Talk to us Risks to Watch

10 steps to better manage Privileged Access

Andrew Dalglish, director of Circle Research, a UK based research firm recently said “The very people working in businesses can pose as the biggest threat to its security.” That’s a pretty huge statement to make come to think of it. Why would he say that when organizations across the world are taking the necessary precautions and spending billions on IT security? Well the answer to that is simple; most organizations are still focused on thoroughly securing their perimeter. Based on a survey by SpectorSoft, a pioneer in user activity monitoring and behavior analysis, a staggering 62% organizations saw a rise in insider attacks over 2014-2015. This means, although a majority of the organizations are aware of privileged access security and have security solutions in place, they have seen a rise in insider threats. Research firm Gartner has solved this mystery stating “Less than 5% of the organizations were tracking and reviewing privileged activity in 2015. The remaining are at best controlling access and logging when, where and by whom privileged access has taken place but not WHAT actually is done.”

Maybe the reason for this is lack of knowledge or awareness amongst the employees about the importance of privileged security. This was validated by Ernst and Young in their 2015 Global Information Security Survey where they identified careless or unaware employees to be one of the top two vulnerabilities exposing organizations to cyber-attacks. And if this is left unaddressed, then as per Gartner, by 2018, privileged access will be responsible for up to 60% of insider misuse and data theft incidents.

So as responsible cyber security specialists, we felt the need to create awareness on this matter. That is why the ARCON team has meticulously devised a list of 10 steps on how you can better manage Privileged Access.

1. Predict: As a first step to your privileged identity program, you must plan and evaluate all your user entries who needs to access your environment, e.g. Contractors, temporary staff, offshore employees, employees etc. As a best practice, these privileged users should be recorded and accounted for.
2. Onboard: Onboard privileged accounts including shared accounts, named entities, service accounts to the PAM solution. This also means the privileged accounts should be assigned an ownership in an indirect manner i.e. on a functional level and not an individual level. This way, your IT system is not exposed to orphan accounts whenever an individual moves out of your organization thereby securing a vulnerability.
3. Change Password: Plan a password rotation program to plan all privileged accounts in the environment are protected by your password management policies. This is best done using an SAPM tool that allows for automatic password generation and change.
4. Protect: Ensure passwords are managed in the electronic password vault which is highly available and tamper proof in nature. This allows for passwords to be stored in a highly secure electronic vault offering several layers of protection and creating a virtual fortress thereby.
5. Request: Design a workflow for password or access usage to control password access to all relevant stakeholders within your IT environment. Manually designing a workflow can be fragile and hence it is advisable to implement solutions worthy of automating processes and enforcing controls.
6. Approve: It’s important to designate competent individuals to ensure right approvals are defined for each access request. This must be managed by a solution with right audit trails to track such approvals. This will also ensure least privilege principle limiting the scope of any privileged account giving them minimum rights for performing exactly the specific task which the respective account is needed to perform and nothing more.
7. Access: Next step is to define and extend governance controls to your access rule list linked to individual and critical accounts. By doing this, you are meeting your organization’s compliance requirements by periodically reviewing and validating number of privileged users, who the privileged users are, their access rights and what activities they perform under the guise of a privileged user.
8. Control: Enforce strict policies in line with your security policies to control password release function, password usage function for all your IT equipment.
9. Monitor:Establish policies in place to log, monitor, report and analyze privileged user sessions/activity. It is highly recommended to monitor and review privileged activity real-time by implementing a live dashboard monitoring tool. Also, it is best practice to periodically review session logs and not just when an incident needs to be investigated as this helps analyze privileged user behavior to critical systems.
10. Prevent:The next and most vital level of privileged access management is to implement preventive access control policies to granularly control critical activities of IT administrators and super-users. This ensures that super-users do not have more privileges than are needed and essentially helps split up required privileges among administrators depending on their specific task. Additionally, it ensures a separation of access privileges between the administrators, developers, testers and operators on your IT systems.
The above are as we have coined it the 10 golden steps of Privileged Access Management / Privileged Identity Management. Our team’s extensive experience and expertise to analyze the IT systems have guided us in developing these steps. Our consultative approach on these matters in addition to our solutions have also primarily led to our clients follow these best practices.We advise the same approach to many of our existing clients, potential clients and partners that we have come across on several events and conferences that ARCON has been a part of. And we are certain that following the above will go a long way in providing what we call ‘absolute protection’ to your organization.

ARCON provides state-of-the-art technology aimed at mitigating information systems related risks thereby enabling organizations to comply with Governance, Risk Management and Compliance (GRC) requirements. The company, in particular, is known for its unique Privileged Identity Management/Privileged Access Management solution, which helps deter the misuse of ‘privileged identities’.

Learn more about us at www.arconnet.com

Password Management Compliances across the World

In one of my previous roles as a test analyst, I was primarily responsible for constructing test cases for password management. At the time, I had devised a whole array of possible test cases for password management which included specifications on the length of the password, complexity of the password, frequency for changing password and so on. However a thought struck me. This tedious manual procedure of password management by the administrator or super-user was done to ensure security but where is the security after all? How many permutations and combinations can a human come up with to ensure these passwords are managed and maintained to comply with regulatory standards? But today working in this cyber security space, I can confidently say that you just have to go knocking on the right door to eliminate this monotonous process and get automated password management solutions that is regulatory compliant and at the same time safe, effective and productive.

As a brief introduction, compliance with government regulations has been a major issue most organizations across the world have been grappled with. The ever increasing regulations are dramatically impacting the IT infrastructure as well as business processes. In the past two decades, several laws have been passed compelling organizations across industries to put corporate compliance policies in place. And these regulations have posed major challenges to the IT departments across organizations to ensure strong internal controls protecting privacy and security of critical data.

