June 2020ENTERPRISE SECURITY| | 9that can tailor to the needs of an organization. The key concept behind any approach is tying service accounts to accountable individuals and processes, regardless of whether personnel change.Once the service accounts are represented in the IDM system, then regular access reviews can be performed so that the validity and the need for those service accounts can be attested by the application owner. In addition, once an application owner moves roles or leaves the organization, the transfer of ownership of the service accounts can be efficiently managed. Finally, to ensure effective oversight, the service account passwords should be stored in a secure safe and rotated regularly. Orphan and Dormant Accounts: Orphan accounts are those that are active but not associated with a valid identity (this usually happens when someone leaves the organization and their identity is revoked but some of their downstream application accounts are not revoked). These accounts could be misused by an attacker or malicious insider to elevate their access in the target system. As these accounts are not tied to an active identity, usage of these accounts will go undetected. Dormant accounts are those with no recent login activity and which have not been used for a while. These accounts are also attractive targets for hackers, because the account owner isn't going to notice account activity.ยท Managing Orphan and Dormant accounts: Lately, industry leading IDM vendors have incorporated features to detect orphan accounts from the target systems and applications provided when these targets are enrolled in the IDM tool. After enrolling the target application/system in the IDM system, when the IDM tool reconciles or reads the accounts/entitlements from the target, a process can be established to detect orphan accounts. This process could involve generating reports of accounts that are not associated with an identity (filtering system level and default accounts), creating risk exceptions and passing it to operations for further analysis. The process could be further enhanced by automating the detection and remediation of these accounts by leveraging the features of the IDM tools. In addition, a number of IDM tools also provide out-of-the-box options to deal with dormant accounts. Some of these options include configuring rules to detect accounts that have not been used for a certain number of days, then creating alerts or reports to further review these accounts with line managers or the cyber-defense team. For example: Active Directory accounts that have not been used in the last 90 days should be disabled or flagged up for further review by the operations or cyber-defense teams. ESActive Directory accounts that have not been used in the last 90 days should be disabled or flagged up for further review by the operations or cyber-defense teams
<
Page 8 |
Page 10 >