BeyondTrust

Security In Context

Bringing you news and commentary on solutions and strategies for protecting your critical IT infrastructure.

Insider Hero Introduced: Secure Sam

Post by Peter McCalister July 18, 2011

In order to put a face on the depth and breadth of potential insiders that can be found throughout your enterprise, I will introduce you to three insider villains and three insider heroes. Each villain will represent one of the key misuse of privileges and each hero will represent key values delivered by least privilege. This fourth introduction will be of the most visible hero.

“Secure Sam” is always on the lookout for exposures, whether intentional, accidental or indirect. And he’s always trying to balance sufficient access with sufficient security. Fortunately for Sam, BeyondTrust Privileged Identity Management solutions provide both, with a complete suite of tools that allow functional access but keep system access on a tight leash.

At face value the successful Secure Sam projects an air of calm, cool and collected control over the enterprise governance, risk and compliance mitigation requirements. Behind the scenes he/she is a whirling dervish of politician meets technician meets mind reader meets soothsayer all served up with one great big stress sandwich.

Ever see how a duck glides through water? It looks effortless from the surface, but beneath the waterline is a different story. In reality the poor duck is paddling his webfeet feverishly in order to move about. Now you know what it’s like to be a Chief Security Officer (CSO), or IT manager responsible for information security, managing today’s enterprise security requirements. One of these, or some variation thereof, is ultimately the title Secure Sam holds in your organization. Now you know what his day is like.

Leave a Reply

Additional articles

BI-Qualys-Connector-IMG1

Getting More Value from QualysGuard Vulnerability Data with BeyondInsight v5.1

If your vulnerability assessment scans can’t produce meaningful and actionable reports, performing a scan does no good for anyone. If you’ve read my other blog posts, you know I have no qualms about stating that BeyondTrust provides the best vulnerability reporting in the industry. Ask your favorite analyst and they’ll tend to agree. Of course,…

Post by Morey Haber April 18, 2014
Tags:
, , , , , , , ,
insider-threat-fed

Mitigating Inside Threats to U.S. Federal IT Environments

Recent high-profile cases have increased the perceived risks that go along with disclosure and usage of confidential information. One of the most difficult security threats to mitigate is an attack from the inside. When an over-privileged user, such as an unhappy current or former employee, contractor, or consultant, begins navigating your network, how will you…

Post by BeyondTrust Software April 17, 2014
Tags:
, , , , ,

Are you a Target? Investigating Security Breaches with Kevin Johnson

Last week, over 1,000 IT security professionals watched as Kevin Johnson, CEO of Secure Ideas, presented his expert opinion on lessons learned from recent, high-profile retail breaches. Here’s a summary of key takeaways from the webcast plus an on-demand recording of the full, 60-minute presentation. Understanding the “why” behind attacks According to Kevin, the primary…

Post by Chris Burd April 17, 2014
Tags:
, , , , ,