April 12, 2022
April 12, 2022
Contributor: Homan Farahmand
It’s essential to prioritize as a cyber defense mechanism.
In short:
Privileged access, which bypasses standard controls to execute operations above those with standard access, can put the target system — or systems, such as infrastructure as a service (IaaS) — at higher risk. This makes privileged access management (PAM) a high-priority cyber defense capability, but effective PAM takes a comprehensive technical strategy. Key success factors include visibility and control of privileged accounts across all assets.
Discover Gartner BuySmartâ„¢: Streamline your tech purchase from start to finish.
Privileged access happens when an entity (human or machine) uses an administrative account or a credential with elevated rights to perform technical maintenance, make changes, or address emergency outages (privileged operations) in an IT or digital system. This can occur either on premises or in the cloud. Privileges in this context are technical, which is different from high-risk entitlements related to business processes. PAM controls ensure authorized use of privileges (including any related mechanism like privileged accounts or credentials) in authorized target systems for all relevant use cases.
Privileged access risks result from the proliferation of privileges, the potential for human error in using privileges (such as administrator mistakes) and unauthorized privilege elevation (techniques that attackers use to gain higher-level permissions on a system, platform or environment).
Traditional PAM controls, such as credential vaulting zeroand session management, ensure that privileged users, applications and services get just enough privileges (JEP) just in time (JIT) to reduce the access risk. However, such measures are essential but insufficient if deployed partially. Emphasizing JIT privilege approaches and managing machine identities are imperative; implementing privilege task automation and advanced analytics is preferred.
Download now:Â 3 Must-Haves in Your Cybersecurity Incident Response Plan
Broader coverage of PAM controls for cloud platforms, DevOps, microservices, and robotic process automation (RPA) scenarios require additional capabilities such as secrets management (with secretless brokering) and cloud infrastructure entitlement management (CIEM).
PAM is applicable to all local and remote human-to-machine and machine-to-machine privileged access scenarios. This makes PAM a critical infrastructure service due to risk aggregation related to storing sensitive credentials/secrets, as well as performing privileged operations in different systems. As such, PAM capabilities require thoughtful high-availability (HA) and recovery mechanisms.
It’s essential to prioritize PAM as a cyber defense mechanism. It plays a key role in enabling zero trust and defense-in-depth strategies that extend beyond mere compliance requirements. Some organizations may choose to deploy a minimum set of PAM controls to meet their compliance obligations in response to the findings of an audit. However, these organizations remain susceptible to attack vectors, such as service accounts, privilege escalation and lateral movements. Although minimalistic controls are better than nothing, expanding PAM control coverage can mitigate a broader number of risks to defend against complex cyberattacks.
Learn more: Your Ultimate Guide to Cybersecurity
The figure below shows the key steps to develop/enhance PAM architecture strategy:
Security and risk management technical professionals should:
A version of this story was originally published on the Gartner Blog Network.
Â
Join your peers for the unveiling of the latest insights at Gartner conferences.
Recommended resources for Gartner clients*:
Guidance for Privileged Access Management
Identity and Access Management for Technical Professionals Primer for 2022
Evaluation Criteria for Privileged Access Management
*Note that some documents may not be available to all Gartner clients.