BR +55 11 3069 3925 | USA +1 469 620 7643

  • BLOG
  • Português
  • BR +55 11 3069 3925 | USA +1 469 620 7643
  • Português
logo senhasegura
  • SOLUTIONS
  • PRODUCTS
  • SERVICES AND SUPPORT
  • PARTNERS
  • COMPANY
  • CONTACT
  • DEMO

Compliance

and Audit

Audit

PCI DSS

SOX

ISO 27001

HIPAA

NIST

GDPR

ISA 62443 |

Industry 4.0

Security and

Risk Management

Privilege Abuse

Third Party Access

Privileged Access Recording

Insider Threat

Data Theft Prevention

Hardcoded Passwords

Password Reset

Solutions

By Industry

Energy and Utilities

Financial

Government

Health Care

Legal

Telecoms

Retail

senhasegura

Testimonials

See Testimonials

360º Privilege Platform

Account and

Session

PAM Core

Domum

Remote Access

MySafe

GO Endpoint

Manager

GO Endpoint

Manager Windows

GO Endpoint

Manager Linux

DevOps Secret

Manager

DevOps Secret

Manager

Multi

Cloud

Cloud IAM

Cloud Entitlements

Certificate

Manager

Certificate

Manager

Privileged

Infrastructure

PAM Crypto Appliance

PAM Load Balancer

Delivery : On Cloud (SaaS) | On-premises | Hybrid

Services

and Support

Documentation

Solution Center

Suggestions

Training and Certification

Deployment and Consulting

PAMaturity

PAM 360º

Support Policy

senhasegura

Resources

Rich Materials

Customer Cases

Webinars Calendar

senhasegura Stickers

BLOG

CONTENT

Is your company really prepared for a cyber attack?

The Pillars of Information Security

7 signs that your company needs to improve the security of sensitive data

See more articles about cybersecurity

Technical

Information

How it works

Product Archicture

Integration

Security

High availability and contingency

Privileged Auditing (Configuration)

Privileged Change Audit

Features and

Functionalities

ITSM Integration

Behavior Analysis

Threat Analysis

Privileged Information Protection

Scan Discovery

Task Management

Session Management (PSM)

Application Identity (AAPM)

SSH Key Management

Affinity Partner

Program

About the Program

Become a Partner

MSSP Affinity Partner Program

Security Alliance Program

Academy | E-learning for Certification

Affinity

Portal

Portal dedicated only for Partners to find commercial, marketing supporting materials and certification program of senhasegura.

Access Partner Portal

Opportunity

Booking

For our Commercial Team to support your sale more effectively, request your opportunity booking here.

Opportunity Booking Request

Find a

Partner

We work together to offer a better solution for your company.

Check all senhasegura partners

About

Company

About us

Achievements

Why senhasegura

Press Release

Press Room

Events

Career

Presence in the World

Terms of Use

End User License Agreement (EULA)

Privacy and Cookie Policy

Information Security Policy

Certification at senhasegura

senhasegura

Testimonials

See Testimonials

Latest Reports

and Awards

KuppingerCole Leadership Compass Report for PAM 2023

Frost & Sullivan Customer Value Leadership Award 2022

Gartner PAM Magic Quadrant 2021 Report

KuppingerCole Leadership Compass: PAM 2021

GigaOm Radar Report 2021

Gartner PAM Magic Quadrant 2020

Gartner Critical Capabilities for PAM 2020

Information Services Group, Inc. (ISG)

KuppingerCole Leadership Compass: PAM 2020

Contact our team

Request a Demonstration

Privileged Access Management and PEDM

by senhasegura Blog Team | Feb 28, 2020 | BLOG

In a cybersecurity context, the privilege aspect is understood as the level of authorization for access (and control) over IT systems, information assets, and applications. In this specific context, low control over privileged user accounts is usually a source of risk in organizations, both from a security and compliance perspective. As outsourcing by using cloud-based services becomes essential to business, organizations need to find a way to have governance over their critical assets and operations through proper control of the privileges granted, not only for employees but also for third parties and service providers. 

In a world increasingly focused on approaches based on Zero Trust, the Information Security area must make efforts to reduce the risks of attacks performed by individuals with privileged credentials throughout the infrastructure.

With that in mind, it is understood how an effective control if required for privileges of access to the critical systems and the continuous monitoring of actions performed by means of administrative credentials within an organization, such as Privileged Access Management (PAM).

PAM solution

A PAM solution is capable of handling all aspects related to privileged accounts, both user and system-related. System accounts include service accounts, hard-coded credentials, and any other account not necessarily owned by an individual. Actions linked to these credentials include provisioning and de-provisioning access, certification of account access in the systems, and generation of audit logs for all privileged actions performed through these accounts.

According to Gartner, PAM-related technologies provide secure privileged access in order to meet business requirements (auditing, for example). This is accomplished by protecting, managing, and monitoring privileged access and accounts. In addition to the controls associated with user access, technologies linked to PAM are also able to reduce cyber risks and the attack surface through the secure storage of credential passwords, both the personal and system ones.

