<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Risky Business</title>
	<atom:link href="http://blog.aujasnetworks.com/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.aujasnetworks.com</link>
	<description>Build Your Information Risk Capabilities</description>
	<lastBuildDate>Mon, 26 Mar 2012 07:51:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>The Need for SAP Identity Management</title>
		<link>http://blog.aujasnetworks.com/sap-identity-management.html</link>
		<comments>http://blog.aujasnetworks.com/sap-identity-management.html#comments</comments>
		<pubDate>Mon, 26 Mar 2012 07:31:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SAP Security]]></category>

		<guid isPermaLink="false">http://blog.aujasnetworks.com/?p=1006</guid>
		<description><![CDATA[Today&#8217;s enterprises act on an increasingly global scale. Their business &#038; technology processes have become more and more complex and require a more comprehensive integration of systems, processes, People and Data across system boundaries and &#8230;<span class="more-link-span"><a href="http://blog.aujasnetworks.com/sap-identity-management.html" class="more-link">Read More </a></span>]]></description>
			<content:encoded><![CDATA[<p>Today&#8217;s enterprises act on an increasingly global scale. Their business &#038; technology processes have become more and more complex and require a more comprehensive integration of systems, processes, People and Data across system boundaries and beyond. Spectacular crashes such as Enron and the Banking &#038; Financial system in the US have made regulators pass tough legislations and now this has become a global norm.</p>
<p>We know that employees who store and deal with business data operate the SAP ERP and all underlying systems that deliver information (Financial, HR processes etc.). It is this exact data that forms an essential part of an enterprise&#8217;s value and thus is considered to be an asset. Employees who use the information within their business processes can read, modify and print data on a daily basis, and systems are set up to support this, which is normal. But the new angle to take into consideration is what happens when an unauthorized person gains access to sensitive data? What is the impact of critical financial, IP related information if or when it leaks out?</p>
<p>SAP now provides a product in the Identity Management (SAP IdM) area that allows for active management of all users and authorizations within an SAP run enterprise, ensuring complete data &#038; access governance. Prior to the introduction of SAP IdM, SAP users managed their ABAP and JAVA systems using CUA – Central User Administration. The new product – SAP IdM , allows for the management of user data, user accounts and authorizations of systems not only on the SAP Platform but also on the entire heterogeneous landscape.</p>
<p>The reasons for implementing SAP IdM are very compelling:</p>
<p><a href="http://blog.aujasnetworks.com/wp-content/uploads/2012/03/need_SAP_-identity.png"><img src="http://blog.aujasnetworks.com/wp-content/uploads/2012/03/need_SAP_-identity-300x196.png" alt="" title="need_SAP_ identity" width="300" height="196" class="alignright size-medium wp-image-1007" /></a></p>
<ol>
<li>To comply with laws and external audits</li>
<li>To reduce security risks</li>
<li>To reduce costs through automation and process optimization</li>
<li>To manage the lifecycle of an identity in the enterprise</li>
</ol>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>We will discuss the detailed functionality and features of the SAP IdM solution in my next blog. Meanwhile. I will leave you with a high level architecture of the SAP IdM as food for thought.</p>
<h4>Author</h4>
<p><strong style="color: #666666;">Dr. Jagan Nathan Vaman PhD CGEIT CISA</strong><br />
Chief Consulting Officer<br /><strong>Aujas Risk Management Services</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.aujasnetworks.com/sap-identity-management.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Should Organizations be concerned about Open Source Software Compliance?</title>
		<link>http://blog.aujasnetworks.com/organizations-concerned-open-source-software-compliance.html</link>
		<comments>http://blog.aujasnetworks.com/organizations-concerned-open-source-software-compliance.html#comments</comments>
		<pubDate>Thu, 22 Mar 2012 04:14:25 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Open Source Software Security]]></category>

		<guid isPermaLink="false">http://blog.aujasnetworks.com/?p=1000</guid>
		<description><![CDATA[Gone are the days when Open Source software (OSS) was only being used in educational institutions like universities, research organizations etc. Today most organizations use open source for a variety of reasons such as accelerating &#8230;<span class="more-link-span"><a href="http://blog.aujasnetworks.com/organizations-concerned-open-source-software-compliance.html" class="more-link">Read More </a></span>]]></description>
			<content:encoded><![CDATA[<p>Gone are the days when Open Source software (OSS) was only being used in educational institutions like universities, research organizations etc. Today most organizations use open source for a variety of reasons such as accelerating time-to-Market, reducing cost of development, dynamic integration etc.  There are many software development organizations that work closely with their customers to determine open source strategy before making them a part of product / application development. By 2016, OSS is expected to be a part of all mission-critical software portfolios in 99% of Global 2000 enterprises, up from 75% in 2010. (Source: Gartner, &#8220;Predicts 2011: Open-Source Software, the Power behind the Throne&#8221; &#8211; 23 Nov 2010).</p>
<p>But there are some serious concerns around the usage of open source in commercial environments. It is imperative to keep in mind the following possibilities if you are considering going the open source way.</p>
<p><strong>Intellectual  Property (IP) Infringement<em>:</em></strong>The licensing aspect of<strong> </strong>open  source code poses some unique challenges. Some of the licenses are permissive, while  the others are restrictive. If you are unaware of this, you face the  possibility of being subject to a &ldquo;breach of agreement&rdquo; on one hand or being subjected  to claims of copyright infringement on the other hand. In fact, there have been  several instances where organizations were asked to stop the <a href="http://www.groklaw.net/articlebasic.php?story=20110815131443415" target="_blank">commercial  distribution of product shipments and product recalls</a>. Recently Oracle sued  Google (GOOG), <a href="http://allthingsd.com/20100812/love-larry-here-is-the-oracle-statement-and-final-complaint-versus-google/" target="_blank">alleging  patent and copyright infringement</a> of Java-related intellectual property in  the development of Android mobile operating system software.</p>
