BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

You Will Know It When You See It

Posted November 21, 2011    Peter McCalister

One of most talked about topics at the just completed Gartner Identity and Access Management Summit in San Diego was advanced persistent threats. While it may be hard to define, and I will leave that to the experts at Gartner, based on the level of discussion at the event and all the available data this is a topic you will get to know in the near future.

no excuses

From Sony to RSA the frequency and sophistication of attacks on your critical IT infrastructure are increasing dramatically. With the rapid changes in technology from desktop and server virtualization to the increasing use of SAAS and public, private and hybrid clouds the old perimeter based model is no longer sufficient. Any weakness in your infrastructure that allows an attacker to access a system will give him or her opportunity to find another weakness and eventually get to the keys to the kingdom – privileged access to a critical server or database with sensitive information.

What’s needed is a comprehensive program to protect privileged access. The tradeoffs everyone has historically made to allow some level of risk no longer apply. Even something as simple as the accidental misconfiguration of a desktop PC can be the weakness a sophisticated attacker uses to gain the access they need to the privileged credentials of a systems or database admin.

There are no excuses any more. Even if you can’t define it you better beware or you will know at lot more about these threats when you see it in your environment.

Leave a Reply

Additional articles

Sudo_logo

Don’t Create a Different sudoers File for Each System

Posted May 20, 2015    Randy Franklin Smith

What if you have multiple Linux and/or Unix systems? Sudo management can become onerous and unwieldy if you try to manage a different sudoers file on each system. The good news is that sudo supports multiple systems.

password-safety

What Does Microsoft Local Administrator Password Solution Really Do?

Posted May 19, 2015    Morey Haber

LAPS is a feature that allows the randomization of local administrator accounts across the domain. Although it would seem that this capability overlaps with features in BeyondTrust’s PowerBroker Password Safe (PBPS), the reality is it is more suited for simple use cases such as changing the local Windows admin account and not much more.

Tags:
, ,
webinar_ondemand

On Demand Webinar: Securing Windows Server with Security Compliance Manager

Posted May 14, 2015    BeyondTrust Software

On Demand Webinar: Security Expert Russell Smith, explains how to use Microsoft’s free Security Compliance Manager (SCM) tool to create and deploy your own security baselines, including user and computer authentication settings.

Tags:
, ,