BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Looking For A Needle In A Haystack Without Least Privilege

Posted December 7, 2011    Peter McCalister

Ever use the phrase that looking for something was like “finding a needle in a haystack”? If you’ve ever seen (or especially played in) a haystack then you understand the magnitude of that challenge. This also applies to IT security when trying to uncover who or what was able to access confidential information and either steal, damage or delete it altogether.

needle

As I talk to CIO’s around the world I am always perplexed why they lament the challenge of rooting out (excuse the pun) potential insider threats responsible for data loss and the possibility of a failed compliance audit. In organizations where everyone has full administrator access to the network, determining who might have leaked, stolen or damaged data would be like looking for a needle in a haystack.

For organizations running good least privilege systems, it’s possible to narrow down the possibilities of who had access to what and when to fewer individuals. With that in mind, employees might think again before blowing the whistle. This is especially true for server-based least privilege solutions where keystroke logging will record everything done at a granular level, whereas desktop least privilege usually just tracks at an event level.

This doesn’t, by any stretch, prevent data breaches from happening. If someone has privilege access, they can still steal or leak sensitive data. As suggested in previous blog posts, what good least privilege solu- tions can do, however, is provide a strong deterrent, because a good least privilege solution means access is not just leveraged on a “needs must” basis, it is logged too. Connect with an expert to find out what can be done for your organization.

Leave a Reply

Additional articles

PowerBroker for Unix & Linux helps prevent Shellshock

Posted September 25, 2014    Paul Harper

Like many other people who tinker with UNIX and Linux on a regular basis, BASH has always been my shell of choice.  Dating back to the early days moving from Windows to a non-Windows platform, mapping the keys correctly to allow easy navigation and control helped ensure an explosion of use for the shell. Unfortunately,…

Bash “Shellshock” Vulnerability – Retina Updates

Posted September 24, 2014    BeyondTrust Research Team

A major vulnerability was recently discovered within bash which allows arbitrary command execution via specially crafted environment variables. This is possible due to the fact that bash supports the assignment of shell functions to shell variables. When bash parses environment shell functions, it continues parsing even after the closing brace of the function definition. If…

pbps-blog3

7 Reasons Customers Switch to Password Safe for Privileged Password Management

Posted September 24, 2014    Chris Burd

It’s clear that privileged password management tools are essential for keeping mission-critical data, servers and assets safe and secure. However, as I discussed in my previous post, there are several pitfalls to look out for when deploying a privileged password management solution. At this point, you may be wondering how BeyondTrust stacks up. With that,…

Tags:
, , , , ,