BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Top 10 Reasons To Implement Least Privilege for Linux Servers

Posted November 19, 2010    Peter McCalister

In the spirit of keeping blog posts informative, short and fun, this one takes a cue from David Letterman in format.  So without further fanfare or wasted space… the Top 10 Reasons to Implement Least Privilege on Linux Servers are:

#10 – Sam, the CSO can now sleep nights knowing that excess privileges will no longer be responsible for failing a SOX, HIPAA, PCI, DSS, GLBA or FDCC and FISMA audit (even though he isn’t required to even deal with the last two).

#9 – Andy the Auditor can get a full report of who has what entitlements instantly to satisfy compliance successfully, instead of taking weeks of manual effort

#8 – Ted in Tech Support won’t be able to reset file and directory permissions on any Linux server he has admin rights to so liberally that anyone with a login can access confidential data just because it makes his job easier

#7 – Sid in Development won’t be able to download Apache applications or any otherunauthorized open source “tools” potentially injecting malware into our corporate network

#6 – Fiona and Felix our new Linux administrators won’t make one, or more, of the 10 Mistakes New Linux Administrators Make

#5 – Vito, the ever-industrious programmer will no longer be able to code suid root binaries into his programs allowing programmatic access beyond what is allowed by corporate policy or regulatory requirements

#4 – Alice in IT will no longer be responsible for DNS misconfiguration errors as her role won’t facilitate this level of admin privilege

#3 – Fred in IT won’t be able to install a Trojan on the mission critical server, bringing it down for 4 hours and costing the company over $1M in lost transactions, because he was passed over for a big promotion

#2 – Sarah, the CIO will no longer have to hide Linux root credentials in a sealed envelope in her office safe and deal with a manual check in/check out process

#1 – Tony, the Palo Alto Linux administrator will no longer be able to wear that ratty old T-shirt with the slogan “Bow before me, for I am root” any longer

Leave a Reply

Additional articles

CyberResiliency

6 things I like about Gartner’s Cyber Resiliency Strategy

Posted August 27, 2015    Nigel Hedges

There were 6 key principles, or recommendations, that Gartner suggested were important drivers towards a great cyber resiliency posture. I commented more than once during the conference that many of these things were not new. They are all important recommendations that are best when placed together and given to senior management and the board – a critical element of organisations that desperately need to “get it”.

Tags:
,
powerbroker-difference-1

Why Customers Choose PowerBroker: Flexible Deployment Options

Posted August 26, 2015    Scott Lang

BeyondTrust commissioned a study of our customer base in early 2015 to determine how we are different from other alternatives in the market. What we learned was that there were six key differentiators that separate BeyondTrust from other solution providers in the market. We call it the PowerBroker difference,

Tags:
, ,
Mac-Security-Enterprise

On Demand Webinar: Security Risk of Mac OS X in the Enterprise

Posted August 20, 2015    BeyondTrust Software

In the last several years, Mac administrators have come to realize that they may be just as vulnerable to exploits and malware as most other operating systems. New malware and adware is released all the time, and there have been serious vulnerabilities patched by Apple in the past several years, some of which may afford attackers full control of your systems.

Tags:
, ,