Violations of the Least Privilege Principle cause major concerns for Energy Company

by Mary Rose 9. April 2012 11:25

FierceGovernmentIT reported that Government Core Baseline (GCB), formerly known as FDCC, violations were found at a large energy company, along with other least privilege violations.  The company responded swiftly and remediation tactics underway, but are they enough to become compliant and reduce exposure to security risks?  They've started with the layered approach with patch management and password controls however our Energy & Utility clients have completely removed administrative privileges and are using Viewfinity Privilege Management to elevate privileges on the application level, closing down the loophole presented when users have administrator accounts. 

Auditors uncover routine security vulnerabilities at Bonneville Power Administration

"The report also criticizes the power administration for not following the Government Configuration Baseline (formerly known as the Federal Desktop Core Configuration) on only two of its four server operating systems.

It also notes violations of the least privilege principle, since 12 regular users had administrative privileges to servers based on group membership but not individual job responsibility.

In a response to the report, Stephen Wright, Bonneville administrator and chief executive officer, says the power administration already has underway a more robust patch management program, and said the number of vulnerabilities uncovered by auditors are an exaggeration. Power administration officials also told auditors they’ve implemented new password controls." 

Read more: Auditors uncover routine security vulnerabilities at Bonneville Power Administration - FierceGovernmentIT http://www.fiercegovernmentit.com/story/auditors-uncover-routine-security-vulnerabilities-bonneville-power-administ/2012-04-09#ixzz1rYcbtbZm

Top 10 Tips for Removing Administrator Rights - Tip #9 Block Non-Business Related Apps

by Mary Rose 23. March 2012 02:33
 
Visit our blog next Friday or the final tip for removing administrator rights.

Viewfinity Privilege Management At-a-Glance

by Mary Rose 21. March 2012 02:22
Viewfinity provides the most reliable and secure privilege management solution for enterprises of all sizes and verticals.   The Viewfinity Privilege Management solution offers IT Administrators a flexible approach for controlling its corporate desktop and laptop environment. With tighter, yet flexible control over the types of applications and privileges your distributed workforce are allowed, the more stable your desktop environment becomes. With this enhanced control over managing your environment, the number of end user support calls to the help desk are reduced. 
 
Take a few minutes to watch Viewfinity Privilege Management at a glance. 
 

Top 10 Tips for Removing Administrator Rights - Tip #8 Customize the End User Experience

by Mary Rose 16. March 2012 02:24
Don't forget to come back next Friday for tip #9! 

Restrict Usage with Viewfinity Privilege Management

by Mary Rose 14. March 2012 14:08
Viewfinity Privilege Management helps to restrict usage.  IT administrators are able to block unapproved applications or toolbars and reduce permissions for privileged users on specific applications and tasks.  
 
Come back next week to see more features with Viewfinity Privilege Management. 

Zero Touch Elevation with Viewfinity Privilege Management

by Mary Rose 7. March 2012 16:01
Ad Hoc Elevation is simple with Viewfinity Privilege Management.  Viewfinity Privilege Management allows for automated self-elevation & on-demand methods for approving privilege requests.  To view the Zero Touch Privilege Elevation in action, click the play button below.
 
 
Visit our blog next Wednesday for another powerful feature!

Discover Users that Have Administrator Rights

by Mary Rose 29. February 2012 15:02
Viewfinity Privilege Management provides a helpful built-in feature that discovers user accounts and groups that are members of the local "Administrators" built-in user group.  The demo clip below explains this feature in more detail.  
 
 
Visit again next Wednesday for another useful feature with Viewfinity Privilege Management.  

Wayne Rash Reviews Viewfinity Privilege Management

by Mary Rose 28. February 2012 11:07

Viewfinity Privilege Management earned high marks in an independent product review by Wayne Rash, President and Analyst, of Wayne Rash & Associates. 

 “The single greatest security threat to most enterprises is the lack of control over administrative rights on client computers. By allowing employees administrative rights, you are opening the door to worms, Trojans and a host of other security problems. The security improvements in Windows 7 and third party privilege management solutions make the OS refresh the perfect time to remove rights. However, this issue is so critical that the removal of administrative privileges should be made as soon as possible,” says Wayne Rash, president and principal analyst of Wayne Rash & Associates.”

Here are some highlights of the Viewfinity review:

  • “You can also use the Policy feature to block applications, so if a user has a peer to peer movie downloading package already installed, for example, you can prevent it from operating.

  • “You can implement Viewfinity on any network using Windows machines, regardless of whether it Active Directory is in place."

  • “With Windows 7, users are presented with a message from the User Account Control system when they attempt to invoke a function that requires administrative rights.” “Because Viewfinity is controlling the administrative rights, you can also control the UAC message.” 

 

 Click the picture to read the entire review:

 
 

Top 10 Tips for Removing Administrator Rights - Tip #5

by Mary Rose 24. February 2012 02:30
 
Tip #6 will be posted next Friday. Don't forget to come back to check it out!
 

Top 10 Tips for Removing Administrator Rights - Tip #4

by Mary Rose 17. February 2012 08:59
Don't forget to stop by next Friday for Tip # 5 
 

Powered by BlogEngine.NET 1.4.5.0
Theme by Mads Kristensen

Calendar

<<  May 2012  >>
MoTuWeThFrSaSu
30123456
78910111213
14151617181920
21222324252627
28293031123
45678910

View posts in large calendar

About Viewfinity

Viewfinity provides privilege management and application control for desktops, laptops and servers, empowering enterprises to meet compliance mandates, reduce security risks, and lower IT costs. Many enterprises are implementing least privileges to add a solid layer of defense for desktop environments, further protecting against malware and Advanced Persistent Threats. Viewfinity allows IT Administrators to create and enforce default-deny and elevated permission policies for endpoint access to applications and desktop functions by controlling user rights for desktops and mobile laptop/netbook users. For more information, visit www.viewfinity.com.

Follow us on Twitter: viewfinity
Find us on LinkedIn: www.linkedin.com/companies/viewfinity
Become a fan on Facebook: www.viewfinity.com/facebook