Windows IT Pro Product Review: Viewfinity Privilege Management

by Mary Rose 25. April 2012 15:24

Eric B. Rux of Windows IT Pro published a recent product review recognizing common challenges  IT adminstrators encounter with software deployment, permission policy, time management and supporting end user requirements.

Eric stated “Viewfinity Privilege Management takes the work out of discovering the permissions that each application needs to function correctly. It also gives you the option of letting users install software on their own, while you still maintain control -- all from an easy-to-manage console.”

Rux’s overview and product summary as cited below:

For the most part, the GPO Editor and SaaS editions of Privilege Management function identically. They divide the applications that your users need to run into two groups:

  • Applications that are currently installed; these applications are managed with applied policies
  • Applications that your users will likely want to use in the future; these applications are managed with a feature named Policy Automation
  • Available in local GPO Editor or SaaS edition
  • Seamless integration with Windows 7
  • SaaS edition shines for mobile workforce

Read more of Rux’s in-depth review… “It also gives you the option of letting users install software on their own, while you still maintain control -- all from an easy-to-manage console.”

SC Magazine: Are security basics getting lost under the cover of cloud and mobile?

by Mary Rose 19. April 2012 14:08

Sean Martin, founder of imsmartin consulting, spoke to many individuals at the recent RSA 2012 conference.  Sean mentioned in his recent article titled “Are security basics getting lost under the cover of cloud and mobile?” that there were numerous topics discussed but he noticed three topics being raised more than others: passwords, identities, and privileges.

Most organizations take steps to remove admin-level access and elevated privileges from standard user accounts. But admin privileges often get granted to additional users over time as a way to allow them to install printer drivers, launch system-level applications, and perform other business-enabling actions on their own without IT help desk involvement,” said Sean Martin.

Viewfinity is seeing that most organizations are victims of “privilege creep” – a situation where privileges are locked down initially and are increased over time. Businesses should follow the basics of managing account privileges on a granular level, controlling access based on need, time, application, location and more.

Viewfinity Exhibiting at the 2012 Microsoft Management Summit

by Mary Rose 13. April 2012 12:48

Viewfinity will be exhibiting in booth 610 at the 2012 Microsoft Management Summit next week! We will be showing live demos of our Privilege Management solution.  We hope to see you there!

To schedule a one-on-one demo at MMS 2012, click here.

 

 

 

Violations of the Least Privilege Principle cause major concerns for Energy Company

by Mary Rose 9. April 2012 11:25

FierceGovernmentIT reported that Government Core Baseline (GCB), formerly known as FDCC, violations were found at a large energy company, along with other least privilege violations.  The company responded swiftly and remediation tactics underway, but are they enough to become compliant and reduce exposure to security risks?  They've started with the layered approach with patch management and password controls however our Energy & Utility clients have completely removed administrative privileges and are using Viewfinity Privilege Management to elevate privileges on the application level, closing down the loophole presented when users have administrator accounts. 

Auditors uncover routine security vulnerabilities at Bonneville Power Administration

"The report also criticizes the power administration for not following the Government Configuration Baseline (formerly known as the Federal Desktop Core Configuration) on only two of its four server operating systems.

It also notes violations of the least privilege principle, since 12 regular users had administrative privileges to servers based on group membership but not individual job responsibility.

In a response to the report, Stephen Wright, Bonneville administrator and chief executive officer, says the power administration already has underway a more robust patch management program, and said the number of vulnerabilities uncovered by auditors are an exaggeration. Power administration officials also told auditors they’ve implemented new password controls." 

Read more: Auditors uncover routine security vulnerabilities at Bonneville Power Administration - FierceGovernmentIT http://www.fiercegovernmentit.com/story/auditors-uncover-routine-security-vulnerabilities-bonneville-power-administ/2012-04-09#ixzz1rYcbtbZm

Top 10 Tips for Removing Administrator Rights - Tip #10 Look for Adaptable, Flexible Products Based on Your Use Case

by Mary Rose 6. April 2012 15:47
 
Viewfinity has valuable resources that can help you with your transition to a least privilege environment.
 

Abuse of System Access and Privileges

by Mary Rose 4. April 2012 14:26
During the "Privilege Creep – How Can You Be Certain Your Environment is Still Locked Down?" webinar on April 3, 2012, Sean Martin, Managing Director of imsmartin, said that 49% of misuse-driven breaches are a result of the abuse of system access and privileges. 
 
 
 Source: Verizon Data Breach Investigation Report 2011
 
To watch the entire webinar, please follow this link
 
 
 

Powered by BlogEngine.NET 1.4.5.0
Theme by Mads Kristensen

Calendar

<<  May 2013  >>
MoTuWeThFrSaSu
293012345
6789101112
13141516171819
20212223242526
272829303112
3456789

View posts in large calendar

About Viewfinity

Viewfinity provides privilege management and application control for desktops, laptops and servers, empowering enterprises to meet compliance mandates, reduce security risks, and lower IT costs. The Viewfinity solution allows enterprises to control end user and privileged user rights for applications and systems which require elevated permissions. Viewfinity's granular-level control enables companies to establish and enforce consistent policies for least privilege Windows-based environments based on segregation of duties. For more information, visit www.viewfinity.com.

Follow us on Twitter: viewfinity
Find us on LinkedIn: www.linkedin.com/companies/viewfinity
Become a fan on Facebook: www.viewfinity.com/facebook