<p>In some cases, organizations have been asked to make the source code available, leading to potential loss of Intellectual Property, loss of competitive advantage and/or possible financial obligations because they were using code from the most viral OSS licenses.</p>
<p><strong>Open  Source Software can be susceptible to security vulnerabilities: </strong>At the end of the day, open source software is nothing but source  code and like any other source code, it is susceptible to security  vulnerabilities. If the source code is not tested rigorously before moving it to  production, it leaves the door open for an adversary to compromise the application  running in production. For example, recently, there was a <a href="http://www.theregister.co.uk/2011/08/24/devastating_apache_vuln/" target="_blank">major  vulnerability</a> discovered in Apache Tomcat which could lead to denial of  service if not patched appropriately </p>
<p><strong>Unknown  Source<em>: </em></strong>Open source components can be made up of other open source components  or derived from other open source components. So, whose code is it anyway? The original code  might have been issued under special GPL license or commercial license forcing the organization to indirectly oblige to licensing terms specified by the original author of the code.</p>
<p></p>
<p><strong>They  are everywhere, yet hidden:</strong> Let us assume that the  organization has a specific policy crafted for open source usage but is unable  to document all the open source and/or third party components that are being used within the organization. During one of the audit engagements, we observed  that the organization had visibility of only 40% of total open source components in use. So the issue is &ldquo;the organization uses  open source software, but it doesn&rsquo;t know where they are&rdquo;. Obviously this can lead to security or legal issues.</p>
<p>The risk of open source usage does not lie in  the usage of open source itself, but on how the open source code is being managed  in the organizational environment. If the organization does not keep track of the  open source code it has adopted, then it is very difficult and expensive to  deal with obligations and vulnerabilities that are associated with it. So,  there is a definite need to create an open source compliance management program  (including an assessment checklist, training programs and software tools to  monitor open source software usage) which can establish a framework for due diligence  to ensure both the security and legal status of resulting application or  product.</p>
<h4>Author</h4>
<p><strong style="color: #666666;">Jaykishan Nirmal</strong><br />
Practice Lead, Aujas Networks</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.aujasnetworks.com/organizations-concerned-open-source-software-compliance.html/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Identity and Access Management: Before and After Scenario</title>
		<link>http://blog.aujasnetworks.com/identity-access-management-scenario.html</link>
		<comments>http://blog.aujasnetworks.com/identity-access-management-scenario.html#comments</comments>
		<pubDate>Tue, 28 Feb 2012 12:46:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Identity and Access]]></category>

		<guid isPermaLink="false">http://blog.aujasnetworks.com/?p=991</guid>
		<description><![CDATA[Scenario 2: Benefits in the Access Governance and Recertification Process Introduction In the last article in the &#8220;IAM: Before and After series&#8221; we looked at how organizations can drastically reduce user access calls to the &#8230;<span class="more-link-span"><a href="http://blog.aujasnetworks.com/identity-access-management-scenario.html" class="more-link">Read More </a></span>]]></description>
			<content:encoded><![CDATA[<p><em>Scenario 2: Benefits in the Access Governance and Recertification Process</em></p>
<h2>Introduction</h2>
<p>In the last article in the &#8220;IAM: Before and After series&#8221; we looked at how organizations can drastically reduce user access calls to the helpdesk by implementing an IAM solution. In the scenario , the client was able to reduce the call volumes by more than 95%.</p>
<p>In the second article of this series, we look at IAM from a security and risk management view – specifically from the Access Governance and Recertification Process in the organization.</p>
<h2>Why is Access Governance Important?</h2>
<p>Access risk is defined as, &#8220;risks related to unauthorized or inappropriate access&#8221;. As per Forrester, access governance includes three key components,</p>
<ol>
<li>Access recertification</li>
<li>Role management and</li>
<li>Access request management</li>
</ol>
<p>Access governance has become a critical component in the information risk management domain. It lowers access risk and improves security because it provides a better understanding of who has access to what and why; thus, fewer people accumulate privileges during their tenure in an organization.</p>
<h2>Client Background</h2>
<p>Let&#8217;s take the same client we discussed in the earlier article. The client is a country arm of a global Fortune 500 financial services company with a large user base of over 12,000 which is still seeing active growth. The user base includes internal users, external users and<br />
contractors. Additionally, the organization works with more than 50,000 agents. The business operations are supported by over 30 business critical applications that are built on diverse and heterogeneous technology platforms, and managed by different business teams.</p>
<h2>Before IAM</h2>
<p>As part of their compliance policy, the client needed to recertify access to all their users and applications on a regular basis. But the process was manual and used to take 2 to 3 months. As it was labor intensive and time consuming, it could not be scheduled more than once a year.</p>
<p>Manual deletion of accounts and recertification took significant effort and so, by default, the tendency was to grant all access unless explicitly denied. Exposure to access risk started increasing year on year, since unwanted access was not being identified and de-provisioned in an assured manner.</p>
<h2>The Solution</h2>
<p>Aujas successfully implemented a comprehensive IAM solution to address client requirements. The solution included:</p>
<ul>
<li>User Provisioning System: This component provided centralized control and 360° automation of business processes involved in user access management. As a result processes for requesting, validating, approving and provisioning access became more efficient and manual errors were eliminated.</li>
