TMCnews Featured Article
Enterprise Password Management Includes Privileged Passwords, So Be Careful
By David Sims, TMCnet Contributing Editor
Thycotic, a provider of secure software products recently produced a white paper entitled, “Are Privileged Passwords Your Weakest Link?” which details a key issue for enterprise password management—privileged passwords.
As enterprise password management professionals know, privileged accounts “can do practically anything on the network with no accountability and the passwords are often known by many IT team members,” as Thycotic officials explain, adding that IT administrators “need access to these accounts to perform certain tasks, and they need to share these credentials among the infrastructure team.”
Of course, you can imagine the problems that would arise should someone breach these accounts. Actually you don’t need to use your imagination – just follow the news of grisly corporate security breaches. Chances are compromised privileged passwords are behind many of them.
Breaching privileged accounts lets attackers “enable malicious network attacks that could result in denial of service, exposure of private information, or any other nightmare scenario that a hacker or disgruntled employee could imagine,” the paper added.
Again, you probably shouldn’t have to tax your imagination too hard to envision what a disgruntled employee could do with a privileged account password. And it’s dangerous changing these passwords, the paper says, since “all of the services that run with the particular service account use the same password, and every one must be updated with the new password. If even one location is missed, then that service will lock out the account,” essentially stopping all the services from using the account.
However, it’s also dangerous not to change the passwords. You knew it wasn’t going to be easy, right? Keeping the same passwords allows not only vulnerability to password cracking tools, the white paper says, but exposes organizations to internal risks. Let’s face it, infrastructure employees come and go. Plus, many large organizations require periodic password changes. Therefore, taking no action at all is simply not an option.
The paper recommends, among other approaches, using an enterprise password vault with certain specific requirements. “Encryption should be standard with the vault and should also include identity access control and full auditing capabilities.”
In addition, controlling access to stored sensitive information should be simple as
“organizations should have the ability to give employees permission to only view information pertinent to their respective jobs. Role-based access control is also needed to match responsibilities to capabilities for role management within the organization.”
Some other basic features include the ability to restrict access, require approval for access, and state a time limit on access.”
It is clear that proper enterprise password management is essential in order to safeguard privileged passwords.
Want to learn more about the latest in communications and technology? Then be sure to attend ITEXPO West 2011, taking place Sept. 13-15, 2011, in Austin, Texas. ITEXPO (News - Alert) offers an educational program to help corporate decision makers select the right IP-based voice, video, fax and unified communications solutions to improve their operations. It's also where service providers learn how to profitably roll out the services their subscribers are clamoring for – and where resellers can learn about new growth opportunities. To register, click here.
David Sims is a contributing editor for TMCnet. To read more of David’s articles, please visit his columnist page. He also blogs for TMCnet here.
Edited by Jamie Epstein


