilege Delegation:  In this situation, you are delegating privileges (system authorizations) to specific users based on defined, centralized corporate policy.  This builds on Session Logging and delivers all of the previous value but now limits the damage potentially done as it limits what authorizations are available based on policy.  In effect you have prevented harm from being done and have a record of who attempted to do harm and what they attempted to do.

Bottom line is that you need some form of solution to protect against the misuse of privilege and remediate any potential harm that does occur.

Leave a Reply

Additional articles

CyberResiliency

6 things I like about Gartner’s Cyber Resiliency Strategy

Posted August 27, 2015    Nigel Hedges

There were 6 key principles, or recommendations, that Gartner suggested were important drivers towards a great cyber resiliency posture. I commented more than once during the conference that many of these things were not new. They are all important recommendations that are best when placed together and given to senior management and the board – a critical element of organisations that desperately need to “get it”.

Tags:
,
powerbroker-difference-1

Why Customers Choose PowerBroker: Flexible Deployment Options

Posted August 26, 2015    Scott Lang

BeyondTrust commissioned a study of our customer base in early 2015 to determine how we are different from other alternatives in the market. What we learned was that there were six key differentiators that separate BeyondTrust from other solution providers in the market. We call it the PowerBroker difference,

Tags:
, ,
Mac-Security-Enterprise

On Demand Webinar: Security Risk of Mac OS X in the Enterprise

Posted August 20, 2015    BeyondTrust Software

In the last several years, Mac administrators have come to realize that they may be just as vulnerable to exploits and malware as most other operating systems. New malware and adware is released all the time, and there have been serious vulnerabilities patched by Apple in the past several years, some of which may afford attackers full control of your systems.

Tags:
, ,