Govern Access, Not Just Identities (via InfoRisk Today)

November 9, 2016

InfoRisk Today has a great video interview with Andy Vallila.  The second half of the video is mostly a sales pitch for Dell Security Solutions, but the first half highlights an often overlooked aspect of access management: system accounts.

The main takeaway is that organizations typically have a focus protecting and managing end-user accounts.  However, IT departments often overlook protecting system accounts because “they’re only used by IT”. At many of my clients, IT managers do not know how the accounts are used and therefore are afraid to disable them because it could cause a production outage.  However, these highly-privileged accounts are often the accounts exploited during an attack.  The video is definitely worth a watch if your company isn’t doing something about protecting these types of accounts.