What is PASM?

 

Accounts stored in a PAM solution are the most critical. In this case, many Information Security policies used in organizations may provide for complex requirements for these passwords, including their frequent changes. Regulatory requirements and cybersecurity best practices require that these passwords are unknown to most people within the organization. Thus, in addition to controlling connectivity to administrative systems, the features of a PAM solution will allow the management of access, the life cycle of privileged credentials, and the audit of privileged actions performed by these credentials. Finally, passwords can be rotated by the end of the respective accesses. Within the PAM universe, this is called Privileged Account and Session Management, or PASM.

However, PAM features linked to PASM grant access based on a “hit or miss” paradigm. Therefore, the user is able to gain access to all the resources of a system, including applications or scripts that they normally would not need or could not access, according to the organization’s policies. As a consequence, if the credential is compromised, a malicious agent could have unrestricted access during the legitimate user’s access period. In this case, many PAM solutions have Privilege Elevation and Delegation Management, or PEDM.

PEDM solutions are a type of PAM solution developed to grant access to the user in different environments in a granular way. A user may, for example, need temporary access to IT resources that they normally would not have access to. In these cases, organizations need a way to provision and grant access only during the required period of time, reducing the attack surface and, consequently, the risks associated with the theft or compromise of an administrative credential.

But, how does a PEDM solution work?

This type of solution typically allows users to work with ordinary user accounts, eliminating the need for administrative accounts. So, privileges for performing actions are granted only to specific applications, scripts, and tasks. The result of this is the reduction or elimination of the number of administrative credentials in the environment through the implementation of a just-in-time least privilege model, which results in reduced attack surface and risk of external threats or human errors.

A PEDM solution, such as senhasegura, ensures a just-in-time approach based on the least privilege model in daily operations, facilitating the process of assigning, changing, and auditing privileges.  In this way, PEDM solutions provide an additional layer of protection that allows organizations to rely entirely on the use of privileged credentials. 

The features of a PEDM solution as senhasegura include:

  • Role-based access controls: It allows the implementation of the least privilege concept, which brings greater control over users’ privileges. Consequently, it is possible to reduce the risks of a range of threats. The access granularity of senhasegura simplifies the implementation of least privilege models in Linux and Windows environments.
  • Access requests based on approval workflow: The solution must allow the invocation of administrator privileges to run applications, considering the control by lists of authorized actions. In addition, it should be possible to protect Linux and Windows systems from the configuration of approval workflows at one or multiple levels.
  • Windows features: Access to Windows Control Panel operations with administrative privileges. Moreover, the solution must allow the invocation of administrator privileges to access sensitive data shared on the network, ensuring the protection of files and directories from threats.
  • Auditing and compliance: All requests for use of administrative credentials must be recorded in session logs, allowing for greater traceability of user actions and easier auditing of privileged activities and actions.

When it comes to cybersecurity, the different components of the infrastructure may demand different solutions involved with PAM. It is therefore recommended to use PASM and PEDM solutions together. While access management and credentials features in isolated applications can be solved with PASM, critical infrastructure such as server environments are best covered with PEDM solutions. Despite being different approaches, PEDM and PASM are complementary, allowing, as a consequence, the creation of a complete, secure, and reliable solution.

← The Cybersecurity Frameworks and PAM Ransomware: what it is, how it works and how to avoid it →

$13 million growth investment drives senhasegura’s expansion in North America and the Middle East

Written by Priscilla Silva São Paulo, March 10, 2023 - senhasegura, an award-winning Privileged Access Management (PAM) solution provider that protects corporate IT environments and critical resources from cyber threats, announces a $13 million funding round from...
Read More

senhasegura wins CyberSecured 2022 award as best PAM solution in the USA

Written by Priscilla Silva SÃO PAULO, February 28 of 2023 - The 2022 edition of the CyberSecured awards, promoted by Security Today magazine, a brand of 1105 Media's Infrastructure Solutions Group, elected senhasegura as the winner in the Privileged Access Management...
Read More

How User and Entity Behavior Analytics Helps Cybersecurity

Cyberattacks are increasingly sophisticated, making traditional digital security tools insufficient to protect organizations from malicious actors. In 2015, Gartner defined a category of solutions called User and Entity Behavior Analytics (UEBA).Its big advantage is...
Read More

Best Practices for Consolidating Active Directory

This article was developed especially for you, who have questions about the best practices for consolidating Active Directory. First of all, you need to understand that directory services have the role of organizing important information for companies in a centralized...
Read More

senhasegura introduces the “Jiu-JitCISO” concept to show the power of Brazilian cybersecurity

Written by Priscilla Silva São Paulo, January 13, 2023 - "Like Jiu-Jitsu senhasegura is about self-defense. Every company must know how to protect itself and its clients". This is the aim based on the philosophy of the Japanese martial art, but made popular and...
Read More
Copyright 2023 senhasegura | All Rights Reserved | Powered by MT4 Group