1
00:00:06,510 --> 00:00:08,250
- In this lesson, 19.6,

2
00:00:08,250 --> 00:00:11,850
we're going to focus in on
privilege access management.

3
00:00:11,850 --> 00:00:15,030
Now, a privileged account,
we're defining as any account

4
00:00:15,030 --> 00:00:16,950
that provides rights and permissions

5
00:00:16,950 --> 00:00:19,710
above and beyond those of a non-privileged

6
00:00:19,710 --> 00:00:22,563
or what we refer to often
as a standard account.

7
00:00:23,820 --> 00:00:26,340
Standing privilege is accounts that have

8
00:00:26,340 --> 00:00:28,620
persistent privilege access,

9
00:00:28,620 --> 00:00:33,620
24 hours a day, seven days
a week, 365 days a year.

10
00:00:33,660 --> 00:00:36,840
So, accounts like are
admins or domain admins

11
00:00:36,840 --> 00:00:40,290
or enterprise admins
or super users or root.

12
00:00:40,290 --> 00:00:42,630
Those are all privileged accounts, right?

13
00:00:42,630 --> 00:00:44,490
They have rights and permissions

14
00:00:44,490 --> 00:00:47,880
way above those of a
non-privileged or standard account,

15
00:00:47,880 --> 00:00:50,940
and they have them whenever
they log in, right?

16
00:00:50,940 --> 00:00:55,290
24 hours a day, seven days
a week, 365 days a year.

17
00:00:55,290 --> 00:00:57,240
We worry a lot about privileged accounts

18
00:00:57,240 --> 00:01:01,800
because they are incredibly
rich targets for cyber attacks.

19
00:01:01,800 --> 00:01:04,770
As we know, right? An
exploit is going to execute

20
00:01:04,770 --> 00:01:07,470
in the context of the
locally logged in user.

21
00:01:07,470 --> 00:01:10,440
So if I'm logged in with, you
know, extraordinary privileges

22
00:01:10,440 --> 00:01:12,540
because I'm an admin, or you know,

23
00:01:12,540 --> 00:01:15,330
we've just effectively given
the keys to the kingdom

24
00:01:15,330 --> 00:01:16,893
to our adversaries.

25
00:01:18,990 --> 00:01:20,610
Zero-standing privilege

26
00:01:20,610 --> 00:01:23,640
aims to minimize the standing privileges

27
00:01:23,640 --> 00:01:27,150
granted to users or
accounts within a system.

28
00:01:27,150 --> 00:01:28,920
I would maybe take it
a step further and say

29
00:01:28,920 --> 00:01:31,350
zero-standing privilege wants to abolish

30
00:01:31,350 --> 00:01:34,530
standing privileges granted
to users or accounts

31
00:01:34,530 --> 00:01:35,583
within a system.

32
00:01:36,630 --> 00:01:40,800
Now, in practice, ZSP,
zero-standing privilege,

33
00:01:40,800 --> 00:01:44,880
means continuous reauthentication
or explicit validation,

34
00:01:44,880 --> 00:01:47,310
and granting to authorize users

35
00:01:47,310 --> 00:01:50,820
the privilege access they
only need for the minimum time

36
00:01:50,820 --> 00:01:53,400
and only minimum rights they need

37
00:01:53,400 --> 00:01:54,780
to complete whatever the task is,

38
00:01:54,780 --> 00:01:58,320
which really goes back to our
principle of least privilege.

39
00:01:58,320 --> 00:02:00,270
And way back at the
beginning of this course

40
00:02:00,270 --> 00:02:03,240
we talked about a zero trust environment.

41
00:02:03,240 --> 00:02:05,310
Well, this is a way that we implement

42
00:02:05,310 --> 00:02:08,640
a zero trust environment
in terms of the privileges

43
00:02:08,640 --> 00:02:10,340
that we are going to be assigning.

44
00:02:12,030 --> 00:02:14,520
So, let me give you some
privileged account examples.