<p></p>
<li>Access Governance Workflows: This component helped by automating and streamlining the periodic review of access entitlements. Additionally, the solution leveraged role information built into the system. As a result, the system proactively prevented violation of separation of duties paradigm while granting access.</li>
<p></p>
<li>Access Management System: A comprehensive access management system comprising web access management and enterprise Single Sign-on (SSO). This solution component helped in enforcing role based access controls. Access Reporting Dashboards: This component allowed business and IT teams to easily track the status of the recertification process. The system the organization to quickly identify specific areas that created a bottleneck in the processes and to provide remediation in a focused manner.</li>
</ul>
<h2>After IAM</h2>
<p>The table below lists some of the significant client benefits after implementing the IAM solution.</p>
<table border="1" cellspacing="0" cellpadding="0" width="94%">
<tbody>
<tr>
<td width="14%" nowrap="" valign="top"><strong>Parameter</strong></td>
<td width="26%" nowrap="" valign="top"><strong>Before IAM</strong></td>
<td width="29%" valign="top"><strong>After IAM</strong></td>
<td width="29%" valign="top"><strong>Benefits</strong></td>
</tr>
<tr>
<td width="14%" valign="top">Review Cycle Time</td>
<td width="26%" valign="top">3 months</td>
<td width="29%" valign="top">10 days</td>
<td width="29%" valign="top">Significant improvement in the reliability of the processes. Time savings and lesser audit fatigue.</a></td>
</tr>
<tr>
<td width="14%" valign="top">Approach</td>
<td width="26%" valign="top">Grant Access unless explicitly denied</td>
<td width="29%" valign="top">Deny Access unless explicitly approved</td>
<td width="29%" valign="top">More secure systems which are only accessible on need to know basis. Lower access risk. Reduced chances on malicious activity and information theft.</td>
</tr>
<tr>
<td width="14%" valign="top">Review Frequency</td>
<td width="26%" valign="top">Annual</td>
<td width="29%" valign="top">Quarterly</td>
<td width="29%" valign="top">Reduce chances of errors in the processes. Faster evolution of role definitions. Reduction in time for potential system misuse. </td>
</tr>
<tr>
<td width="14%" valign="top">Review mode</td>
<td width="26%" valign="top">Manual</td>
<td width="29%" valign="top">Automated</td>
<td width="29%" valign="top">How many people hours was saved? Approximately 1000 man hours for every review.</td>
</tr>
</tbody>
</table>
<p>Automating the access governance and recertification process simplified the jobs of the security and risk management team and they were able to ensure a much more focused and tighter life-cycle process to manage access risk. </p>
<p>The biggest benefit for the client was moving from a reactive audit approach to a more proactive role management to manage access risk problem.</p>
<h2>Conclusion</h2>
<p>One of the key security concerns in any large organization is access risk. Governing access and conducting recertification manually is a tedious process, and most organizations shy away from a comprehensive and frequent review, which leads to access risks. Automating the entire process brings significant efficiency related benefits to the organization and more importantly peace of mind due to reduced risk!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.aujasnetworks.com/identity-access-management-scenario.html/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Securing B2C Mobile Applications</title>
		<link>http://blog.aujasnetworks.com/securing-b2c-mobile-applications.html</link>
		<comments>http://blog.aujasnetworks.com/securing-b2c-mobile-applications.html#comments</comments>
		<pubDate>Sat, 21 Jan 2012 11:18:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Mobile Security]]></category>

		<guid isPermaLink="false">http://blog.aujasnetworks.com/?p=965</guid>
		<description><![CDATA[Introduction: Last month, I met some major telecom companies and during these meetings, the business and security leaders discussed the challenges they face in their B2C mobility initiative. The concerns were around launching mobile applications &#8230;<span class="more-link-span"><a href="http://blog.aujasnetworks.com/securing-b2c-mobile-applications.html" class="more-link">Read More </a></span>]]></description>
			<content:encoded><![CDATA[<h2>Introduction:</h2>
<p>Last month, I met some major telecom companies and during these meetings, the business and security leaders discussed the challenges they face in their B2C mobility initiative. The concerns were around launching mobile applications for various mobile operating systems and platforms, deciding the right communication channels and of course security.</p>
<p>B2C mobile apps architecture involves mobile client apps, middleware applications and external integration services which make it complex. This is true for any company wanting to provide a mobile application to their consumers and not just telecom companies.</p>
<h2>Key Security Risks</h2>
<p>A B2C mobile apps has four major risk categories – mobile client app risk, middleware application risk, mobile applications interfaces risks and device lost / stolen case risks. Below are some major security risks for mobile applications:</p>
<ul>
<ul>
<li>Mobile Client App Security Risks</li>
</ul>
</ul>
<ul>
<ul>
<ol>
<li>A malicious user can perform reverse engineering attacks to get sensitive information on improper signed application.</li>
<li>Weak cryptographic implementation for critical data storage on device&#8217;s local data storage can lead to fraudulent transactions.</li>
</ol>
</ul>
</ul>
<ul>
<ul>
<li>Middleware Application Security risks</li>
</ul>
</ul>
<ul>
<ul>
<ol>
<li>In middleware applications where web services – HTTP, SOAP, REST – are used, an adversary may attempt to intercept request/response messages</li>
<li>Insecure network communications channels may lead to tampering of middleware/interfaces parameters and/or database compromises.</li>
</ol>
</ul>
</ul>
<ul>
<ul>
<li>Mobile Application Interfaces risks</li>
</ul>
</ul>
<ul>
<ul>
<ol>
<li>Mobile applications connect to the backend and database servers through various interfaces. Insecure interfaces may lead to data tampering, Denial of Services and message reply attacks.</li>
<li>Improper data validations may lead to SQL injections, Cross site scripting attacks.</li>
</ol>
</ul>
</ul>
<ul>
<ul>
<li>Device lost/stolen case risks</li>
</ul>
</ul>
<ul>
<ol>
<li>In case of device lost/stolen, un-authorized user may misuse data on device</li>
</ol>
</ul>
<h3>Securing the B2C Mobile Application</h3>
