Home > Security Tips > IAM Insights > The steps of privileged account management implementation
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

IAM INSIGHTS

The steps of privileged account management implementation


Mark Diodati, Contributor
07.24.2008
Rating: -4.12- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


This tip is part of the SearchSecurity.com Identity and Access Management Security School lesson on the 'new school' of enterprise authentication . Visit the New school of enterprise authentication lesson page for additional learning resources.

A standard part of the application installation process -- be it an operating system, database or other application platform -- is the creation of privileged accounts. Similar to Unix's root and Windows' administrator accounts, privileged accounts are required for platforms to function and are frequently used by system administrators to do their jobs, granting special privileges that average users don't need, and that even administrators need only from time to time when making major changes. Privileged accounts, however, have no accountability, as they do not belong to real users and are commonly shared by many people.

So why should you care about these boring, hum-drum privileged accounts? Because these accounts have elevated access rights, meaning those with access can bypass the internal controls of the target platform. Once these controls are bypassed, users can breach confidential information, change transactions and destroy audit data.

Need another reason? The security of privileged accounts is likely at the top of your compliance auditor's concerns. This tip will offer an introduction to the technology available for managing the security of privileged accounts, and best practices to consider when developing an implementation strategy.

What is privileged account management?
Privileged account management products can help secure these overarching accounts. Such products control access to privileged accounts by (1) enforcing the checkout (that is, retrieval) of the account's password and (2) changing the password frequently. The products can be configured to change the password periodically (for exam



ple, every few hours) or every time the password is checked out.

Privileged account management products provide two password-checkout modes: interactive and programmatic. With interactive checkout, the system administrator authenticates to the privileged account management portal, receives the privileged account management password, and then logs on to the target platform (examples include telnet and Remote Desktop Protocol). Conversely, batch jobs, scripts and services check out passwords programmatically. With this method, the privileged account management product locally installs middleware, which can retrieve the credentials for the batch job or script. In the basic use case, the privileged account password is removed from the script or batch job and replaced with a few lines of code to retrieve the privileged account password when needed.

Privileged account management vendors include Cloakware Inc. (a subsidiary of Irdeto Access B.V.), Cyber-Ark Software Inc., Lieberman Software Corp., Passlogix Inc. and Symark International Inc.

Recommendations

Here are a few key points enterprises should consider when choosing and preparing to implement privileged account management technology.

Enterprises have struggled with the scalable security of privileged accounts for decades. These accounts are created upon installation and are shared by many people in order to do their job. These powerful accounts can access sensitive data because they bypass most of the platform's security controls. Today's privileged account management products can limit account access to authorized personnel. However, privileged account management products don't provide everything an organization might need in the event of a forensic investigation, so look into SEIM, provisioning (or LDAP), and similar security tools to finish the job.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
IAM Insights,   Two-Factor and Multifactor Authentication Strategies,   Enterprise Identity and Access Management,   User Authentication Services,   Identity Management Technology and Strategy,   Enterprise User Provisioning Tools,   Identity and Access Management Security School,   The new school of enterprise authentication,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
IAM Insights
Best practices for a privileged access policy to secure user accounts
Best practices: How to implement and maintain enterprise user roles
Kerberos configuration as an authentication system for single sign-on
How to use single sign-on for Web access control to prevent malware
Identity and access management 2009: Staff cuts, insider threats
Deleting user accounts: How to manage users during a layoff
The value of application whitelists
User provisioning: Emerging product features reveal market's future
Trends in enterprise identity and access management

Two-Factor and Multifactor Authentication Strategies
PCI compliance requirement 7: Restrict access
PCI compliance requirement 9: Physical access
Best practices: How to implement and maintain enterprise user roles
Changing times for identity management
RSA researcher Ari Juels: RFID tags may be easily hacked
Apple iPhone app could boost two-factor
CA steers DLP towards access, identity management
PKI and digital certificates: Security, authentication and implementation
Security token and smart card authentication
Enterprise single sign-on: Easing the authentication process

Enterprise User Provisioning Tools
Best practices for a privileged access policy to secure user accounts
Risk management must include physical-logical security convergence
PCI compliance requirement 7: Restrict access
PCI compliance requirement 8: Unique IDs
Using IAM tools to improve compliance
Best practices: How to implement and maintain enterprise user roles
Enterprise password management policy: Finding the balance
Ease the compliance burden with automation
In Oracle-Sun deal, analysts predict identity management fallout
Kerberos configuration as an authentication system for single sign-on

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
AAA server  (SearchSecurity.com)
authentication  (SearchSecurity.com)
authentication, authorization, and accounting  (SearchSecurity.com)
federated identity management  (SearchSecurity.com)
Kerberos  (SearchSecurity.com)
password hardening  (SearchSecurity.com)
typeprint analysis  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts