BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Reducing Help Desk Costs Is a Least Privilege Benefit

Posted December 15, 2010    Peter McCalister

The problem exists between the keyboard and the chair (PEBKAC).  This is the recurring mantra of most help desk technicians and a leading cause of budget dollars bleeding out of most organizations.  Why, you may ask?  The answer is simple:

  • Users use computers
  • Users are human (usually)
  • Humans make mistakes often: sometimes intentionally, usually accidentally and occasionally indirectly
  • When users have excessive admin rights these mistakes can be very costly

Implementing a privilege identity management solution will effectively limit the potential for impact on these mistakes through a least privilege environment.  One of the most compelling areas will be for the desktop users as there are over 200 documented vulnerabilites in MS Windows. Check out the “3 Ways to Reduce Help Desk Costs” blog for specifics on cost savings, but the intangible benefit that your techs will appreciate the most is the reduction of PEBKAC calls.  With the implementation of a least privilege solution, the user community will only have enough privilege to get their job done but not enough to have a misuse of privilege problem. Now the problem won’t be the user (what lies between the keyboard and the chair), but a genuine technical problem, like installing a print driver.  What price can be put on the sanity of your help desk staff?

Leave a Reply

Additional articles

VMware Hardening Guidelines-img3

How to Audit VMware ESX and ESXi Servers Against the VMware Hardening Guidelines with Retina CS

Posted February 27, 2015    BeyondTrust Research Team

Retina CS Enterprise Vulnerability Management has included advanced VMware auditing capabilities for some time, including virtual machine discovery and scanning through a cloud connection, plus the ability to scan ESX and ESXi hosts using SSH. However, in response to recent security concerns associated with SSH, VMware has disabled SSH by default in its more recent…

Tags:
, , , ,
dave-shackleford-headshot

Privileged Passwords: The Bane of Security Professionals Everywhere

Posted February 19, 2015    Dave Shackleford

Passwords have been with us since ancient times. Known as “watchwords”, ancient Roman military guards would pass a wooden tablet with a daily secret word engraved from one shift to the next, with each guard position marking the tablet to indicate it had been received. The military has been using passwords, counter-passwords, and even sound…

Tags:
, , ,
Privileged Account Management Process

In Vulnerability Management, Process is King

Posted February 18, 2015    Morey Haber

You have a vulnerability scanner, but where’s your process? Most organizations are rightly concerned about possible vulnerabilities in their systems, applications, networked devices, and other digital assets and infrastructure components. Identifying vulnerabilities is indeed important, and most security professionals have some kind of scanning solution in place. But what is most essential to understand is…

Tags:
, , , , ,