<p>To secure your mobility initiative organizations should focus on security of the entire eco-system including:</p>
<ul>
<li>Mobile client and server applications,</li>
<li>Middleware applications, its interfaces, web services,</li>
<li>Communication channels and</li>
<li>Local device data storage.</li>
</ul>
<p>Securing only one or two components will not help secure the entire chain, since the chain is only as strong as your weakest link.</p>
<p>Top 10 suggestions to secure your B2C mobile application would be:</p>
<ol>
<li>Validate all trusted (local data storage or server data storage) and not trusted (invalid user inputs e.g., special characters) inputs in the mobile client application</li>
<li>Encrypt request and response messages</li>
<li>Use secure web services</li>
<li>Use appropriate security controls for firmware and middleware applications</li>
<li>Encrypt data storage on local handheld devices</li>
<li>Employ a strong authentication mechanism</li>
<li>Release proper signed mobile apps</li>
<li>Remote data wipe configurations to prevent unauthorized access</li>
<li>Session management</li>
<li>Restricting access to the integration services and its configurations</li>
</ol>
<p>Happy mobilizing!</p>
<h4>Author</h4>
<p><strong style="color: #666666;">Mr. Suhas Desai,</strong><br />
Sr. Consultant – Mobile Security Practice<br />
Aujas Risk Management Services</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.aujasnetworks.com/securing-b2c-mobile-applications.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Identity and Access Management: Before and After Scenario</title>
		<link>http://blog.aujasnetworks.com/identity-and-access-management-before-and-after-scenario.html</link>
		<comments>http://blog.aujasnetworks.com/identity-and-access-management-before-and-after-scenario.html#comments</comments>
		<pubDate>Wed, 21 Dec 2011 10:38:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Identity and Access]]></category>

		<guid isPermaLink="false">http://blog.aujasnetworks.com/?p=842</guid>
		<description><![CDATA[Scenario 1: Reduction in Access Management Related Helpdesk Calls Introduction: While Identity and Access management (IAM) projects can solve multiple problems, they can also become complex and time consuming. Most organizations struggle with the question, &#8230;<span class="more-link-span"><a href="http://blog.aujasnetworks.com/identity-and-access-management-before-and-after-scenario.html" class="more-link">Read More </a></span>]]></description>
			<content:encoded><![CDATA[<p><em>Scenario 1: Reduction in Access Management Related Helpdesk Calls</em></p>
<h2>Introduction:</h2>
<p>While Identity and Access management (IAM) projects can solve multiple  problems, they can also become complex and time consuming. Most organizations  struggle with the question, &ldquo;To deploy or not to deploy&rdquo;. Is there an ROI? Are  there real benefits at the end of the tunnel? These are typical questions most  CIOs ask.</p>
<p>  Aujas has implemented large IAM projects for clients across industry  verticals. In a series of articles, we plan to discuss what benefits a client  can expect realistically. We will provide the <strong>&ldquo;Before and After&rdquo;</strong> view by discussing scenarios prior to IAM  implementation and scenarios post implementation.</p>
<p>  In this first article of the series, we are going to cover the aspect  of Helpdesk calls related to access management.</p>
<h2>Client Background: </h2>
<p>The client is a country arm of a global financial services company with  a large user base of over 10,000 and growing. The user base includes internal  users, external users and contractors. Additionally, the organization works  with more than 50,000 agents. The business operations are supported by over 30  business critical applications that are built on diverse and heterogeneous  technology platforms, and managed by different business teams.</p>
<h3>Before IAM:</h3>
<p>One key problem the client had was of managing user identities across  enterprise applications. While there were support teams for each of the  application, there were no universal and common procedure followed for user requests  to avail application access. </p>
<p>  With this approach, although the process for requesting access was  defined, the implementation lacked user ID standardization, strong password  policies, escalation matrix, audit and compliance reports to name a few.</p>
<p>  Users had to remember multiple sets of user IDs and passwords to login  to applications. Because of this, there was a huge backlog in helpdesk calls  for password reset, unlocking accounts and other such requests.</p>
<h2>The Solution:</h2>
<p>Aujas successfully implemented a leading IAM suite to address the client  requirements. The solution included: </p>
<ul>
<li><strong>User Provisioning  System</strong>: To streamline the business processes by defining a centralized control  to manage identity records. The processes to provision access to business  applications were refined to leverage the automated system. Access provisioning  was aligned with roles and a self-service interface was setup to allow users to  request application access and their approvers to grant or reject the request.</li>
</ul>
<ul>
<li><strong>Access Management System</strong>: A comprehensive access  management system comprising web access management and enterprise Single  Sign-on (SSO) was setup. The access management system provided a unified and  dynamic portal for users to see and access their currently approved  applications. This system allowed users to access the web easily, thick client  and terminal based applications in a safe manner without the hassle of  remembering different passwords and policies, thereby drastically enhancing  user experience.&nbsp; <strong> </strong></li>
</ul>
<h3>After IAM: </h3>
<p>Even though the client saw many positive improvements, the biggest  benefits were seen in the following two categories:</p>
<ul>
<li><strong><u>Productivity Increase</u></strong>: The key factor in productivity  increase stemmed from the reduction in <strong>turn-around  time</strong> for Access Provisioning. The turn-around time reduced from an average of  4 days to less than 15 minutes &ndash; a 99% decline.
<p>This led to an enormous  productivity improvement for the client. With an average growth of user base at  30% (3000 employees), the 4 days saved per employee in access provisioning led  to tremendous increase in productivity as the client saved over 12,000 man-days  of effort annually.</li>
</ul>
<ul>
<li><strong><u>Cost savings</u></strong>: Reduction in user account  management related helpdesk calls from 5500 per month to 500 per month (90%  reduction). On an average, a helpdesk call costs $10. Hence, the solution  provided savings of $50,000 per month ($600,000 per annum).