45
00:02:14,520 --> 00:02:17,100
Administrator, root, super user,

46
00:02:17,100 --> 00:02:20,940
or someone using the the sudo
command, a service account,

47
00:02:20,940 --> 00:02:23,400
or even embedded
application accounts, right?

48
00:02:23,400 --> 00:02:24,870
Administrative accounts generally

49
00:02:24,870 --> 00:02:27,870
have the highest level
of access and control

50
00:02:27,870 --> 00:02:31,110
over an operating system, or
a device, or an application,

51
00:02:31,110 --> 00:02:34,713
a database, a domain, or
even over our entire network.

52
00:02:35,640 --> 00:02:37,440
The route or super user accounts,

53
00:02:37,440 --> 00:02:39,510
again have complete control as well,

54
00:02:39,510 --> 00:02:42,600
but these would be over
a Unix or a Linux system.

55
00:02:42,600 --> 00:02:46,680
Now sudo, S-U-D-O, is the
Linux command to run programs

56
00:02:46,680 --> 00:02:49,800
with the security
privileges of another user,

57
00:02:49,800 --> 00:02:52,020
and by default, when you run that command,

58
00:02:52,020 --> 00:02:54,813
you're actually running as the super user.

59
00:02:55,966 --> 00:02:57,480
Now, we don't generally think about

60
00:02:57,480 --> 00:02:59,490
service accounts being
a privileged account,

61
00:02:59,490 --> 00:03:00,450
but they could be

62
00:03:00,450 --> 00:03:02,700
because they often have
elevated privileges

63
00:03:02,700 --> 00:03:07,080
to access required system
resources or network services.

64
00:03:07,080 --> 00:03:09,390
And the embedded in applications,

65
00:03:09,390 --> 00:03:11,700
there are embedded application accounts

66
00:03:11,700 --> 00:03:15,120
that are hardcoded credentials
embedded in the software.

67
00:03:15,120 --> 00:03:18,300
Now, they should just be used
for development purposes,

68
00:03:18,300 --> 00:03:20,583
but sometimes they still exist.

69
00:03:23,340 --> 00:03:25,080
Now, there are a number of regulations

70
00:03:25,080 --> 00:03:26,490
and contractual obligations,

71
00:03:26,490 --> 00:03:28,770
including HIPAA, PCI DSS,

72
00:03:28,770 --> 00:03:31,110
the payment card industry
data security standard,

73
00:03:31,110 --> 00:03:34,560
GLBA, that's Gramm-Leach-Bliley
Act, and GDPR

74
00:03:34,560 --> 00:03:36,270
that expect organizations

75
00:03:36,270 --> 00:03:40,320
to manage and to monitor
privileged accounts.

76
00:03:40,320 --> 00:03:43,740
Now, expectations include
having a formal approval process

77
00:03:43,740 --> 00:03:46,410
for new privilege account creation,

78
00:03:46,410 --> 00:03:49,050
limiting privilege account use,

79
00:03:49,050 --> 00:03:52,170
monitoring and tracing
all privilege activity,

80
00:03:52,170 --> 00:03:55,440
and then auditing privilege
account assignments

81
00:03:55,440 --> 00:03:56,913
and memberships.

82
00:03:59,010 --> 00:04:01,650
So, privilege account management or PAM

83
00:04:01,650 --> 00:04:04,050
is a really interesting and emerging

84
00:04:04,050 --> 00:04:07,890
set of practices and
technologies and policies

85
00:04:07,890 --> 00:04:11,070
designed to manage and
secure privilege accounts

86
00:04:11,070 --> 00:04:14,850
and access to critical
systems and to sensitive data

87
00:04:14,850 --> 00:04:17,220
within our organization.

88
00:04:17,220 --> 00:04:19,890
Now, the goal of PAM is
to minimize the risks

89
00:04:19,890 --> 00:04:23,640
associated with privileged
accounts and standing access.

