• No results found

2013 AWS Worldwide Public Sector Summit Washington, D.C.

N/A
N/A
Protected

Academic year: 2021

Share "2013 AWS Worldwide Public Sector Summit Washington, D.C."

Copied!
22
0
0

Loading.... (view fulltext now)

Full text

(1)

2013 AWS Worldwide Public Sector Summit

Washington, D.C.

Next Generation Privileged Identity Management

(2)

Who We Are

Security software company providing Next

Generation Privileged Identity Management

solutions

Global Fortune 1000 and Government

(3)

Our Customers Include

Commercial

• Top 5 Global Bank

• Top 3 Telecommunications Company • Fortune 10 Financial Services Company • Top 5 Global Retailer

• Multiple Global Stock Exchanges • Fortune 200 Food Products Company • Top 3 Online Broker

• Top 3 Smart Phone Provider • Top 3 Food and Drug Retailer

(4)

The Problem We Solve

Protect Enterprises from Privileged User Risks

Reduced Complexity of Audit and Compliance Controls

– PCI/DSS, HIPAA/HITECH, NERC CIP, FISMA, GLBA, SOX

Privilege Usage Gateway to Manage Access Across Traditional, Virtualized,

Cloud, and Hybrid Environments

(5)

Deploy Privileged Account Management for

IaaS and Private Cloud

Administrators of private cloud and IaaS environments gain more concentrated power — and the risk that goes with it — ………..additional controls should be put in place around the

privileged accounts within these environments and employ privileged account management products to aid in placing finer-grained controls around the additional operations that these environments provide.

(6)

Compliance and Audit

Controls, Directives, Policy, Frameworks….

– HSPD-12, CAP Goals (PIV, Cont. Monitoring, TIC) – NIST SP-800-53(r4) (Insider Threat, Cloud)

Audit Findings (POAM)

– Shared accounts (“who was root”)

– Shared credentials (email / sticky note) – Weak / default passwords

(7)

DoD 8520.03- Identity Authentication

for Information Systems

Credential Strength “E”

all administrative access

Hardware token PKI

technology

Identity proofing

Identity vetting

Credential registration

(8)

Who Are Privileged Users?

On Premise Employees/Partners • Systems Admins • Network Admins • DB Admins • Application Admins Partners Systems/NW/DB/Application Admins Employees Systems/NW/DB/A pplication Admins Public Cloud Apps Apps

Unauthorized User Hacker (Malware/APT)

(9)

Migration to the New Enterprise

Figure 2. The Virtualization Road Map Through Private Cloud Computing

Source: Gartner (February 2012) • Consolidation

• Capital expense

• Capital expense elimination • Increased

flexibility (up and down)

• Flexibility and speed • Operational expense automation • Less downtime • Self-serve agility • Standardization • IT as a business • Usage metering STAGE 1: Server Virtualization STAGE 5: Public Cloud STAGE 2: Distributed Virtualization STAGE 3: Private Cloud STAGE 4: Hybrid Cloud

• Costs for peak loads

(10)

NIST 800-125

“Guide to Security for Full Virtualization Technology”

Restrict and protect administrator access to the virtualization solution

•“The security of the entire virtual infrastructure relies on the security of the virtualization

management system”

•“…start guest OSs, create new guest OS images, and perform other administrative actions.

Because of the security implications of these actions, access to the virtualization management system should be restricted to authorized administrators only.”

•“Secure each management interface, whether locally or remotely accessible.”

