BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Network Devices Need Least Privilege Too

Posted December 21, 2010    Peter McCalister

Any security infrastructure at an organization is only effective as its weakest link.  All too often, the weakest link in today’s enterprise networks are the non-production servers and network devices not deemed mission critical.  Eliminating shared passwords and logging activities down to the keystroke level on SSH-based network devices is a critical success factor for eliminating that security “weakest link”.

Implementing least privilege with a privilege identity management solution is the only way to ensure network devices aren’t susceptible to intentional, accidental or indirect misuse of privilege.  It closes an often overlooked “back door” frequented by hackers and malware who hijack accounts with admin or excessive privilege.

As seen in this diagram there are three levels of risk mitigation available.

  1. Vaulting passwords will let you know who was using the resource and when, but not what they did.
  2. Session management gives the who and when as well as what they did by logging everything and therefore, from a forensic perspective, you will know how to “unwind” what was done.
  3. Privilege delegation does all of the above, but also eliminates the possibility of someone doing something they should not be doing, thus stopping the problem before it occurs.

Implementing a privilege identity management solution across SSH based network devices can deliver the following key benefits:

  • Transparent role-based access to non-mission critical servers and devices
  • Full keystroke logging with firecall capability and auditing
  • Agentless deployment, no performance impact
  • Instantly indexable and searchable logging

If you are interested in testing out a least privilege solution for yourself then check out the free evaluation of BeyondTrust’s PowerBroker Express today.

Leave a Reply

Additional articles

BA_Hacked

British Airways Executive Club Member Accounts Hacked

Posted March 30, 2015    Brian Chappell

British Airways has released information regarding the hacking of a number of their Executive Club (BA’s frequent flyer programme) member’s accounts.

Tags:
, , ,
webinar_ondemand

On Demand Webinar – Why You Still Suck at Patching

Posted March 27, 2015    Lindsay Marsh

On Demand Webinar: Dave Shackleford recounts some of his personal experiences in patch management failure, and breaks down the most critical issues holding many teams back from patching more effectively.

Tags:
,
dave-shackleford-headshot

Why You Still Suck at Patching…and How to Turn Your Life Around

Posted March 25, 2015    Dave Shackleford

Live webinar | March 26, 2015 | 10am PT/1pm ET | Dave Shackleford, SANS Instructor | Why You Still Suck at Patching…and How to Turn Your Life Around

Tags:
, ,