Interestingly, amongst all of the compliance policies, it was stated by PistolStar in one of their white paper publications that password management emerged as a strategic component for successful compliance. From a CIO or CISO perspective, many have unanimously opined that passwords are not the problem but the behavior for how passwords are managed is. It would suffice to say that adhering to regulations and standards both from the end user perspective and privileged user perspective is fundamental to worthy compliance.

Here is a list of the most common compliance regulations that organizations across industries are required to follow.

  • Sarbanes-Oxley Act (SOX- for all public companies)
  • Payment Card Industry Data Standards (PCI DSS- especially for credit card companies)
  • Gramm-Leach-Bliley Act (GLB- for financial institutions)
  • Health Insurance Portability and Accountability Act (HIPAA- for the healthcare industry)
  • Basel II Compliance (for financial institutions)

The password management requirements prescribed by these regulatory policies are unanimous and fairly similar with regards to privileged account passwords.

We at ARCON understand the need of the organizations and the nitty-gritties of the regulatory measures. This has equipped us to provide a sound password management solution adhering to the required compliance standards. Our password management solution is an automated tool with customizable features. It generates strong dynamic passwords with an engine that can automatically change passwords for several devices and systems at one go. The passwords are subsequently stored in a highly secured electronic vault with several layers of protection creating a virtual fortress. This ensures a high level of security, compliance with regulations and essentially does away with the mind-numbing procedure of manually changing a gazillion passwords protecting human energy thereby enhancing efficiency in other areas of the business.

Let’s stop blaming the passwords and take measures to change our behavior in managing them better by empowering the appropriate solutions.

Privileged Thinking of the Cloud

Just as I went to collect my iPad this morning from the study room, something that was an integral part of my childhood grabbed my attention. This precious treasure was lying in one corner dusted and covered by a cloth which had torn. The treasure that I speak about was my best friend and is nothing else but the desktop computer that I used in the 90’s and early 2000’s. There was a time when for any important work or internet use, only one device could be used – the computer. Today if I want information on the internet, the last thing I use will probably be that desktop computer. And this is the same for most of us today.

You must be thinking many organizations still use them. Think again, do they? Everything you need right from information to shopping to paying bills is available at the click of a button on a laptop, tablet or a smartphone. Over the past two decades, technology including the internet has truly been on a revolutionary path. So how has this transformation happened? How is it that all the information we need can be accessed through any device from the biggest to the smallest? One of the phenomena responsible for this radical change is called Cloud Computing.

Cloud computing in very simple language is like a one stop shop. You want to access information, store information, monitor, communicate, organize, compute and almost anything you need is enabled by this internet-based computing. Cloud computing enables for a seamless access to a shared pool of configurable resources such as networks, servers, databases, storage and applications to name a few. Most of the organizations are shifting their businesses on cloud courtesy low infrastructure cost, high performance, more scalability and accessibility. You can’t resist but acknowledge that Cloud computing is a blessing.

Having said that, there are two sides to the same coin. Such high levels of technological advancement and automation comes with an excess baggage of security threat. Hackers are always eager to find a way to penetrate and disrupt the systems in some way. In addition, with the rise in Bring Your Own Device (BYOD) trends, organizations are facing a challenge of provisioning and managing large number of identities within the organizations. Owing to this, security has taken a front seat such that itis being enabled to centrally manage, control and secure information accessed by identities. Access management practices are under tight scrutiny with regulators constantly updating and increasing the controlling standards.

This is the reason that Identity and Access Management (IAM) solutions have become uniquely important to organizations across industries. Cloud IAM is a simple solution that answers who, what and which – who has what access for which resource. It helps control, manage, and record user identities and their respective access permissions that can be instrumental in protecting company confidential records thereby preventing cyber threats. But is that enough? Maybe, maybe not.

We have heard of several catastrophic insider threats in the recent past, from large enterprises to SMB’s. These companies had good security policies in place but maybe what they didn’t see coming was an attack from the inside. There were still loopholes that the dominant users within the organizations could take advantage of. And this is where an additional layer of security within the domain of IAM called Privileged Identity Management (PIM) solutions comes into picture.

Privileged Identity Management (PIM) focuses more on who, what and which of the powerful accounts within the IT infrastructure such as the super-users, DBA users, CIO’s etc. Privileged Identity Management controls and monitors the influential users within the system. So is Privileged Identity Management solution only good to provide security? No. It makes life easy for the super-user and the CIO or CISO or CTO and subsequently the owner. How is that? Well, that is because PIM solution controls and authenticates the many users in your system, it manages passwords changing it regularly aligning with the regulatory policies for password change for you (boon for super-user/admin because he doesn’t have to go through the long tedious procedure of changing passwords manually for all the users), it restricts access to certain secure databases and systems from people who are not authorized to access them, it monitors by video and by log of all the activities that the users perform, it allows for a single sign on enabling users to only remember one password for a single entry and seamlessly access there on applications and servers the user has access to, it flags and alerts on a live dashboard monitoring tool whenever there has been a breach and lastly it ensures adherence to the compliance and regulatory procedures giving a good night’s sleep to the CISO’s and the owners. Nothing like a good night’s sleep now, is there!

Do your part, switch to cloud but ensure you have the Privileged Identity Management solutions put in place today, if you haven’t already done so.

About ARCON
ARCON is a leading technology company specializing in risk control solutions. ARCON offers a proprietary unified governance framework, which addresses risk across various technology platforms. ARCON in the last one decade has been at the forefront of innovations in risk control solutions, with its roots strongly entranced in identifying business risk across industries it is in a unique position to react with innovative solutions/products.

Learn more about us at https://www.arconnet.com