BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Born To Run…and Can Your Cloud Escape Injury?

Posted November 16, 2011    Peter McCalister

There’s a lot of hype in the running community over the 2009 book by Christopher McDougal, “Born To Run.” It has inspired a host of people–experienced runners and average Joes–to switch to barefoot running, where people where either nothing on their feet at all or some sort of minimalist shoe. The most headturning of these minimalist shoes have to be the Vibram Five Fingers shoes. You’ve seen them–they look like gloves for feet.

BTR cvr

I’m certainly no expert on running or barefoot running, but the jury still seems to be out on whether or not barefoot running is the right way to go. I recently heard from a podiatrist friend that he was seeing a significant increase in patients who had running injuries from the barefoot style. This has also been noted on sites like Competitor. The injuries seem to stem primarily from those runners who make a dramatic switch to barefoot running rather than making a gradual change.

So what does barefoot running have to do with desktop and server security technologies? Let me draw a parallel to cloud computing and new cloud initiatives. Frequently enterprise IT organizations embark on new cloud initiatives and often sink a lot of money into exploring the options available. Sometimes the rollout is underway before the planning phase has even gotten approval from the CIO.

With virtualization and the cloud getting all the hype these days, it’s certainly enticing to want to jump right in and start virtualizing everything. We know the benefits: pay for only what you use, greater reliability, replication of data, disaster recovery, etc. However, in many cases, the new cloud initiatives fail to examine the most important aspect of any virtual deployment–security.

Much like the barefoot runners who go all barefoot without a gradual entry and careful planning of their “migration” to the barefoot style, IT departments can essentially be “injured” by security breaches if they fail to properly secure their cloud environments.

Security in the private cloud starts at the hypervisor level. At BeyondTrust we’re primarily concerned with keeping insider threats–the threats posed by employees and internal trusted users. And, the best way to ensure that data in the private cloud stays secure and insider threats are kept at bay is to make sure that users are logging on to the hypervisors with their directory credentials.

From there, IT administrators can make sure that users are logging on to virtual machines–both desktops and servers–using their directory credentials provisioned in Active Directory. PowerBroker Identity Services features tools for securing desktops and servers–whether physical or virtual–and hypervisors. So don’t get caught up in the hype and end up with a cloud “injury.” Proper planning of your security and identity management is essential.

Leave a Reply

Additional articles

webinar 2

On Demand Webinar: Because Auditing Stinks Sometimes

Posted July 2, 2015    Lindsay Marsh

Auditing stinks. Well, mostly stinks. In this on demand webinar, lead by Group Policy MVP Jeremy Moskowitz, you’ll learn the three key tenets to real Group Policy auditing. Tenet 1: Why do you care about Group Policy auditing? Tenet 2: How does Eventing help you know “Who did what?” Tenet 3: How does Reporting tell…

Tags:
, , , ,
skeletonkey3_713678_713680

Stopping the Skeleton Key Trojan

Posted June 29, 2015    Robert Auch

Earlier this year Dell’s SecureWorks published an analysis of a malware they named “Skeleton Key”. This malware bypasses authentication for Active Directory users who have single-factor (password only) authentication. The “Skeleton Key” attack as documented by the SecureWorks CTU relies on several critical parts.

Tags:
, , , , ,
webinar 2

On Demand Webinar: 10 Steps to Building an Effective Vulnerability Management Program

Posted June 26, 2015    BeyondTrust Software

In this on demand webinar, Cybersecurity Expert, Derek A.Smith will take you through his 10 steps for a successful vulnerability management program and how to get started now.

Tags:
, ,