<p>Additionally, the solution  provided savings in lost productivity. Earlier the helpdesk received 100  account lockout tickets per day with an average turnaround time of 4 hours. The  new solution allowed the client to eliminate almost all account lockout  situations (90% reduction). Totally, around 13,000 man-days were saved which  would have been wasted otherwise. </li>
</ul>
<table border="0" cellspacing="0" cellpadding="0" width="98%" style="border:1px solid #CCCCCC;">
<tr>
<td width="22%" nowrap valign="top" style="border:1px solid #CCCCCC;">
<p><strong>&nbsp;&nbsp;Parameter</strong></p>
</td>
<td width="32%" nowrap valign="top" style="border:1px solid #CCCCCC;">
<p><strong>&nbsp;&nbsp;Before IAM</strong></p>
</td>
<td width="32%" nowrap valign="top" style="border:1px solid #CCCCCC;">
<p><strong>&nbsp;&nbsp;After IAM</strong></p>
</td>
<td width="12%" valign="top" style="border:1px solid #CCCCCC;">
<p align="center"><strong>Time saved per annum</strong></p>
</td>
</tr>
<tr>
<td width="22%" valign="top" style="border:1px solid #CCCCCC;">
<p><strong>Turnaround time for access    provisioning</strong></p>
</td>
<td width="32%" valign="top" style="border:1px solid #CCCCCC;" align="left">
<p>&nbsp;&nbsp;4 days</p>
</td>
<td width="32%" valign="top" style="border:1px solid #CCCCCC;" align="left">
<p >&nbsp;&nbsp;&lt; 15 minutes</p>
</td>
<td width="12%" valign="top" style="border:1px solid #CCCCCC;">
<p align="center">12,000 man-days</p>
</td>
</tr>
<tr>
<td width="22%" valign="top" style="border:1px solid #CCCCCC;">
<p><strong>Account lockouts and passwords    resets</strong></p>
</td>
<td width="32%" valign="top" style="border:1px solid #CCCCCC;">
<ul>
<li>4 to 5 hours</li>
<li>100+ accounts lockouts per day</li>
<li>Heavy involvement of a helpdesk team</li>
</ul>
</td>
<td width="32%" valign="top" style="border:1px solid #CCCCCC;">
<ul>
<li>Couple of minutes</li>
<li>Almost zero account lockouts per    month</li>
<li>Users can reset and reclaim their    access using self service</li>
</ul>
</td>
<td width="12%" valign="top" style="border:1px solid #CCCCCC;">
<p align="center">13,000    man-days</p>
</td>
</tr>
</table>
<h2>Conclusion:</h2>
<p>There are definite benefits in terms of automating your access  provisioning system. The primary benefits are around productivity increase and  cost savings and these are only a few of them. We will cover other benefits  like security, risk management and other productivity improvements as we go  along in this series.</p>
<h4>Author(s):</h4>
<p><strong>Mohit Vaish</strong><br />
  Practice  Head &ndash; IAM<br />
  Aujas  Risk Management Services</p>
<p>Ms. Amitha  Raju<br />
  Consultant  &ndash; IAM Practice</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.aujasnetworks.com/identity-and-access-management-before-and-after-scenario.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Smooth Sailing Fallacy &#8211; CEO&#8217;s Watch-Out &#8211; Your ERP may be Insecure!</title>
		<link>http://blog.aujasnetworks.com/the-smooth-sailing-fallacy-ceos-watch-out-your-erp-may-be-insecure.html</link>
		<comments>http://blog.aujasnetworks.com/the-smooth-sailing-fallacy-ceos-watch-out-your-erp-may-be-insecure.html#comments</comments>
		<pubDate>Wed, 21 Dec 2011 06:39:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[SAP Security]]></category>

		<guid isPermaLink="false">http://blog.aujasnetworks.com/?p=828</guid>
		<description><![CDATA[An interesting and thought provoking observation was made by&#160;Richard Rumelt in&#160;McKinsey Quarterly. He says &#8220;There&#8217;s been a dramatic failure in management governance. And so our basic doctrines of how we manage things are in question &#8230;<span class="more-link-span"><a href="http://blog.aujasnetworks.com/the-smooth-sailing-fallacy-ceos-watch-out-your-erp-may-be-insecure.html" class="more-link">Read More </a></span>]]></description>
			<content:encoded><![CDATA[<p>An  interesting and thought provoking observation was made by&nbsp;Richard Rumelt  in&nbsp;<a href="http://www.mckinseyquarterly.com/Management_lessons_from_the_financial_crisis_A_conversation_with_Lowell_Bryan_and_Richard_Rumelt_236" target="_blank">McKinsey  Quarterly</a>. He says &ldquo;There&rsquo;s been a dramatic failure in management  governance. And so our basic doctrines of how we manage things are in question  and need revision.&rdquo; At the heart of this failure is what I call the&nbsp;<strong>&ldquo;smooth  sailing&rdquo; </strong>fallacy. </p>
<p>Here is what  Rumelt says, &ldquo;Back in the 1930s, the Graf Zeppelin and the Hindenburg were the  largest aircraft that had ever flown. The Hindenburg was as big as the&nbsp;<em>Titanic</em>.  Together these vehicles had made 620-odd successful flights when one evening  the Hindenburg suddenly burst into flames and fell to the ground in New Jersey.  That was May 1937.&rdquo;</p>
<p>Years ago, I  had a chance to chat with a guy who had actually flown over Europe in the  Hindenburg. He had this wistful memory of it being a wonderful ride. He said,  &ldquo;It seemed so safe. It was smooth, not like the bumpy rides you get in  airplanes today.&rdquo; Well, the ride in the Hindenburg&nbsp;<em>was</em> smooth,  until it exploded. </p>
<p>The risk that  passengers took wasn&rsquo;t related to the bumps in the ride or to its smoothness.  If you had a modern econometrician on board, no matter how hard he studied  those bumps and wiggles in the ride, he wouldn&rsquo;t have been able to predict the  disaster. The fallacy is the idea that you can predict disaster by looking at  the bumps and wiggles in current results.&rdquo;</p>
<p>To see the  disaster coming, you had to have looked beyond the data about flight  bumpiness&mdash;beyond the professionalism of the staff&mdash;and really think, &ldquo;Does it  make any sense to have people riding in a gondola, strapped to a giant sack of  flammable hydrogen gas?&rdquo; There&rsquo;s just not a data series that lets you think  about that. &nbsp;The history of bumps and  wiggles&mdash;and of GDP and prices&mdash;didn&rsquo;t predict economic disaster. That is the  fallacy most people fall into when they talk about security, Tail risk or Black  Swan events. <strong></strong></p>
<p>If we apply  this logic to any ERP &ndash; I find many ERP customers suffer from the smooth sailing  fallacy. </p>
<ul>
<li>&ldquo;Well &ndash; we implemented SAP 10 years back, IBM is  managing the support and we have no problems!&rdquo; </li>
<li>&ldquo;Our security incidents are insignificant.&rdquo; </li>
<li>&ldquo;Oh we have installed SAP GRC solutions but no  one uses them! And so we are secure!&rdquo;</li>
</ul>
<p><strong>This  smooth-sailing fallacy in security arises when we mistake a measure for reality</strong>.  Mature managers always look deeper than the numbers, deeper than the current  measures. Others just focus on the metrics that are based on past reality. That&rsquo;s  how we get into trouble. </p>
