Home > CA Community > Security Management

CA Community





This Blog

Security Management

Insight and opinion on the world of security management. Visit often for commentary on security industry issues around identity and access management, data protection, advanced authentication, single sign-on and access management, cloud security and more.

Privileged Identity Management vs. Privileged User Management – It does make a difference!

Published: June 27 2012, 04:05 PM
by Russell Miller

The market for controlling administrative accounts is alternately called "Privileged Identity Management" (PIM) and "Privileged User Management" (PUM). While many in the security field use these terms interchangeably, the choice of term can color how we perceive the problem we're trying to address. I strongly advocate the use of the first term (PIM) for three primary reasons:

1. When you use the term "privileged user," you tend to think of people. There is not - or should not be - such a thing as a person who is a generically privileged user, which "PUM" seems to imply. There are individuals who need very specific access in order to perform a particular task on a specific system or application. "All-powerful" administrators should only exist in exceptional cases.

2. Using the term "privileged identity" makes it easier to think about identities as tools. They are the means by which certain users can gain the ability to perform certain tasks. This also enables us to think about these identities as a potential avenue for abuse by external "hackers," and defenses as not solely aimed at insider threats.

3. By positioning privileged identities as depersonalized tools, it becomes much easier to navigate a political environment to implement security controls. It's much easier to explain to administrators that you're securing a tool that they use, rather than implementing controls that target them personally. It may be a fine distinction, but often the message is seen as the reality. And, in fact, user activity reporting PIM tools can protect administrators in the event of a breach by being able to prove "who did what."

With all the benefits of administrative controls, from accountability to being able to enforce the principles of least privilege and segregation of duties, it's worth spending the time to craft your message. Talking about "privileged identities" is a good start.

 

By: Russell Miller
Russell Miller has spent over five years in network security in various roles from ethical hacking to solutions marketing. He currently manages marketing activities for the CA ControlMinder products. Russell has a B.A. in Computer Science from Middlebury College and an M.B.A. from the MIT Sloan School...
Read More..

1 person has left a comment:

Russel - excellent post, especially point 3. If only that was easily attainable in big corporations to speed up and improve the quality of big systems and their output!

Posted by: Brandon Klein | June 28, 2012 9:53 AM

Leave a Comment

* An asterisk indicates a required field

* :  

:

* :  

  Submit