BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Confessions of a Paranoid IT Director

Posted April 6, 2011    Peter McCalister

Hi, my name is Betty, I’m an IT Director at a large utility company and it’s been 1 week since my VP of Software Development complained that security was locked down too tight to get anything done. (All together now) HI BETTY!

I know this is a support group for IT Directors suffering from governance, risk and compliance issues, but candidly I don’t acknowledge that I, or my organization, has a problem.  I’ve locked down every network, server, desktop, cloud and virtual environment so tightly that it takes a call to the help desk anytime someone needs admin rights to do anything.  Sure, our help desk costs skyrocketed, but this way I have complete control over who does what to our IT systems and can guarantee security to my boss.

The other problem that I have to ignore frequently is the VP of the Software Development organization who is constant complaining that his team can’t get anything done and will be missing their deadlines because of my security policies.  He is now threatening to break into our data center and reprogram all security policies one night, so I am evaluating new physical security measures as well.

I recently saw an ad for Guido the Gorilla who is trained to protect IT assets the old fashioned way…with intimidation and brute force.  Do you think he will be worth the investment or not worth his weight in bananas?

Leave a Reply

Additional articles

Password Game Show

Managing Shared Accounts for Privileged Users: 5 Best Practices for Achieving Control and Accountability

Posted November 20, 2014    Scott Lang

How do organizations ensure accountability of shared privileged accounts to meet compliance and security requirements without impacting administrator productivity? Consider these five best practices…

Tags:
, , , , , ,
Triggering MS14-066

Triggering MS14-066

Posted November 17, 2014    Research Team

Microsoft addressed CVE-2014-6321 this Patch Tuesday, which has been hyped as the next Heartbleed.  This vulnerability (actually at least 2 vulnerabilities) promises remote code execution in applications that use the SChannel Security Service Provider, such as Microsoft Internet Information Services (IIS). The details have been scarce.  Lets fix that. Looking at the bindiff of schannel.dll, we see a…

Tags:
, , , ,
Monetary Authority of Singapore

Why MAS Compliance is Still a Real MUST

Posted November 12, 2014    Morey Haber

As reported in our blog earlier this year MAS guidelines are set to change the way financial institutions conduct business in Singapore. Now, nearly four months past the compliance date of July 2014, we are revisiting the guidelines that surround the regulations. Non-compliance was said to result in the following implications for financial institutions: Financial…

Tags:
, , , , ,