<p>This lesson  is fundamental: you cannot manage by just looking at the results. &nbsp;You  have to have a big picture view of security by applying constant changes in  security issues, technology, protocols and metrics. That means your security  policy which may be 3 years old is useless and you have no security in place. CEOs  and CFOs will use the smooth sailing argument &ndash; Hey! We never had a security  issue in the past 2 years? So why worry now? </p>
<p>You have to  show them what Rumelt said about Hindenburg! A small design flaw can blow them  out of business since the ERP system is the business backbone in many  companies.</p>
<p>So it is  important to focus on three things:</p>
<ol>
<li>Critically question your IT systems &amp; the  Security design &ndash; are they relevant? Are they bullet proof &amp; future proof?  Is there a hidden flaw? </li>
<li>Hope is not a strategy! So create a Security  Team to redesign the IT Security Framework based on a thorough and annual Risk  Assessment (mere adherence to ISO 27001 or ITIL will not do!). Use professional  help if needed.</li>
<li>Execute your plans in a phased manner &ndash; first  time right. Do not try to boil the ocean. Keep this as a continuous improvement  process.</li>
</ol>
<p>Author:<br />
  Dr. Jagan Nathan Vaman PhD CGEIT  CISA<br />
  Chief  Consulting Officer<br />
  <strong>Aujas Risk Management Services</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.aujasnetworks.com/the-smooth-sailing-fallacy-ceos-watch-out-your-erp-may-be-insecure.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>High Performance SAP Security – Guard Your Business, Not Just Your SAP ERP</title>
		<link>http://blog.aujasnetworks.com/high-performance-sap-security-guard-your-business-not-just-your-sap-erp.html</link>
		<comments>http://blog.aujasnetworks.com/high-performance-sap-security-guard-your-business-not-just-your-sap-erp.html#comments</comments>
		<pubDate>Mon, 28 Nov 2011 13:47:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Article]]></category>

		<guid isPermaLink="false">http://6d158577-f05a-40db-8337-31b7942af722</guid>
		<description><![CDATA[Businesses are now inseparable from their IT systems, computers, networks and data; companies are their ERP, which in turn enables most of their business processes. Accordingly, risk management, security and compliance are increasingly viewed as &#8230;<span class="more-link-span"><a href="http://blog.aujasnetworks.com/high-performance-sap-security-guard-your-business-not-just-your-sap-erp.html" class="more-link">Read More </a></span>]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: 12px; font-family: Verdana;">Businesses are now inseparable from their IT systems, computers, networks and data; companies are their ERP, which in turn enables most of their business processes. Accordingly, risk management, security and compliance are increasingly viewed as board level concerns. </span></p>
<p><span style="font-size: 12px; font-family: Verdana;">Maintaining awareness of potential security incidents all the time, every day, is difficult, and knowing how to react to incidents is more difficult still. Your company needs to be ‘right’ all the time, but intruders only need to be ‘right’ once. Imagine an IP, Design, Customer Data, Financial data theft from your SAP system! It can lead to both a reputation loss and a loss of business.</span></p>
<p><span style="font-size: 12px; font-family: Verdana;">Companies that run SAP ERP &amp; their security teams should understand how vulnerable your SAP system is! Here are some facts that might shake you:</span></p>
<ol>
<li><span style="font-size: 12px; font-family: Verdana;">In a typical SAP environment, data transferred between a client and the server is unencrypted. E.g. Any communication with the SAP server using a Desktop or mobile device or client app or portal transmits unencrypted data! It is a high risk area, “client to server un-encrypted communication”, and makes your entire SAP system highly vulnerable.</span></li>
<li><span style="font-size: 12px; font-family: Verdana;">To fix this gap, SAP has recently introduced “SNC Encryption module” in<br />
October 2011 and is a free release for the SAP clients. Through this<br />
small upgrade you can quickly fix one of the most vulnerable areas of<br />
your SAP system.  Point to note here is that this un-encrypted<br />
communication vulnerability existed for a long time in your SAP system<br />
and even now you are vulnerable without this fix.<br />
</span></li>
</ol>
<p><span style="font-size: 12px; font-family: Verdana;">SAP did two acquisitions to provide a Secure SAP system and these are recent events.</span></p>
<ol>
<li><span style="font-size: 12px; font-family: Verdana;">SAP acquired MaxWare Identity Management solution in 2006. This is incorporated as SAP Netweaver Identity Management solution &amp; sold with a licensing model.</span></li>
<li><span style="font-size: 12px; font-family: Verdana;">SAP acquired SECUDE (a Swiss SAP Information security company) software assets in March 2011. With this acquisition came Single Sign-On (Secure Log-In), ESSO – Enterprise SSO and SNC Encryption. </span></li>
</ol>
<p><span style="font-size: 12px; font-family: Verdana;">There is a lot to catch up and be compliant with these security solutions – to ensure a secure SAP environment. To bring you up-to-date on the SAP security and improve your SAP Security posture – you need a roadmap.  </span></p>
<p><span style="font-size: 12px; font-family: Verdana;">The road map broadly should focus on a combination of business focus, scenario analysis and SAP security tools. The combined knowledge of your security experts and a purpose driven SAP security assessments, provide you with a world-class SAP security service at a low cost.</span></p>
<p><span style="font-size: 12px; font-family: Verdana;">High Performance SAP Security road-map is developed with a three phased approach:</span></p>
<p><span style="font-size: 12px; font-family: Verdana;"><strong>1. Assessment</strong> – This phase is designed to understand the ‘as-is’ risk profile of your organization, and how it fits with the business requirements of your enterprise. Based on this assessment you should tailor SAP Security design and controls to monitor and protect key business assets as well as the enabling IT of your enterprise. </span></p>
<p><span style="font-size: 12px; font-family: Verdana;"><strong>2. Implementation</strong> – Deployment of controls processes and tools to put the right monitoring capability in place, and building of the right rule-sets to prioritize and escalate events in line with business priorities. </span></p>
<p><span style="font-size: 12px; font-family: Verdana;"><strong>3. Ongoing Management </strong>–SAP Security process that works on intelligent escalation as required and continuous improvement of your risk management and security posture with a managed SAP Security service. A Security Management Portal should be built so that your company can drill down into the status of threats and remediation actions underway.</span></p>
<p><span style="font-size: 12px; font-family: Verdana;">The benefits of a high performance SAP Security includes:</span></p>
<ul>
<li><span style="font-size: 12px; font-family: Verdana;">Business-focused security delivery model: guard your business, not just your SAP ERP</span></li>
