21. Administrative Personnel Controls Flashcards
Administrative Personnel Controls
Administrative Security
Means to control peoples operational access to data
Administrative Personnel Controls
Least privilege
Minimum necessary access - No more, no less
- exactly the access rights they need
- Go through the adminsitrative process in the future if change of access is required in the future
- Requires a lot of time and effort to maintain - not ideal for emergency situations
Administrative Personnel Controls
Need to know
Even if you have access, you do not need to know, you should not have access
*
Administrative Personnel Controls
Separation of Duties
Internal control inteded to prevent fraud and error
- Large organisations. Same person entering a purchase order does not issue the check
- If one person can do all the admin controls himself, fraud is more likely
- Exam assumes large organisation
Administrative Personnel Controls
Job Rotation
Detect Errors and Frauds
- Less change of collusion between individuals if they rotate jobs
- Helps avoid employee burnout
- Can be cost prohibitive IRL
- EXAM HINT: make sure cost justifies the benefit
Administrative Personnel Controls
Mandatory Vacations
Ensure one person is not always performing the same task
- Accounts can be locked and audited
- Audit will discover fraud if employee has been covering it up
- Give little or not notice
Administrative Personnel Controls
Minimise insider threats with the 5 controls
- Least privilege
- Need to know
- Seperation of duties
- Job rotation
- Mandatory Vacations
Administrative Personnel Controls
NDA
New Employee
Non Disclosure Agreement
- Clauses restricting employees use and dissemination of company owned confidential information
Administrative Personnel Controls
Background Checks
New Employee
- References
- Degrees
- Employment
- Criminal
- Credit history
- Typically for sensitive positions
- Can be an ongoing process
Administrative Personnel Controls
Privilege Monitoring
New Employee
Monitoring highly privileged employees
- The more privilege an employee has, the more we need to keep an eye on them
- More access = more responsibility = more scrutiny
- Privileged employees can expose more risks
- Should be automated as much as possible
Administrative Personnel Controls
PAM
Privileged Account/Access Management
- Account - Account safeguarded
- Access - What the account has access to
- Monitor What, when, how, why, where
Administrative Personnel Controls
Regular Users
PAM Monitoring
Analyse Performance
Improve Efficiency
Administrative Personnel Controls
Privileged Users
PAM Monitoring
Access Matrix
(what changed?)
- what was done, why, where, when
Administrative Personnel Controls
All Users
PAM Monitoring
- Sensitive Data
- Critical Systems
- Insider/Outsider threats
- Compliance/regulatory requirements
Administrative Personnel Controls
Systems
PAM Monitoring
- All servers (incl Jumpboxes)
- Endpoints
- Remote workstations