BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Governance, Risk, and Compliance- Cogs of Security Clock

Posted October 5, 2011    Peter McCalister

Enterprise security, as I’m sure all of you are aware of, is complex. There are a lot of differentfacets and initiatives, and they all fit together in a very intricate and complicated way. The image of a clock, with all those little gears moving together, is how I picture a healthy security program in any given organization. But to think of security objectives like cogs in a clock begs the question of where is the IT parallel? What cogs are crucial to making the clock tick and which ones aren’t? I submit that the governance, security, and compliance mechanisms are the most significant. With these cogs, you set the pattern for security in your enterprise.

Governance is crucial to the plan of your IT infrastructure. We’ve talked about the role of a CSO or IT manager before- it’s these roles that keep the cogs turning in your IT clock. Governance makes sure that your policies are cohesive and that appropriate management is taking place. Without it, whatever security endeavors you have in place will fail.

Risk is another vital element in your security structure. Monitoring the dangers associated with privileged identities is a huge part of why this cog is so important. The management of identities (i.e. – who has access to what information) is key in preventing insider threat and the misuse of privilege. Risk must be kept at a minimum in order for your security system to continue to operate like clockwork (pun intended).

Compliance, the last of the three major mechanisms in your IT organization, is critical to the prosperity of your security plan. The government has mandated several regulations in the defense of data and the protection of information. Following these mandates, as well as passing required security audits, is what drives compliance within organizations.

Leave a Reply

Additional articles

ovum-research

New Analyst SWOT Assessment Identifies Key Strengths of PowerBroker

Posted November 24, 2014    Scott Lang

Following on the heels of the Gartner PAM market guide and Frost & Sullivan review of Password Safe comes a new analyst review of our BeyondInsight and PowerBroker platforms, a SWOT assessment of BeyondTrust written by Ovum. Ovum’s honest and thorough review of BeyondTrust indicates that we are delivering, “…an integrated, one-stop approach to PAM….

Tags:
, , ,

Patented Windows privilege management brings you unmatched benefits

Posted November 24, 2014    Scott Lang

We are pleased to announce that BeyondTrust has been granted a new U.S. Patent (No. 8,850,549) for privilege management, validating our approach to helping our customers achieve least privilege in Windows environments. The methods and systems that we employ for controlling access to resources and privileges per process are unique to BeyondTrust PowerBroker for Windows….

Tags:
6

A Quick Look at MS14-068

Posted November 20, 2014    BeyondTrust Research Team

Microsoft recently released an out of band patch for Kerberos.  Taking a look at the Microsoft security bulletin, it seems like there is some kind of issue with Kerberos signatures related to tickets. Further information is available in the Microsoft SRD Blogpost So it looks like there is an issue with PAC signatures.  But what…

Tags:
, , , ,