Home > Security Tips > IAM Insights > Best practices for a privileged access policy to secure user accounts
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

IAM INSIGHTS

Best practices for a privileged access policy to secure user accounts


Mark Diodati, Contributor
06.09.2009
Rating: -3.50- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


The process of securing accounts includes a variety of factors, one of the most important being ensuring employees have the minimum access necessary to target platforms. In addition, employees' job functions and related access should be reviewed to ensure there are no separation of duties issues. Case in point: A person who creates a vendor account should not be able to approve payment to that vendor.

The access-review process includes understanding workflow: A baseline of access policies must be reviewed and approved by application owners. Additionally, subsequent changes to access rights should be reviewed and approved. Access certification tools, including those embedded in identity management provisioning systems from various vendors, can assist with the review process.

In some cases, a third-party security tool like CA Inc.'s Access Control or Symark International Inc.'s PowerBroker is required to limit privileged user access. For example, rather than giving the UNIX database administrator access to the root account for the purpose of restarting the server, the security tool can delegate the privilege of system restart to a real user.

Assuming you have locked down privileged user access, you should be all set, right? Not quite; you need to ensure privileged users do not abuse their access rights. One common use case concerns the customer support supervisor who appropriately has access to confidential customer data. If the supervisor accesses an excessive number of customer records on a given day, it may be an indication of a problem. A security information management (SIM) system would not likely detect this anomaly. Increasingly, enterprises are looking to deploy risk-based consumer authentication techniques to detect this level of access, b...



ut for the most part, these risk-based tools aren't ready for enterprise use because they are oriented toward financial transactions. Consumer authentication vendors with risk-based authentication include Hagel Technologies Ltd.'s AdmitOne, Arcot Systems Inc., Entrust, Oracle Corp., RSA Security and VeriSign Inc.

Some organizations consider the use of two separate accounts to address excessive user privilege. The first one is the "everyday" account for use in routine activities such as logging onto Windows workstations and checking email. The second account is only used for administrative tasks that require high privilege, including working with high-risk production systems. The high privilege account is not used during everyday tasks, which limits exposure to malware. However, the use of two accounts will not address the issue of excessive privileges granted to the user.

Balancing user access between the too lenient and the overly strict can be a challenge, but with these best practices, it can be a bit less daunting.

About the author:
Mark Diodati, CPA, CISA, CISSP, MCP, CISM, has more than 18 years of experience in the development and deployment of information security technologies. He has served as vice president of worldwide IAM for CA Inc., as well as senior product manager for RSA Security's smart card, SSO, UNIX security, mobile PKI and file encryption products. He has had extensive experience implementing information security systems for the financial services industry since starting his career at Arthur Andersen & Co. He is a frequent speaker at information security conferences, a contributor to numerous publications, and has been referenced as an authority on IAM in a number of academic and industry research publications.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
IAM Insights,   Password Management and Policy,   Enterprise Identity and Access Management,   Identity Management Technology and Strategy,   Enterprise User Provisioning Tools,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
IAM Insights
Content-aware IAM: Uniting user access and data rights
Security on a budget: How to make the most of authentication tools
Making the case for enterprise IAM centralized access control
Best practices: How to implement and maintain enterprise user roles
Kerberos configuration as an authentication system for single sign-on
How to use single sign-on for Web access control to prevent malware
Identity and access management 2009: Staff cuts, insider threats
Deleting user accounts: How to manage users during a layoff
The value of application whitelists
User provisioning: Emerging product features reveal market's future

Password Management and Policy
Two-factor authentication, vigilance foil password theft
Group to shed light on secure identity management threats
Brute force attacks target Yahoo email accounts
Best Identity and Access Management Products
Privileged account management critical to data security
Making the case for enterprise IAM centralized access control
How to prevent brute force webmail attacks
Mature SIMs do more than log aggregation and correlation
PCI compliance requirement 2: Defaults
PCI compliance requirement 8: Unique IDs

Enterprise User Provisioning Tools
Identity lifecycle management for security and compliance
Content-aware IAM: Uniting user access and data rights
Is Identity Management as a Service (IDaaS) a good idea?
Top tactics for endpoint security
How to edit group policy objects to give a user local admin rights
Privileged account management critical to data security
Making the case for enterprise IAM centralized access control
Lesson 3: How to implement secure access
Risk management must include physical-logical security convergence
PCI compliance requirement 7: Restrict access

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
graphical password  (SearchSecurity.com)
identity chaos  (SearchSecurity.com)
logon  (SearchSecurity.com)
masquerade  (SearchSecurity.com)
OpenID  (WhatIs.com)
salt  (SearchSecurity.com)
session replay  (SearchSecurity.com)
single-factor authentication (SFA)  (SearchSecurity.com)
TACACS  (SearchSecurity.com)
war dialer  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts