{"id":2109,"date":"2020-04-06T14:05:35","date_gmt":"2020-04-06T10:05:35","guid":{"rendered":"https:\/\/techxmedia.com\/?p=2109"},"modified":"2025-04-17T23:59:21","modified_gmt":"2025-04-17T19:59:21","slug":"journey-universal-privilege-management","status":"publish","type":"post","link":"https:\/\/techxmedia.com\/en\/journey-universal-privilege-management\/","title":{"rendered":"The journey to Universal Privilege Management"},"content":{"rendered":"\n<p><strong><em>Author: Karl Lankford, Director \u2013 Solutions Engineering, BeyondTrust<\/em><\/strong><\/p>\n\n\n\n<p>Almost without\nexception, today\u2019s threat actors leverage readily available automated tools \u2014\nautomation increases the speed and probability that the attacker can find and\nexploit that initial weak link that gives them a \u201chook\u201d into an environment. <\/p>\n\n\n\n<p>The good news is\nthat organizations increasingly recognize that to maintain a level playing\nfield, they need automation and purpose-built solutions to protect privileges,\nand PAM has become a cornerstone of an effective, modern cybersecurity defense.\nThe bad news is that many organizations mistakenly presume that privileged\npassword management alone will solve the problem, when it\u2019s only one part of a\nnecessary, comprehensive PAM solution.<\/p>\n\n\n\n<p><strong>Universal Privilege\nManagement (UPM)<\/strong><\/p>\n\n\n\n<p>The Universal\nPrivilege Management model allows enterprises to start with the PAM use cases\nthat are most urgent to the organization, and then seamlessly address remaining\nuse cases over time. Each use case, once addressed, will give enhanced control\nand accountability over the accounts, assets, users, systems, and activities\nthat comprise the privilege environment, while eliminating and mitigating\nmultiple threat vectors. The more use cases that are addressed, the more PAM\nsynergies emerge, and the more impact organizations will realize in reducing\nenterprise risk and improving operations. <\/p>\n\n\n\n<p>So here are the 10\nuse cases on your journey to UPM.<\/p>\n\n\n\n<p><strong>Accountability <\/strong><\/p>\n\n\n\n<p>While not mandated,\nmany organizations find discovering and securing privileged accounts the\nlogical starting point for improving privilege security controls. But this\ndemands a privileged credential management solution that automatically\ndiscovers and onboards the ever-expanding list of privileged\naccounts\/credential types and brings those under management within a\ncentralized password safe. This includes both human (employee, vendor) and\nnon-human (functional, service, application, software robot, etc.) accounts in the\nenvironment. <\/p>\n\n\n\n<p>The solution should\nallow control over which accounts are being shared, by whom, when, where, and\nwhy. It should provide mechanisms to find hardcoded credentials and deliver\noptions to replace them with managed credentials. Critically, the solution\nshould monitor, manage, and audit every privileged session regardless of where\nit originates.<\/p>\n\n\n\n<p><strong>Least privilege on desktops<\/strong><\/p>\n\n\n\n<p>Another important\nstep to achieving Universal Privilege Management is implementing least\nprivilege on end-user machines. Least privilege is defined as, \u201cthe minimum\nprivileges\/rights\/access necessary for the user or process to be fully\nproductive.\u201d <\/p>\n\n\n\n<p>With a\nleast-privilege approach, users receive permissions only to the systems,\napplications, and data they need for their current roles. Rather than being\nenabled, persistent, and always-on, the privileges are only elevated on an\nas-needed basis and only for the targeted application or process. This is the\nbasis for a just-in-time (JIT) PAM model. <\/p>\n\n\n\n<p><strong>Least privilege on servers\n<\/strong><\/p>\n\n\n\n<p>Organizations must\nlimit, control, and audit who has access to superuser accounts and privileges,\nwithout impairing productivity. Organizations must be able to efficiently and\neffectively delegate server privileges without disclosing the passwords for\nroot, local, or domain administrator accounts. They should record all\nprivileged sessions to help meet regulatory compliance. This is conceptually\nlike the removal of administrative rights on desktops, but with the added\nrequirements of supporting server-class operating systems in Tier-1 regulated\nenvironments.<\/p>\n\n\n\n<p><strong>Application reputation\n<\/strong><\/p>\n\n\n\n<p>Another application\nreputation capability involves empowering organizations to make better informed\nprivilege elevation decisions by understanding the vulnerability of an\napplication or an asset with which it interacts. Applying real-time risk\nintelligence to privilege delegation and elevation not only stops exploits from\nbecoming a privileged attack vector, but it also blocks drive-by social\nengineering threats that can leverage vulnerabilities within the environment.\nSimilar to application control on Windows, command filtering on Unix and Linux\nis a critical security, compliance, and reliability control. For both\napplication control and command filtering, a full audit trail of everything, attempted\nand allowed, is important. <\/p>\n\n\n\n<p><strong>Remote access<\/strong><\/p>\n\n\n\n<p>The vast majority of\nremotely launched attacks come from threat actors who are not specifically\ntargeting the organization, but rather through remote contractors, vendors,\nand, even remote employees, who have themselves been compromised. <\/p>\n\n\n\n<p>The ideal defense is\nto extend PAM best practices beyond the perimeter. This ensures only the right\nidentity has access to the right resources in the right context. It eliminates\n\u201call or nothing\u201d remote access for vendors by implementing least-privilege\naccess to specific systems for a defined duration of time, potentially\nrequiring a chaperone when appropriate. <\/p>\n\n\n\n<p>Vendor credentials\nshould be managed through the solution with policies, mandating rotation or\nsingle use passwords, and utilizing credential injection in sessions so that\npasswords are never exposed to end users. <\/p>\n\n\n\n<p>Finally, session\nmanagement and monitoring should be enforced to audit and control all\nvendor\/remote access activity. This approach is far more secure than\ntraditional protocol routing technologies like VPN.