BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Granular Control is Gold

Posted March 9, 2012    Peter McCalister

If you haven’t noticed, there are some things in our enterprises that we just can’t afford to leave generic. Certain things need to be fine-tuned and customized in ensure the success (and security) of each individual company. One of these is the level of privilege each user has. You need to be able to define how much access each user/manager/administrator is allowed to operate with. You should know exactly who has access to what information and what time, and how they are using it. In a world where new data breaches are showing up in the media daily, the need for the shift to granular classifications is immediate. Making such a security measure a priority will ensure a more secure enterprise. Ignoring the need will create an incompliant environment and leave your company open to security breaches.

Letting everyone have access to your system is a bad security practice. Especially on your servers, where 90% of data breaches occur. Sure, turning a blind eye and giving employees access to the root password can be easier than the alternative, but at what cost do you put ease over security? Root itself is not necessary for employees to complete their jobs- just the elevated access to certain tasks. The most dangerous security risk that every corporation needs to address is the over-privileged account. The reason? All those open, unsecured gateways that lead directly to your sensitive information! Both internal breaches (caused by the misuse of privileges) and external breaches (which are caused when a hacker hijacks the credentials of someone with all-powerful access) can be prevented with granular control and monitoring of who has access to what information within the walls of your organization.

Click here to read this cutting-edge whitepaper on how to acheive this level of security in your company.

Leave a Reply

Additional articles

dave-shackleford-headshot

Privileged Passwords: The Bane of Security Professionals Everywhere

Posted February 19, 2015    Dave Shackleford

Passwords have been with us since ancient times. Known as “watchwords”, ancient Roman military guards would pass a wooden tablet with a daily secret word engraved from one shift to the next, with each guard position marking the tablet to indicate it had been received. The military has been using passwords, counter-passwords, and even sound…

Tags:
, , ,
Privileged Account Management Process

In Vulnerability Management, Process is King

Posted February 18, 2015    Morey Haber

You have a vulnerability scanner, but where’s your process? Most organizations are rightly concerned about possible vulnerabilities in their systems, applications, networked devices, and other digital assets and infrastructure components. Identifying vulnerabilities is indeed important, and most security professionals have some kind of scanning solution in place. But what is most essential to understand is…

Tags:
, , , , ,
bank theft img

The Vulnerabilities and Privileges of Carbanak Bank Thieves

Posted February 17, 2015    BeyondTrust Research Team

Recently Kaspersky released analysis of a series of significant breaches against financial institutions by a group they have dubbed Carbanak. The attacks go back over 2 years and estimates are that potentially $1 billion dollars in total were stolen from more than 100 financial institutions. In some cases the attackers were active in victim organizations between…

Tags:
, , ,