<li><span style="font-size: 12px; font-family: Verdana;">Improved security efficiency as a result of wider SAP Security situational awareness and Business asset aligned prioritization</span></li>
<li><span style="font-size: 12px; font-family: Verdana;">SAP Security and compliance tools, dashboards that provide you with a view of your security posture and results of security improvement programs</span></li>
<li><span style="font-size: 12px; font-family: Verdana;">Improved manageability and reduction in security operating costs</span></li>
<li><span style="font-size: 12px; font-family: Verdana;">Reduced security ‘distraction factor’ so that you can focus on your core business objectives.</span></li>
</ul>
<p>Author:<br />
  Dr. Jagan Nathan Vaman PhD CGEIT  CISA<br />
  Chief  Consulting Officer<br />
  <strong>Aujas Risk Management Services</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.aujasnetworks.com/high-performance-sap-security-guard-your-business-not-just-your-sap-erp.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Aujas signs with Palamida to offer Intellectual Property and Security compliance services</title>
		<link>http://blog.aujasnetworks.com/aujas-signs-with-palamida-to-offer-intellectual-property-and-security-compliance-services.html</link>
		<comments>http://blog.aujasnetworks.com/aujas-signs-with-palamida-to-offer-intellectual-property-and-security-compliance-services.html#comments</comments>
		<pubDate>Wed, 05 Oct 2011 08:49:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Secure Development]]></category>

		<guid isPermaLink="false">http://3235145c-d42b-4a0c-966d-de5929ee1219</guid>
		<description><![CDATA[Software products today are the result of reuse of code from many sources, especially open source software. It is a good strategy, if you go by the principle “Why build when you can re-use?” There &#8230;<span class="more-link-span"><a href="http://blog.aujasnetworks.com/aujas-signs-with-palamida-to-offer-intellectual-property-and-security-compliance-services.html" class="more-link">Read More </a></span>]]></description>
			<content:encoded><![CDATA[<p><font style="font-size: 12px;" color="#17365d" face="arial"></p>
<p><font style="font-size: 10pt;">Software products today are the result of reuse of code from many sources, especially open source software. It is a good strategy, if you go by the principle “Why build when you can re-use?” There are definite benefits including faster time to market and lower costs. The only hitch is open source software comes with their own legal requirements, security issues and intellectual property content.</font></p>
<p><font style="font-size: 10pt;">So it becomes mandatory to have a framework in place to ensure that the security and legal status of resulting applications are managed well. We are seeing an increased demand from our clients to help them understand the content in their software projects. Given that for a lot of applications, more than 50% of code is open source or third party code. </font></p>
<p><font style="font-size: 10pt;">We are pleased to announce a partnership with Palamida, a leader in application security for open source software headquartered in San Francisco. The partnership will help Aujas deliver solutions to assist clients to manage the intellectual property content to their software products. Aujas will enhance our Secure Development life cycle (SDL) services with software composition analysis services, which will help in quickly identifying and track undocumented code, associated security vulnerabilities </font><font style="font-size: 10pt;">as well as intellectual property and compliance issues, enabling organizations to cost-effectively manage and secure mission critical applications and products. </font><font style="font-size: 10pt;">For more information <a href="http://www.aujas.com/open_source_software_security_services.html" target="_blank" class="">click here</a>. <br /></font></p>
<p>Software security is one of the biggest risk in the industry today, and while the industry is definitely taking steps to address this issue, it is still too little given the scale of the issue. We are exploring innovative ways to address these risk and help clients with tackle this issue effectively with our SDL services. Our partnership with Palamida is one more step in this direction. </p>
<p></font></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.aujasnetworks.com/aujas-signs-with-palamida-to-offer-intellectual-property-and-security-compliance-services.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Aujas wins NASSCOM EMERGE 50 2011 award and also Deloitte Technology Fast 50 India 2011 award</title>
		<link>http://blog.aujasnetworks.com/aujas-wins-nasscom-emerge-50-2011-award-and-also-deloitte-technology-fast-50-india-2011-award.html</link>
		<comments>http://blog.aujasnetworks.com/aujas-wins-nasscom-emerge-50-2011-award-and-also-deloitte-technology-fast-50-india-2011-award.html#comments</comments>
		<pubDate>Wed, 05 Oct 2011 08:38:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Announcement]]></category>

		<guid isPermaLink="false">http://8a09d068-1cdf-47a1-92d4-86abff610311</guid>
		<description><![CDATA[Last week was a good week. First we got the news that Aujas has won the Deloitte Technology Fast 50 India 2011 award. And just as we were about to start the celebrations, we got &#8230;<span class="more-link-span"><a href="http://blog.aujasnetworks.com/aujas-wins-nasscom-emerge-50-2011-award-and-also-deloitte-technology-fast-50-india-2011-award.html" class="more-link">Read More </a></span>]]></description>
			<content:encoded><![CDATA[<p><font style="font-size: 12px;" face="Arial">
<p><font color="#002060"><font style="font-size: 12px;"></font>Last week was a good week. First we got the news that Aujas has won the Deloitte Technology Fast 50 India 2011 award. And just as we were about to start the celebrations, we got the news that we are also a NASSCOM EMERGE 50 2011 winner. What better way to begin the new quarter?</font></p>
<p><font color="#002060">The Technology Fast 50 is a global program run by Deloitte, one of the Big 4 and a leading professional services firm. It is a pre-eminent technology awards program which ranks India’s 50 fastest-growing technology companies based on percentage revenue growth over three years. Deloitte has been running this program for last 7 years and previous winners include Fastpipe, iCreate, 3i Infotech and others. This is the first year Aujas participated in the program. </font></p>
<p><font color="#002060">The EMERGE 50 is a program by NASSCOM to celebrate the spirit of entrepreneurship in the emerging business and showcasing success at early growth stage. The objective of NASSCOM EMERGE 50 is to recognize, celebrate, mentor, and offer crucial growth assistance to the next batch of 50 emerging companies. This is the second consecutive year for us where we are part of EMERGE 50.</font></p>