<\/p>\n\n\n\n<p><strong>Network devices and\nIoT<\/strong><\/p>\n\n\n\n<p>Many PAM tools lack\nthe ability to extend granular privileged access controls to non-traditional\nendpoints, such as medical or industrial-connected devices and control systems.\n<\/p>\n\n\n\n<p>Organizations need a\nsolution that delivers the capability of least privilege to those endpoints by\nallowing fine-grained control over the commands sent and the responses received\nover SSH sessions. This offers the ability to control the operation of\nfunctions like tab completion, restricting access to only those aspects of the\nendpoint that are appropriate for the user. Administrators and vendors can be\nconstrained within their area of responsibility without impacting their\nproductivity.<\/p>\n\n\n\n<p><strong>Cloud and\nvirtualization<\/strong><\/p>\n\n\n\n<p>With the accelerated\nuse of virtualized data centers and cloud environments for processing, storage,\napplication hosting and development, organizations have opened new avenues for\nthreat actors to access sensitive data and cause disruption. <\/p>\n\n\n\n<p>From a privileged\naccess management perspective, the options to secure these assets are like\ntraditional desktops and servers as described earlier. However, here are a few\nunique privileged security use cases for the cloud:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Utilize a password management solution to manage the passwords and\nkeys that are unique to the cloud environment, like the hypervisor, APIs, and\nmanagement consoles.<\/li><li>Implement a PAM solution with session monitoring for all\nadministrative or root access into cloud providers, regardless of whether they\nare SaaS, PaaS, or IaaS-based.<\/li><li>When performing RPA or variations on DevOps, utilize a password\nmanagement or secrets store to protect application-to-application secrets used\nin the cloud<\/li><\/ul>\n\n\n\n<p><strong>DevOps and DevSecOps<\/strong><\/p>\n\n\n\n<p>DevOps delivers\ncondensed development and deployment cycles through automation, frequently\nleveraging the scale of the cloud. The downside is that DevOps processes can\nalso \u201cautomate insecurity,\u201d creating massive risks as well as compliance and\noperational gaps.<\/p>\n\n\n\n<p>The right solution\ncan discover all privileged automation accounts (including for CI\/CD tools,\nservice accounts, RPA, etc.) and replace the credentials with trusted API\ncalls. The automatic retrieval and injection of the proper tool credentials\nhelps protect developers, operations teams, and applications from attacks when\nprivilege accounts are used for automation.<\/p>\n\n\n\n<p><strong>Privileged account integration\n<\/strong><\/p>\n\n\n\n<p>Modern PAM solutions\nmust communicate with the rest of the IT security environment. By unifying\nprivileged access management and other IT and security management solutions, IT\nteams benefit from a single, contextual lens through which to view and address\nrisk by activity, asset, user, identity, and privilege. <\/p>\n\n\n\n<p><strong>Identity Access\nManagement (IAM) integration<\/strong><\/p>\n\n\n\n<p>Access to an\norganization\u2019s resources is ideally managed through an IAM solution, which\noffers capabilities such as single sign-on, user provisioning\/deprovisioning,\nrole-based user management, access control, and governance. But managing a\nheterogeneous environment that contains silos for Unix, Linux and macOS, plus a\nMicrosoft or cloud environment, leads to inconsistent administration for IT,\nunnecessary complexity for end users, and a vast sprawling of alias accounts. <\/p>\n\n\n\n<p>The ideal solution\nis to centralize identity management and authentication and provide single sign\non across Windows, Unix, Linux, and macOS environments by extending a directory\nstore like Microsoft\u2019s Active Directory with single sign-on capabilities to non-Windows\nplatforms.<\/p>\n\n\n\n<p>By evolving PAM\ncapabilities using this UPM model, organizations will not only reduce the\nthreat surface, eliminate security gaps, improve response capabilities, and\nease compliance, but will also deter many attackers, who are still largely\nopportunistic in seeking to exploit the easiest prey.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Universal Privilege Management model allows enterprises to start with the PAM use cases that are most urgent to the organization, and then seamlessly address remaining use cases over time. <\/p>\n","protected":false},"author":8,"featured_media":1669,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[154,149],"tags":[570,1072,1077,879,941,1076,1069,673],"contributor":[],"class_list":["post-2109","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-computing","category-networking","tag-beyondtrust","tag-cloud","tag-network_devices","tag-remote_access","tag-server","tag-universal_privilege_management","tag-upm","tag-virtualisation"],"featured_image_src":"https:\/\/techxmedia.com\/en\/wp-content\/uploads\/2020\/03\/Karl-Lankford-Director-Solutions-Engineering-BeyondTrust-e1586167420606.jpg","author_info":{"display_name":"Rabab","author_link":"https:\/\/techxmedia.com\/en\/author\/rabab\/"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/2109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/comments?post=2109"}],"version-history":[{"count":0,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/posts\/2109\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media\/1669"}],"wp:attachment":[{"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/media?parent=2109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/categories?post=2109"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/tags?post=2109"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/techxmedia.com\/en\/wp-json\/wp\/v2\/contributor?post=2109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}