90
00:04:23,640 --> 00:04:27,270
Now, PAM can be applied on
premises and in the cloud,

91
00:04:27,270 --> 00:04:29,910
and PAM solutions really assist

92
00:04:29,910 --> 00:04:33,510
in meeting regulatory and
compliance requirements

93
00:04:33,510 --> 00:04:37,770
by providing detailed audit
logs, reports, and visibility

94
00:04:37,770 --> 00:04:40,083
into privileged account activities.

95
00:04:42,060 --> 00:04:44,880
So, let's look at some
PAM solution elements.

96
00:04:44,880 --> 00:04:46,950
We have privileged account discovery,

97
00:04:46,950 --> 00:04:49,020
privileged account credentials,

98
00:04:49,020 --> 00:04:51,000
just-in-time privilege access,

99
00:04:51,000 --> 00:04:53,613
and privileged elevation and delegation.

100
00:04:54,600 --> 00:04:57,390
Now, privileged account
discovery is used to identify

101
00:04:57,390 --> 00:04:59,790
and to catalog all privileged accounts

102
00:04:59,790 --> 00:05:02,340
within the organization, that's
really our starting point.

103
00:05:02,340 --> 00:05:04,503
What are all of our privileged accounts?

104
00:05:05,400 --> 00:05:07,140
Then privileged account credentials,

105
00:05:07,140 --> 00:05:08,700
enforce a strict controls

106
00:05:08,700 --> 00:05:10,680
over privileged account credentials.

107
00:05:10,680 --> 00:05:14,160
So for example, they have
to be, you know, encrypted

108
00:05:14,160 --> 00:05:15,660
or if we're using passwords,

109
00:05:15,660 --> 00:05:17,610
they have to have secure
storage in a vault

110
00:05:17,610 --> 00:05:21,030
or they have to rotate them or
they have to be multifactor.

111
00:05:21,030 --> 00:05:23,910
Whatever it is, it's really
putting the rules, right?

112
00:05:23,910 --> 00:05:24,930
The strict controls

113
00:05:24,930 --> 00:05:27,513
over those privileged account credentials.

114
00:05:28,830 --> 00:05:32,340
Then we have JIT or
just-in-time privilege access.

115
00:05:32,340 --> 00:05:34,320
Now this privilege access is provided

116
00:05:34,320 --> 00:05:36,360
only for a limited duration

117
00:05:36,360 --> 00:05:39,603
so a limited time and specific tasks.

118
00:05:40,890 --> 00:05:44,640
And then privilege elevation
and delegation are mechanisms

119
00:05:44,640 --> 00:05:47,700
for granting temporary
or restricted privileges

120
00:05:47,700 --> 00:05:50,400
to non-privileged users when needed.

121
00:05:50,400 --> 00:05:51,990
Really reducing the dependency

122
00:05:51,990 --> 00:05:55,410
on having those persistent
privileged accounts.

123
00:05:55,410 --> 00:05:57,180
So, account discovery,

124
00:05:57,180 --> 00:06:00,660
having strict controls over
the account credentials,

125
00:06:00,660 --> 00:06:02,940
implementing just-in-time privilege access

126
00:06:02,940 --> 00:06:06,000
which means you're only going
to get access when you need it

127
00:06:06,000 --> 00:06:08,100
for a limited amount of time

128
00:06:08,100 --> 00:06:10,680
and only the rights and
permissions you need,

129
00:06:10,680 --> 00:06:12,360
and then having this ability

130
00:06:12,360 --> 00:06:14,670
to delegate this
privilege escalation again

131
00:06:14,670 --> 00:06:16,650
for just specific tasks

132
00:06:16,650 --> 00:06:18,600
so that we don't have to give someone

133
00:06:18,600 --> 00:06:21,693
administrative privileges,
if they really don't need it.

134
00:06:23,400 --> 00:06:26,340
Now, PAM solutions enable organizations

135
00:06:26,340 --> 00:06:31,340
to monitor and control privilege
user sessions in real time,

136
00:06:31,350 --> 00:06:34,350
and that includes capturing
and recording activities

137
00:06:34,350 --> 00:06:38,100
performed during privileged
sessions, enabling auditing,

138
00:06:38,100 --> 00:06:40,623
and if needed, forensic access.