<p><font color="#002060">As Gerard Ekedal said, “Recognition is the greatest motivator.” It is true for people, it is true for employees and it is true for companies as well. The awards are a recognition of all the hard work that everyone at Aujas has put into building a great company. It motivates all of us at Aujas, to try harder and do more as we help our clients “Manage Information Risk and Enhance Value” </font></p>
<p><font color="#002060">Any significant achievement is only possible when everyone involved contributes significantly to the cause. A big thank you to all of the wonderful team at Aujas who have worked so hard to get us here, as well as our supportive Board and investors IDG Ventures India.&nbsp;Working with the team over these last few years through challenging times and creating an entity with 120 people, 150 customers in 15 countries has been a great journey and a life affirming experience about focus, commitment and humility. </font></p>
<p><font color="#002060">We would also like to thank all our clients who have partnered with us in this journey and have guided, supported and helped us. As mentioned earlier, it only motivates us to do more for you and stretch the extra mile.</font>  <font style="font-size: 11pt;" color="#002060"></font><font style="font-size: 10px;"><font style="font-size: 11pt;" color="#002060"><br /></font></font></p>
<p><font style="font-size: 12px;"><font style="font-size: 11pt;" color="#002060">The awards are a good encouragement on this long journey, but it is still a long road ahead. As a wise man once said, “Success is a journey and not a destination.”</font></font></p>
<p></font></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.aujasnetworks.com/aujas-wins-nasscom-emerge-50-2011-award-and-also-deloitte-technology-fast-50-india-2011-award.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Managing Risk of Privileged Access and Activity Management</title>
		<link>http://blog.aujasnetworks.com/managing-risk-of-privileged-access-and-activity-management.html</link>
		<comments>http://blog.aujasnetworks.com/managing-risk-of-privileged-access-and-activity-management.html#comments</comments>
		<pubDate>Tue, 26 Jul 2011 14:32:55 +0000</pubDate>
		<dc:creator>aujasus</dc:creator>
				<category><![CDATA[Identity and Access]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Access Management]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Information technology]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://aujasus.com/?p=761</guid>
		<description><![CDATA[The Problem As organizations continue to leverage IT systems to support their businesses, the requirement of managing privileged users is rapidly emerging. Privileged IDs are the in-built system accounts within applications, operating systems, and databases. &#8230;<span class="more-link-span"><a href="http://blog.aujasnetworks.com/managing-risk-of-privileged-access-and-activity-management.html" class="more-link">Read More </a></span>]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://developer.leadformix.net/aujasblog/wp-content/uploads/2011/07/privileged-access.jpg"><img class="alignright size-medium wp-image-770" title="Privileged access" src="http://developer.leadformix.net/aujasblog/wp-content/uploads/2011/07/privileged-access.jpg?w=300" alt="Managing the risk of privileged access" width="300" height="187" /></a>The Problem</strong><br />
As organizations continue to leverage IT systems to support their businesses, the requirement of managing privileged users is rapidly emerging. Privileged IDs are the in-built system accounts within applications, operating systems, and databases. Additionally, user accounts that are created for administration of systems are also privileged IDs.<br />
These IDs have higher and generally unrestricted authority associated with them to allow efficient system maintenance. As a side effect, these IDs can also be used to make widespread changes to the business systems.</p>
<p><strong>The Risk</strong><br />
Usually, these IDs, especially the ones that are in-built, are shared among the groups of administrators. This method of sharing highly powerful access can cause accountability concerns and non compliance with regulatory requirement, thereby significantly increasing the access risk.</p>
<p>Data can be stolen undetected or IT systems can be sabotaged by misusing the privileged access, since these IDs have access to systems from the backend and can bypass the control deployed for business users.</p>
<p>The rapidly emerging trends of cloud computing, consolidation of data centers, virtualization and hosted application services providers imply growing numbers of IT systems and privileged IDs. Any organization using significant number of IT systems like servers, network devices, desktops, or applications faces the requirement of managing privileged IDs.</p>
<p>Regulatory and government requirements for telecom, banking and IT verticals create an even greater need to address this requirement. Recent prominent and high profile security breaches in these verticals across the globe highlight the degree of access risk caused by inadequate privileged ID management.</p>
<p><strong>What Not to Do</strong><br />
Limiting the privileges granted to these IDs will not mitigate the risk as it will render the useless IDs to perform its functions. Alternatively, some organizations aim to bring in accountability by assigning individual IDs to their administrators in order to eliminate sharing. This approach is helpful only for managing a small number of administrators managing few systems.</p>
<p>In-built IDs will still need to be shared even if administrators use their own individual IDs. To add to the complexity, some IT systems enforce a limit on the number of individual accounts that can be created to manage them. Moreover, the number of individual IDs grows multiplicatively with the increase in both the number of administrators and managed systems.</p>
<p>For example, an admin team of twenty managing a thousand systems can easily be dealing with more than 20,000 IDs. The cost and complexity of managing the lifecycle, enforcing password policies and access controls on so many individual IDs makes this approach suboptimal.</p>
<p><strong>Mitigating the Risk</strong><br />
What is needed is a comprehensive and modular approach to privileged access and activity management. Privileged access and activity management is an identity management domain comprising of the same traditional building blocks of User Provisioning, Single Sign-on and Access Management, Role Management, Password Vault and SIEM tied together with robust solution design based on well thought of policies and procedures.</p>
<p>A good solution approach uses an iterative model to focus on each of these areas and improve them incrementally by understanding how it integrated with other building blocks. This approach allows for a modular solution which not only can solve immediate problems with least disruption and change to the existing practices, but also scale to meet the evolved requirements as the business and expectations grow.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.aujasnetworks.com/managing-risk-of-privileged-access-and-activity-management.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

