BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

The Intersection of Policy, Technology & People

Posted May 16, 2011    Peter McCalister

Lot’s of things come in threes. You can’t get fire unless you have heat, fuel and oxygen and a great swing just needs a tree, a tire and some rope. Turns out that you also can’t get to a least privilege environment unless you’ve dealt with the intersection of policy, technology and people.

Achieving least privilege isn’t as elusive as one might perceive and it certainly is one of the key requirements to eliminate the misuse of privilege throughout the extended enterprise (physical servers and desktops, cloud and virtual environments) or to greatly mitigate the risk of an insider breach. We have reported extensively on the cost of intentional, accidental and indirect misuse of privilege as well as highlighted numerous examples where insider breaches have cost organizations millions of dollars in the blog over the last year.

So why is it that most organizations still struggle with the decision to implement a least privilege solution let alone the steps necessary to implement it correctly? All too often, the solution is simple if one just steps back and chooses not to over-complicate the requirements. In this case the 3 step process would be:

Decide to invest in eliminating insider threats with as much tenacity and urgency as you have in preventing outsider threats.
Determine which roles (people) should have access/authorization to do what (policy) and implement a least privilege solution (technology) that enforces those policies to those people.
Monitor, measure and refine for further improvements as well as satisfy governance and compliance audit requirements.

Leave a Reply

Additional articles

Dark Reading

2014: The Year of Privilege Vulnerabilities

Posted December 18, 2014    Chris Burd

Of the 30 critical-rated Microsoft Security Bulletins this year, 24 involved vulnerabilities where the age-old best practice of “least privilege” could limit the impact of malware and raise the bar of difficulty for attackers.

Tags:
, , , , ,
dave-shackleford-headshot

Looking back on information security in 2014

Posted December 16, 2014    Dave Shackleford

Dave Shackleford is a SANS Instructor and founder of Voodoo Security. Join Dave for a closer look at the year in security, and learn what you can do to prepare for 2015, with this upcoming webinar. 2014 has been one heck of an insane year for information security professionals. To start with, we’ve been forced…

Tags:
, ,
patch-tuesday

December 2014 Patch Tuesday

Posted December 9, 2014    BeyondTrust Research Team

This month marks the final Patch Tuesday of 2014. Most of what is being patched this month includes Internet Explorer, Exchange, Office, etc… and continues a trend of the greatest hits collection of commonly attacked Microsoft software. Probably the one thing that broke the mold this month is that for once there is not some…

Tags:
,