This involves just-in-time and just-enough privileges being granted and then automatically deleted. What’s the result? Zero standing privileges, so your digital vault is not required for operational digital privileged accounts. More and more PAM and IAM solutions are offering this. It’s a highly effective security solution, although you do need to bear a number of things in mind.
Every organization has to deal with privileged accounts. These are digital identities with more privileges, which are used to work on systems, applications and confidential information. These are an organization’s crown jewels and are highly sought after by hackers.
In their rapidly changing IT landscape, organizations face an explosion of privileged accounts. Internal and external teams want to have privileged access from every location and device, and no longer just for assets within their own infrastructure, but also for cloud-based assets.
Privileged accounts are often created on a permanent basis. To secure access to, and management and usage of privileged accounts, many organizations employ privileged access management (PAM) solutions. Traditionally, privileged accounts are securely and centrally locked away in a digital vault.
While a PAM solution reduces the risk of privileged accounts being abused, they remain in existence for all time. These are the standing privileges. The implicit idea behind them is that the PAM solution can be trusted.
The concept of implicit trust is at odds with the principle of zero trust, which is all about explicit trust. In other words, every use requires re-authentication. Modern PAM (and IAM) solutions can operate under what is known as the zero standing privileges principle, which is in line with the principle of least privilege.
With zero standing privileges, tasks are assigned based on just-in-time and just-enough privileges. In other words, the privileges are only valid for a set time and only with the rights that are strictly necessary for a specific asset.
When an administrator needs to carry out operational work and requires appropriate rights, then he or she submits a request through the PAM (or IAM) system. If the requester meets the requirements to obtain access to the necessary admin rights for the asset, then this is defined according to attribute-based access control (ABAC) As soon as the request is approved, the PAM system creates a temporary privileged account. This is valid only for the asset and for the period specified in the request.
Zero standing privileges are granted through ephemeral access. As soon as the period has elapsed, the user is logged off and the privileged account is automatically removed. The PAM system automatically records who had access to which asset and when in a full audit log. The absence of zero standing privileges prevents misuse. After all, there is no account present that can be hacked. The ephemeral privileged account is created in such a way that it can be recognized in log files and the SIEM system.
Applying zero standing privileges to operational accounts through ephemeral access is the new standard in privileged access management. More and more PAM and IAM solutions also offer this feature, allowing you to protect your organization even more effectively against cyber attacks.
We recommend keeping track of the system and application accounts used in your organization. These kinds of privileged accounts will persist through standing privileges and will therefore need to be secured using the traditional PAM method. You should therefore store these accounts centrally and securely in a digital vault and apply password management to them. When selecting a product for granting privileged access, then it is wise to consider this.
Read more about PAM here.
Traxion is part of the SITS group. With over 700 employees, SITS Group combines the experience, expertise, resources and services of a top-class IT security provider to form a comprehensive whole. Read more here