惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
D
Docker
Blog — PlanetScale
Blog — PlanetScale
罗磊的独立博客
美团技术团队
V
V2EX
Last Week in AI
Last Week in AI
D
DataBreaches.Net
T
The Blog of Author Tim Ferriss
宝玉的分享
宝玉的分享
Microsoft Security Blog
Microsoft Security Blog
Microsoft Azure Blog
Microsoft Azure Blog
人人都是产品经理
人人都是产品经理
M
MIT News - Artificial intelligence
P
Proofpoint News Feed
B
Blog RSS Feed
博客园_首页
B
Blog
博客园 - 叶小钗
I
InfoQ
WordPress大学
WordPress大学
L
LangChain Blog
Apple Machine Learning Research
Apple Machine Learning Research
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
A
About on SuperTechFans
The GitHub Blog
The GitHub Blog
The Register - Security
The Register - Security
MyScale Blog
MyScale Blog
云风的 BLOG
云风的 BLOG
博客园 - 司徒正美
Latest news
Latest news
W
WeLiveSecurity
T
The Exploit Database - CXSecurity.com
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
小众软件
小众软件
Cyberwarzone
Cyberwarzone
Scott Helme
Scott Helme
D
Darknet – Hacking Tools, Hacker News & Cyber Security
C
CERT Recently Published Vulnerability Notes
C
CXSECURITY Database RSS Feed - CXSecurity.com
Recent Commits to openclaw:main
Recent Commits to openclaw:main
N
News and Events Feed by Topic
S
Secure Thoughts
The Hacker News
The Hacker News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Google DeepMind News
Google DeepMind News

Insights

ChatGPT is the ultimate phishing tool, so why aren’t companies boosting security budgets? Absolute, Trellix team up to enhance endpoint security Overcoming the challenges faced by a modern-day SOC Top 3 trade-offs commonly encountered in identity security circles Cyber security in the Pacific: How island nations are building their online defences State sanctioned (cyber) violence, Australia’s next security threat Drawing a line in the sand for cyber conflict Automation: The future of the combat vehicle? Billion-dollar cyber boost: A cash cow for defence SMEs?
The linkages between privileged access management and zero trust
Scott Hesford · 2022-06-22 · via Insights

Most IT security teams are familiar with the concept of using traditional privileged access management (PAM) solutions to secure critical elements within their organisation’s technology infrastructure. PAM allows more granular control and visibility over who has authority to access certain resources, Scott Hesford at BeyondTrust writes.

Scott Hesford

Some IT professionals are now asking about the value of PAM within a zero-trust strategy.

To understand the purpose of zero trust, it’s important to know exactly what it delivers. Zero trust is not a technology or set of tools, but rather an entire security paradigm or framework. It works on the principle of least privilege – the concept and practice of restricting access rights for users, accounts, and computing processes to only those resources absolutely required to perform authorised activities. Never trust, always verify, is the mantra.

You’re out of free articles for this month

To continue reading the rest of this article, please log in.

Within a zero-trust environment, both devices and users must be authenticated before being granted access permission. The approach is very familiar in the world of protecting IT assets that sit outside an organisation’s tradition perimeter, such as remote workers and cloud-based resources. But zero-trust applies to all users and devices, regardless of where they reside and assumes they are a potential attacker until they prove otherwise.

Managing authorisations – who can do what and where – is an essential ingredient of the “Never trust, always verify” mantra that guides zero trust. Modern PAM is the key to managing authorisations at disparate levels because it can enforce authorisations on how systems are accessed and then apply granular controls on administrative tasks, applications or services running on workstations or servers. Many organisations have even implemented the use of granular endpoint management functions such as application control for regular employees on workstations before applying access controls to servers via traditional PAM. This in turn lowers their overall attack surface.

For this reason, modern PAM, which entails privileged account and session management (PASM), privilege elevation and delegation management (PEDM) and secure remote access are key enablers to a successful implementation of a zero-trust strategy.

Implementing a zero-trust strategy

A popular analogy used when discussing zero-trust is a person boarding an aircraft. That person will firstly be checked and scanned as they walk through security. They will be checked again before being allowed to board the aircraft and yet again once inside the plane as they make their way to their seat.

This process of constant checking is exactly what modern PAM achieves in a zero-trust environment. Users and devices will be constantly challenged to prove that they are who they claim to be and that they have the right to do what they want. Traditional PAM can provide restriction about the zero trust path you take. However, another advantage of modern PAM encompassing Password Safe and Endpoint Privilege Management from BeyondTrust is the flexibility to start with your own priorities around zero trust. Want to start with PEDM rather than PASM? That flexibility is available.

When undertaking a zero-trust strategy, there are some key steps that will need to be taken. These steps include:

  • Gain senior management support:
    The planned strategy will have an impact on all areas of the business, and so it is vital that support is obtained from the top. Brief senior leaders on what is required and the benefits it will deliver.
  • Review the proposed architecture:
    No two zero trust deployments are the same. It’s therefore important to allow all parties involved to review the proposed architecture to ensure it will meet their requirements. This will minimise the likelihood of problems during the deployment process.
  • Assess internal IT skills:
    While some organisations will have the skills needed for a successful deployment in-house, others will need to look for external assistance. Assess the capabilities of your internal IT team before work begins.
  • Check the credentials of chosen technology vendors:
    The term zero trust has been adopted by a large number of technology companies that use it to promote a diverse range of technologies and tools. Carefully assess what a vendor is actually able to deliver before signing a deployment contract.
  • Undertake a rollout:
    It should be remembered that a zero-trust strategy is a journey and not a big bang deployment. Many organisations find it more beneficial to take a staged approach and add additional components and capabilities over time.
  • Conduct ongoing reviews:
    Zero trust is not a set-and-forget item but rather something that will require ongoing management and review. Check that everything is operating as it should and where and when adjustments might be required.

Modern PAM provides valuable tools for a security team’s zero-trust toolbox. Understanding its role in achieving the principle of least privilege will help you to maximise your investment as part of a zero-trust strategy.

Scott Hesford is director of solutions engineering, Asia-Pacific and Japan, BeyondTrust.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.