139
00:06:42,360 --> 00:06:44,130
So that brings us to a
three second challenge,

140
00:06:44,130 --> 00:06:45,360
but before we go there,

141
00:06:45,360 --> 00:06:46,680
I just want you to think about

142
00:06:46,680 --> 00:06:48,570
how we're handling privileged access

143
00:06:48,570 --> 00:06:50,910
in most of our organizations right now.

144
00:06:50,910 --> 00:06:54,420
In most of our organizations,
we say to our administrators,

145
00:06:54,420 --> 00:06:55,497
hey, you should have two accounts,

146
00:06:55,497 --> 00:06:59,100
your administrator account
and your regular user account.

147
00:06:59,100 --> 00:07:00,870
And when you're doing normal stuff,

148
00:07:00,870 --> 00:07:03,570
like your email or you
know, going out to the web,

149
00:07:03,570 --> 00:07:05,610
make sure you're logged
in as your user account,

150
00:07:05,610 --> 00:07:09,033
and when you're doing admin
stuff, use your admin account.

151
00:07:09,900 --> 00:07:12,390
But the reality is, that doesn't work

152
00:07:12,390 --> 00:07:14,130
and it's never really worked.

153
00:07:14,130 --> 00:07:15,360
And it's why we really need

154
00:07:15,360 --> 00:07:17,820
to look at new ways of doing things.

155
00:07:17,820 --> 00:07:19,650
And privileged account management,

156
00:07:19,650 --> 00:07:22,620
I'm pretty convinced is
the way of the future.

157
00:07:22,620 --> 00:07:24,780
So, let's do our three second challenge,

158
00:07:24,780 --> 00:07:27,063
five challenge questions,
three seconds each.

159
00:07:27,990 --> 00:07:31,470
Number one, any account that
provides rights and permissions

160
00:07:31,470 --> 00:07:34,500
above and beyond those
of a standard account.

161
00:07:34,500 --> 00:07:36,840
1, 2, 3.

162
00:07:36,840 --> 00:07:38,970
And that's a privileged account.

163
00:07:38,970 --> 00:07:42,780
Number two, a set of practices
technologies and policies

164
00:07:42,780 --> 00:07:45,933
designed to manage and
secure privileged accounts.

165
00:07:47,070 --> 00:07:49,290
1, 2, 3.

166
00:07:49,290 --> 00:07:52,083
That's going to be PAM or
privilege access management.

167
00:07:53,190 --> 00:07:56,760
Number three, methodology
to provide privilege access

168
00:07:56,760 --> 00:08:00,603
only for a limited duration
and specific tasks.

169
00:08:01,560 --> 00:08:03,123
1, 2, 3.

170
00:08:04,410 --> 00:08:06,693
Just-in-time privilege access.

171
00:08:08,700 --> 00:08:11,460
Number four, the Linux
command to run programs

172
00:08:11,460 --> 00:08:13,980
with the security
privileges of another user,

173
00:08:13,980 --> 00:08:15,903
by default, that's the super user.

174
00:08:16,950 --> 00:08:18,363
1, 2, 3.

175
00:08:19,749 --> 00:08:22,500
And that's going to be
the sudo or sudo command

176
00:08:22,500 --> 00:08:23,333
pronounced differently

177
00:08:23,333 --> 00:08:26,283
maybe in different parts
of the world, S-U-D-O.

178
00:08:27,450 --> 00:08:29,610
And number five, hardcoded credentials

179
00:08:29,610 --> 00:08:31,773
used for software development purposes,

180
00:08:32,910 --> 00:08:34,560
but not always removed.

181
00:08:34,560 --> 00:08:36,630
1, 2, 3.

182
00:08:36,630 --> 00:08:39,093
That's going to be embedded
application accounts.

