Privileged Access Management as a priority task in information security (using Fudo PAM as an example)

Privileged Access Management as a priority task in information security (using Fudo PAM as an example)

There is quite an interesting document CIS Controls, which addresses Information Security using the Pareto principle (80/20). This principle states that 20% of security measures provide 80% of the result in terms of the company’s protection. Many security professionals find that when selecting security measures, they do not start with the most effective ones. The document highlights 5 key protective measures that have the most significant impact on Information Security:

  1. Inventory of all devices in the network. It's hard to protect a network when you don’t know what’s in it.
  2. Inventory of all software. Software with vulnerabilities often becomes the entry point for hackers.
  3. Secure Configuration — or the mandatory use of built-in security features of software or devices. In short, change default passwords and restrict access.
  4. Vulnerability scanning and remediation. Most attacks start with known vulnerabilities.
  5. Privileged Access Management. Your users should only have the rights they really need and perform only the actions that are absolutely necessary.

In this article, we will specifically discuss the 5th point using Fudo PAM. More precisely, we will examine typical cases and issues that can be identified after implementation or during a free trial of Fudo PAM.

Fudo PAM

Just a few words about the solution. Fudo PAM is a relatively new privileged access management solution. Key features include:

  • Session recording. Real-time session viewing. Connection to sessions. Creating evidence for legal proceedings.
  • Proactive monitoring. Flexible policies. Pattern searching. Action automation.
  • Threat alerts. Unauthorized account usage. Threat level assessment. Anomaly detection.
  • Identification of responsible parties. In case a single account is used for login by multiple users.
  • Effectiveness analysis. For individual users, departments, or entire organizations.
  • Precise access control. Traffic limitation and access for users during specific time intervals.

And the biggest advantage — it can be deployed literally within a couple of hours, after which the system is ready for use.

For those interested in the product, a webinar will be held with a detailed overview and demonstration of the functionality. We will move on to real issues that can be discovered in pilot projects of privileged access management systems.

1. Network administrators regularly gain access to prohibited resources

Strangely enough, the first incidents that are discovered involve violations by administrators. Most often, this means unauthorized changes to access lists on network equipment. For example, to allow access to a prohibited website or application. It should be noted that such changes can remain in the equipment’s configuration for years.

2. One account is used by multiple administrators

Another common issue related to administrators. Sharing one account among colleagues is a frequent practice. It is convenient, but afterward, it becomes quite difficult to determine who is responsible for specific actions.

3. Remote employees work less than 2 hours a day

Many companies have remote employees or partners who need access to internal resources (most often, remote desktop). Fudo PAM allows monitoring real activity during such sessions. It is often found that remote employees work much less than reported.

4. The same password is used across multiple systems

This is a significant problem. Remembering several passwords is always challenging, so users often use a single password for all systems. If this password leaks, a potential intruder can gain access to almost the entire IT infrastructure.

5. Users have more rights than expected

It is often found that users who seemingly have limited rights actually possess greater privileges than they should. For example, they can reboot a controlled device. Typically, this is either an error in the permissions granted or simply flaws in the built-in rights management system.

Webinar

If you are interested in the topic of PAM, we invite you to the upcoming webinar on Fudo PAM, which will take place on November 21.

This is not our last webinar of the year that we plan to hold, so stay tuned for updates (Telegram, Facebook, VK, TS Solution Blog)!

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster