Identity consolidation and privileged access management across Windows, Linux, and UNIX serversEnterprise Edition
Detailed auditing of privileged user sessions on Windows, Linux and UNIX systemsPlatinum Edition
Dynamically segment and isolate cross-platform systemsApplication Edition
Secure, centralized single sign-on to on-premise business applications
Single sign-on and unified management for cloud and mobile apps and devicesMac Edition
Centralized security and management for Macs and mobile devicesPremium Edition
SaaS and Mac Editions combined with mobile security managementCentrify for Samsung KNOX
Enterprise management of SSO, MCM and MDM for Samsung KNOX
Tuesday, March 3, 2009
I have been beating the drum a bunch lately on privileged user management ("PUM" — the expression Forrester uses) aka superuser privilege management ("SUPM" — the expression Gartner uses) aka privileged account management ("PAM" — the expression Burton Group uses). Check out my recent blogs on this topic: overview of the problem, how the recent Fannie Mae security incident was in all likelihood caused by not having this capability in place, and how a recent court ruling is not showing any love to companies negatively impacted by this problem. Well Gartner has just weighed in again on this topic in a just published report, and in this blog post I will give you some of my thoughts on the report and also discuss a recent article that I wrote on this subject that was published on LinuxInsider.com.
But first, what is superuser privilege management and why is this an issue that needs to be addressed in IT organizations? This issue arises from that fact that most operating systems, applications and databases have an administrative account to enable installation, configuration, administration and management of those platforms. And most large organizations have multiple personnel that need to administer Windows or UNIX systems ("the sys admins"), multiple personnel that administer their Oracle or DB2 databases ("the DBAs"), and multiple personnel who either develop applications ("the developers") and/or administer applications ("the app admins"). This means that, in effect, there are multiple people that have "keys" (i.e. administrative access) to these "doors" (i.e. systems and applications) and the valuable information that reside behind those doors.
As Gartner notes on page 2 of this presentation, organizations need to worry about important things such as (and the bullets below are direct quotes from the slide):
Gartner has further weighed in on this topic with the publication of a new report entitled "Superuser Privilege Management Tools for IBM i, Unix and MS Windows Server Operating Systems" (Gartner report #G00164893). Authors Perry Carpenter and Ant Allan summarize the heart of the overall problem by saying that "accidental misuse and deliberate abuse of superuser privileges [can] yield critical compliance and privacy risks with potentially severe financial and reputational impacts."
The report not only describes which tools exists to enable SUPM on the various platforms (including the Centrify Suite) but also discusses how SUPM tools can manage authorization by controlling privileges (e.g. commands that are allowed), by controlling scope (on what resources and systems), by controlling access time (e.g. midnight to 3 a.m. or just on weekends), or through a combination of the above.
The permissions and restrictions described above are exactly what DirectAuthorize can enable. DirectAuthorize does this via roles and rights. A role is a logical job function (e.g. backup operator, DBA, web developer, application administrator, etc.) that carries with it specific rights that are needed to perform duties within a role. Rights describe both access methods and privileges, specifically:
Roles are defined for a DirectControl Zone, which is a logical collection of DirectControl-managed systems. Active Directory users or groups can be assigned to one or more roles. A role assignment can apply to all computers in a Zone, or to a specific computer. For example, in the Engineering Zone the user Fred could be assigned the system administrator role for all computers, and also be assigned a DBA role for a single database server. Thus, roles are a flexible and scalable method for defining users' access methods and privileges for a specific set of systems.
One of the key recommendations from the Gartner report that I found most interesting was their recommendation that IT organizations should "Favor products that ... exploit existing infrastructure components (to reduce cost and to simplify implementation and maintenance)." Ironically, the only vendor and product that Gartner documented that leverages an existing de facto standard infrastructure was Centrify and our Centrify Suite, which leverages a customer's pre-existing Active Directory deployment. Unlike all the other SUPM solutions that typically store their policy data in proprietary data stores and/or leverage proprietary administrative servers, the Centrify Suite stores its policy management capabilities (to enable role-based access control and authorization) directly in Active Directory. And our solution is the only solution for *nix that provided the ability to cache locally the policies.
Finally, be sure to check out my article on superuser privilege management on LinuxInsider.com — it was only coincidence that my article and Gartner's report were published the same week, but indicative of the relevance and importance of the topic.