The 7 Layers of Privileged Access Management

27
The 7 Layers of Privilege Management -Anirban Banerjee, Ph.D. [email protected]

Transcript of The 7 Layers of Privileged Access Management

Page 1: The 7 Layers of Privileged Access Management

The7LayersofPrivilegeManagement

-AnirbanBanerjee,[email protected]

Page 2: The 7 Layers of Privileged Access Management

HELLO!IamAnirbanBanerjee.FounderandCEOofOnionID.

https://www.linkedin.com/in/anirbanbanerjeephd

Page 3: The 7 Layers of Privileged Access Management

Current Status

Challenges

Solutions

Page 4: The 7 Layers of Privileged Access Management

Current Status

4

Page 5: The 7 Layers of Privileged Access Management

Laptops In house servers

Mobile devices

Cloud Servers

The Landscape is ChangingITLandscape

Page 6: The 7 Layers of Privileged Access Management

• Shift in Capex to Opex• Cost savings – 25% on avg.

• Employee Mobility• Easy access – 49% on avg.

• Scaling is easier• More efficient – 55% on avg.

• Time savings• More time to innovate – 31% on avg.

• Choice – no traditional vendor lock in

WhyistheCloudPopular

Page 7: The 7 Layers of Privileged Access Management

SAML&SaaS

• Less than 25% of corporate apps have SSO support• Less than 1% of all SaaS apps understand SAML• Passwordsareheretostay!

Page 8: The 7 Layers of Privileged Access Management

MappingUserRoles

• How to map to 3rd party SaaS apps?• SAML assertions - weak support.• Nomagicbullet

Page 9: The 7 Layers of Privileged Access Management

What is Privilege

9

Page 10: The 7 Layers of Privileged Access Management

PrivilegeManagementisnotjustAccessControl

PrivilegeManagement

Page 11: The 7 Layers of Privileged Access Management

PAM- 100%Coverage

Web Apps Servers and Containers

Page 12: The 7 Layers of Privileged Access Management

PAM- LayersShrek: Ogres are like onionsDonkey: They Stink?

Shrek: Yes. No.Donkey: Oh.....they make you cry

Shrek: No!Donkey: Oh, you leave 'em out in the sun, they get all brown, start sproutin' little white hairs

Shrek: NO. Layers. Onions have layers. Ogres have layers. Onions have layers. You get it? We both have layers. [sigh]Donkey: Oh, you both have layers.Oh.

PAM has layers. Onions have layers. We both have layers. Get it?

Page 13: The 7 Layers of Privileged Access Management

PAM- The7Layers

2FA on Apps and Servers

SaaS PAM

SSH Session Control

Secret Storage

Access sharing

Reporting and Audits

Server PAM

Page 14: The 7 Layers of Privileged Access Management

EvolutionofPAM

PAM 1.0Crawl

• Password Vaulting• SSH Key Rotation• Video-session Recording

PAM 2.0Walk

• Rights Management• Time based checkout• Credential rotation

PAM 3.0Run

• SaaS PAM• Adaptive authentication• Automated auditing

Page 15: The 7 Layers of Privileged Access Management

Challenges

15

Page 16: The 7 Layers of Privileged Access Management

q PrivilegedAccessManagement§ Fullcontroloverwhohasaccesstowhatandwhen.§ RealtimeandIntuitive

HardProblems

Page 17: The 7 Layers of Privileged Access Management

q Vigilance§ Keeptrackofuseractivity§ Receivealertsforanomalousbehavior§ Gaincompletevisibilitythroughdetailedreports

HardProblems

Page 18: The 7 Layers of Privileged Access Management

q Secretsmanagement§ API/MachinetoAPI/Machineauthentication§ APIkeysincode

HardProblems

Page 19: The 7 Layers of Privileged Access Management

q ReportsandAuditing§ Complianceiscomplex,disparatesystems§ Continuousauditingisnecessary

HardProblems

Page 20: The 7 Layers of Privileged Access Management

Strategies

20

Page 21: The 7 Layers of Privileged Access Management

Layer on top of existing services

Dynamic Privilege Management

SSO NAC CASB

Deployment

Page 22: The 7 Layers of Privileged Access Management

User Fatigue

2FA=Friction

• Entering 8 Digit Codes

• Carrying Hardware• One time Passwords• Multiple IDs

Page 23: The 7 Layers of Privileged Access Management

HappyUsers

2FA≠Friction

Air-Signature

Touch ID

Proximity

Geo Fencing

Page 24: The 7 Layers of Privileged Access Management

What can an employee see

What can an employee click

What can an employee fill

What can an employee download

UseCase

Page 25: The 7 Layers of Privileged Access Management

Command Filtering

SSH Key Management

Session Recording

URL Filtering

Action Filtering

View Filtering

Solution

Page 26: The 7 Layers of Privileged Access Management

Conclusion

2FA on Apps and Servers

SaaS PAM

SSH Session Control

Secret Storage

Access sharing

Reporting and Audits

Server PAM

q FineGrainedControl- SaaSPAMisimportant.

q Sessionrecordingforcomplianceandsecurity.

q Secretsmanagement- isanemergingarea.

q ReportsandAuditing- needcontinuousprocess.

q Simplify2FAExperience- reducefriction.

Page 27: The 7 Layers of Privileged Access Management

[email protected]: +1-888-315-4745

https://www.linkedin.com/in/anirbanbanerjeephd