Tuesday, April 10, 2012

Utah Breach Shows Vulnerability of Health Records - NYTimes.com

Utah Breach Shows Vulnerability of Health Records - NYTimes.com

The same week that I am reading about the NSA building a big facility in Utah there's a data breach in Utah...
"Eastern European hackers have stolen personal records for 780,000 people in the breach of a computer server in Utah...Hackers were able to breach the servers by exploiting a technician’s weak password."
And this is definitely a hack that could have been avoided if the proper procedures were followed for configuration of their server according to the article. Personally, I'd go further and take the reliance off of manual procedures and eliminate weak passwords through the use of a privileged account management product like Quest One Privileged Password Manager. Why bother leaving this to manual procedures that may be "forgotten" as happened in this case?

Privileged Password Manager ensures that when administrators require elevated access, that access is granted according to established policy, with appropriate approvals, that all actions are fully audited and tracked and that the password is changed immediately upon its return. It’s a secure, compliant and efficient solution to the age-old “keys to the kingdom” problem. Privileged Password Manager is deployed on a secure, hardened appliance.

Friday, March 09, 2012

IETF explores new working group on identity management in the cloud - Computerworld

Great article on the SCIM (simple cloud identity management) specification that you should read. The key paragraph to note is:

"Momentum for SCIM is going to be key," Land says. "We've got Google, Webex, VMware all saying that they've got it ready to go. You'll see a lot more of the smaller vendors, the middleware guys, build products with SCIM. Towards the end of 2012, we should start seeing implementations of SCIM within the enterprise."

I talked about this in my previous post on the topic “SCIM, PEX and what the parrot saw”. Momentum is exactly what I am hoping to see in 2012. Which companies will adopt it and release support for SCIM in their product? Salesforce.com? Google? Webex? VMWare? Any of those 4 would be great. All of those four would be awesome! Customers will ask us to support those platforms for sure. But it is pretty doubtful customers will ask us to support Ping Identity, Courion, UNBoundID or SailPoint.

I’m not a complete Doubting Thomas on this topic (sorry, it is Lent after all) – just a pragmatist.

Like this post? Please +1 it or tweet it (below)!

Wednesday, March 07, 2012

Answers to Common Privileged Account Management Challenges

We have a webcast coming up on this topic and I’d like to invite you to join us for it. There are two times for the webinar: March 14 and March 16 so hopefully one of them fits your schedule. A few more details…

Access through privileged accounts is one of the most troublesome security and compliance challenges. Manually controlling administrative access is tedious and error prone and leads to a lack of accountability, auditing and, at times, administrators having more access than necessary.
Join Quest Software for this informative webcast where we will walk you through the issues of common privileged account scenarios such as:
  • Controlling remote vendor access
  • Enabling developer access to production
  • Managing the issuance and approval of credentials
  • Facilitating separation of duties
  • Providing limited rights for daily administrative tasks 
  • Managing a Sudo environment

You will also see a quick demo on how Quest One Privileged Account Management solutions help you control access through granular delegation and policy-based control of administrative accounts and tightly controlled and audited issuance of full administrative credentials.

Registration date and time information:

Wednesday, March 14, 2012 3:00 PM EST

Friday, March 16, 2012 3:00 PM EST

Like this post? Please +1 it or tweet it (below)!

Friday, February 10, 2012

Looking for a federation expert!

I'm looking at adding a new member to our band of merry product managers here at Quest. Someone who will have a strong focus on federation and especially on authorization. With the acquisition of BiTKOO they will be driving the product strategy for our authorization solution both externally for our customers and internally for use by other Quest products. Throw in a dash of XACML, strong authentication and simmer with SAML and ADFS - then bake.

Interested? Take a look at the job description and feel free to submit your resume.


Help me get the word out and +1 or tweet this post (below)!