183
00:08:40,020 --> 00:08:41,130
Let's do a security and action,

184
00:08:41,130 --> 00:08:42,300
so we can apply our knowledge.

185
00:08:42,300 --> 00:08:44,970
This one's about administrative access

186
00:08:44,970 --> 00:08:47,250
and standing privilege.

187
00:08:47,250 --> 00:08:49,800
You are concerned about
administrative access

188
00:08:49,800 --> 00:08:52,080
and the issue of standing privilege.

189
00:08:52,080 --> 00:08:54,040
Now, you're planning on
introducing the concept

190
00:08:54,040 --> 00:08:57,960
of zero-standing privilege,
so no standing privilege,

191
00:08:57,960 --> 00:09:00,780
and privilege access management or PAM

192
00:09:00,780 --> 00:09:04,263
with the goal of significantly
reducing the attack surface.

193
00:09:05,280 --> 00:09:07,710
But your organization is pretty resistant

194
00:09:07,710 --> 00:09:09,660
to new methodologies.

195
00:09:09,660 --> 00:09:11,820
How do you impress upon your audience

196
00:09:11,820 --> 00:09:15,600
the importance of reducing
standing privilege?

197
00:09:15,600 --> 00:09:16,800
Think about how you might do that,

198
00:09:16,800 --> 00:09:19,623
go ahead and put me on pause
and jot down some notes.

199
00:09:23,460 --> 00:09:25,290
Well, let's do the math.

200
00:09:25,290 --> 00:09:28,860
Let's say in an organization,
we have three domain admins

201
00:09:28,860 --> 00:09:31,710
managing 10 domain controllers,

202
00:09:31,710 --> 00:09:34,083
that's 30 instances of standing privilege.

203
00:09:35,400 --> 00:09:38,340
Let's say we have one server admin group

204
00:09:38,340 --> 00:09:40,110
that has five users in it,

205
00:09:40,110 --> 00:09:43,560
and they're supporting a hundred servers,

206
00:09:43,560 --> 00:09:47,103
that's 500 instances
of standing privilege.

207
00:09:48,000 --> 00:09:49,710
Let's say we have one help desk group

208
00:09:49,710 --> 00:09:54,210
that has five users in it,
and they support 500 users,

209
00:09:54,210 --> 00:09:59,210
that's potentially 2,500
instances of standing privilege.

210
00:09:59,550 --> 00:10:01,860
So when we do the math,
we can say, oh my god,

211
00:10:01,860 --> 00:10:04,440
there is just so much
standing privilege going on,

212
00:10:04,440 --> 00:10:06,030
you know, over and over again,

213
00:10:06,030 --> 00:10:09,360
and 24 hours a day seven
days a week, 365 days a year,

214
00:10:09,360 --> 00:10:12,090
and maybe doing the math
will impress upon someone

215
00:10:12,090 --> 00:10:15,090
that this is really a significant exposure

216
00:10:15,090 --> 00:10:17,520
and we need to do everything we can

217
00:10:17,520 --> 00:10:19,500
to reduce standing privilege

218
00:10:19,500 --> 00:10:22,440
and certainly zero-standing privilege,

219
00:10:22,440 --> 00:10:23,273
zero trust,

220
00:10:23,273 --> 00:10:26,130
the requirement to
reauthenticate every single time.

221
00:10:26,130 --> 00:10:28,290
And privilege access management,

222
00:10:28,290 --> 00:10:31,230
you know, definitely, you
know, addresses this issue.

223
00:10:31,230 --> 00:10:34,320
And certainly, I think
the wave of the future.

224
00:10:34,320 --> 00:10:37,020
Explaining that, convincing people,

225
00:10:37,020 --> 00:10:38,940
security and action, right?

226
00:10:38,940 --> 00:10:41,100
There's your word cloud,
you know what to do,

227
00:10:41,100 --> 00:10:43,320
and when you're ready,
we've got a quiz coming up,

228
00:10:43,320 --> 00:10:44,270
I'll see you there.
