BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

I See Dead People- and All Database Activity

Posted August 26, 2011    Peter McCalister

Remember The Sixth Sense, that movie where Haley Joel Osmond’s character can see ghosts are if they were living people? It’s an interesting premise to give a character such a unique and special capability- to see and communicate with ghosts, whether benign or hostile, is clearly something out of the ordinary. Knowledge is power, and because he knew they were there and could communicate with said entities, he eventually was able to diffuse tense situations and helped achieve solutions in the existence of the ghosts in the movie.

Since this is a blog about enterprise security, let’s take a look at the film through the eyes of an IT administrator. There is one huge parallel that I can’t help but draw- the ability to see entities that others aren’t aware of. While we may not have to deal with actual ghosts, that specific ability to see and communicate with things that otherwise go unnoticed is one of the keys to compelte enterprise security. Also known as monitoring, that communication and awareness is crucial to an effective security program.

So many things in an enterprise need to be monitored. Privileged users, what users can and cannot access, all activity (down to the keystroke level), access to systems, error reports, security controls, compliance reporting, and session activity are just a few. Without monitoring, those responsible for IT have no idea what is going on in these areas. It’s impossible to know where problems exist and what can be done to fix them, and it’s hard to be confident in the status of your company’s secure information. Monitoring is also a huge part of having a compliant IT infrastructure. The ability to oversee activity is critical, and truly a capability that must be included in each IT environment’s security strategy.

Click here to learn how to go Sixth Sense on your IT infrastructure.

Leave a Reply

Additional articles

dave-shackleford-headshot

Looking back on information security in 2014

Posted December 16, 2014    Dave Shackleford

Dave Shackleford is a SANS Instructor and founder of Voodoo Security. Join Dave for a closer look at the year in security, and learn what you can do to prepare for 2015, with this upcoming webinar. 2014 has been one heck of an insane year for information security professionals. To start with, we’ve been forced…

Tags:
, ,
patch-tuesday

December 2014 Patch Tuesday

Posted December 9, 2014    BeyondTrust Research Team

This month marks the final Patch Tuesday of 2014. Most of what is being patched this month includes Internet Explorer, Exchange, Office, etc… and continues a trend of the greatest hits collection of commonly attacked Microsoft software. Probably the one thing that broke the mold this month is that for once there is not some…

Tags:
,
Chained to the phone

“I’d love to come, but I’m on-call”: Privilege management can relieve holiday help desk headaches

Posted December 3, 2014    Jason Silva

Part of working in IT means you put in your time “on-call.” Companies either don’t realize there is a better way to allow users to maintain administrative access to endpoints, or they remove admin rights from users but don’t account for the resulting operational inefficiencies.

Tags:
, , , , , , ,