•“For remote administration, the confidentiality of communications should be protected, such as

(11)
(12)

NIST Cloud Security Architecture

Privilege Management Infrastructure

Identity Management Authentication Services

Authorization Services Privilege Usage Management Domain Unique Identifier Identity Provisioning Federated IDM Attribute Provisioning Policy Enforcement Policy Management Resource or Data Management Policy Definition Privileged Data Management XACML Role Management Obligation Out of the Box (OTB)

SAML Token Risk Based Authenticati on Multifactor OTP Smart Card Password Management Network Authentication Middleware Authentication OTB Keystroke/Sessio n Logging Privilege Usage Gateway Password Vaulting Resource Protection Biometrics Single Sign On WS Security Identity

(13)

Identity Integration Enterprise-Class Core

Hardware Appliance OVF Virtual Appliance AWS AMI

Unified Policy Management

Control and Audit All Privileged Access

• Vault Credentials

• Centralized Authentication • Federated Identity

• Privileged Single Sign-on

• Role-Based Access Control • Prevent Leapfrogging • Monitor & Record Sessions • Full Attribution

Introducing Xsuite

®

Next Generation Privileged Identity Management

Traditional Data Center

Mainframe, Windows, Linux, Unix, Networking

New Enterprise

Virtualized Data Center

VMware Console

SaaS Applications

Office 365 Console Public Cloud - IaaS

(14)

High Level Xsuite Architecture

- Security, Compliance, and Audit…simplified

Xs ui te Se c urity A dm in

Keystroke and Session Recording Alerting, Logging, and Resource

Protection

Web Interface

Password and Key Vaulting and FIPS 140-2 Encryption

Federated Privileged Identity Service

API Proxy

Security Policy Engine (Authorization Services)

Session Applets

Third Party Log and SIEM Platform

Third Party Encryption, Identity Providers, and X.509 Services Directory Services (LDAP, AD FS, AD) Target Cloud, Application or Host Platform Authentication Service

Privileged Identity and Authentication Management

HSM Crypto Support

(15)

Credential Safe Session

Logs Policies

Attribute Identity for Shared Accounts (e.g., Root/Admin)

Control Access to Target Systems Prevent Leapfrogging

Monitor Sessions & Prevent Unauthorized Commands Record Sessions

Positively Authenticate Users

Before: ID: abc123 PW: password After: ID: abc123 PW:x8km&eie10$z*!B

Vault & Manage Credentials

(16)

Xsuite for AWS

Security Across AWS Regions, Management Console, and APIs

Xceedium Announces Privileged User Protection for AWS

Cloud Management APIs

(17)

AWS Management API Security

Shared credentials are

typical

Difficult to attribute

privileged API activities to

unique users

No log files of what

happened

AWS APIs

(Compute/Networking, Storage/Content Delivery, App Services, Database)

(18)

Xsuite for AWS API Proxy

• Single point of access control, monitoring, and audit - all activity with AWS Management Console and REST APIs • Role-based API access control for programmatic and manual

AWS API Access • Separation of duties

• Full, real-time bi-directional audit trail of all API calls

• Attribute AWS API activity to a specific user – no need to add users to AWS Identity and Access Management (IAM)

• Uses alternative credentials valid only with the Xsuite AWS API Proxy – no direct access to AWS APIs

• Vault and manage the credentials used by scripts to access AWS APIs and eliminate the practice of sharing these

important keys

Public Cloud/ Gov. Cloud/ VPC

(19)

Core Xsuite Capabilities

Comprehensive Protection for Management Consoles, APIs and Guest

Systems:

– Role Based Privileged Access Control

– Password and Access Key Vaulting & Management – Application-to-Application Password Vaulting

– Privileged User Single Sign-On

– Full Audit Trail and Session Recording – Full Identity Attribution for Shared Accounts – Auto-discovery and Provisioning

(20)

What Sets Xceedium Apart?

Next Generation Privileged Identity Management

Xsuite is the Only Platform With:

– A comprehensive set of well integrated controls enforced across hybrid cloud environments – Single policy enforcement point across hybrid-cloud environments

– Unified policy management

– Protection for both management consoles and guest systems

– Integration with VMware, Amazon Web Services and Microsoft Office 365 – Control and Auditing of AWS management API calls

– Specifically architected for dynamic, elastic cloud environments – Choice of appliance form factor: hardware, OVF or AMI

(21)

Contact Us

2214 Rock Hill Road, Suite 100

Herndon, VA 20170

Phone: 866-636-5803

(22)

References

Related documents