Administrative passwords, whatever the platform, application or appliance present a unique set of management challenges. The nature of these credentials is that they tend to be role based, and therefore there is a tendency for them to be shared between a number of individual users, leading to the well understood mismanagement scenarios.
Although many organisations have procedural controls and policies governing the use of these credentials, where the number and range of systems is extensive this can clearly be a costly and time consuming exercise. That is of course assuming that the procedures and policies have in fact been followed.
|
In many cases organisations simply ignore the risks, and hope nothing bad will ever happen to them. The days of the envelope containing credentials in the fire safe is simply past.
These credentials simply must be available at the point of need, such as when rebuilding mission critical infrastructure in the small hours of the morning.
Once a shared account is designated as a SafeKeeping Managed account, a password change for the credentials on that account is scheduled. The new password will be selected in accordance with SafeKeeping’s user defined strong password policies, after which it will not be known to a single individual until it is issued following a successfully authorised release request.
All SafeKeeping’s actions are fully audited to ensure conformance with compliance requirements. |