It all starts with a PDF attachment. An employee doesn’t detect the signs of a social engineering attack, and so they open the attachment on their work-issued laptop, not knowing that their computer has local administrator access. Invisible malware then edits the laptop’s registry and erases the audit trails as it infiltrates the whole network. And this entire security breach could have been prevented with the principle of least privilege.

Identity and access management (IAM) issues aren’t technically the leading cause of data breaches, but they’re definitely contributors. Countless enterprises are still using static, role-based access methods from the pre-cloud era, but assigning local admin group privileges based on a user’s job title is a recipe for overprivileged users and widespread vulnerabilities.

The Principle of Least Privilege Means Minimal Trust

The principle of least privilege is a simple cybersecurity concept. It means assigning the least amount of capabilities possible to accomplish a task and limit the possible impact of identities and applications dynamically in order to limit risk exposure. A least-privilege model balances risk, productivity, security and privacy in environments where workloads and risks change constantly.

Minimal trust describes the concept of providing the least privilege possible to get the job done. It’s a risk-based model for IAM that requires a dynamic approach to security, privacy and privilege. The benefits of privileged access management are obvious, but implementing the idea will require some work.

The Overprivileged Account Epidemic

How bad is the crisis of overprivilege, anyway? One study from Centrify found that 72 percent of enterprises know they struggle to control excessive admin accounts, but the actual figure is likely higher. Experts estimate up to 99 percent of user privileges are unused and represent points of failure, according to MIS Training Institute.

And humans aren’t the only privileged users in the enterprise. “Identity” extends to anything that can access secure resources, including service accounts and APIs. MIS Training Institute noted that users represent just one-seventh of an enterprise’s identities. There’s an epidemic of issues concerning privileged access management among human users, but that’s just the tip of the iceberg.

Putting the Principle of Least Privilege to Work

The principle of least privilege isn’t a formula. Minimal trust is a concept, and it’s a moving target. Any efforts to mitigate privileged access management issues are worthwhile if they reduce vulnerabilities. For example, simply targeting overprivileged user accounts can have an effect. Targeting excessive local admin privileges can significantly reduce the risks of patch vulnerabilities. More than 80 percent of patch vulnerabilities on operating systems require admin privileges for a successful exploit.

Putting the least privilege principle into practice means finding the perfect balance between user trust, privacy and security across identities, applications and services. Getting there requires adopting a new IAM life cycle for minimal trust, which involves:

  • Discovery
  • Defining policy
  • Managing
  • Detecting and responding
  • Reviewing and auditing

Discover

The first step is an assessment of assets, identities, access and risk. To that end, a data risk assessment can reveal a comprehensive index of your assets and the risks they pose. Identity your business-critical assets based on which ones would have the greatest impact on the enterprise if they were breached, stolen or compromised.

Identify privileged accounts and map access pathways between identities and assets. Understand where privileged identities exist across all types of identities, including both internal and external users, services, applications and systems. Next, map all possible points of privileged access, including hardware, software, on-premises environments and those that exist in the cloud.

Discovery needs to be a comprehensive effort to see all privileged account management concerns, including third-party access issues and cloud vulnerabilities. This is an opportunity to see legitimate use cases for privileged access and instances of excessive permission.

Define Policy

Dynamic access policies are the foundation of the least privilege principle. To orchestrate and automate minimal trust, you need policies that dictate the baseline for trust. To that end, create an application whitelist and blacklist. For example, whitelisting for trusted apps and processes could include an “always trust” policy for mobile apps downloaded from your corporate app store. A blacklist policy might set a policy to “always quarantine and monitor” applications that come from sources other than verified vendors.

Your policies define the level of risk you’re willing to accept in applications, identities and services and how you monitor and verify access to secure assets based on a user’s behavior. An effective policy balances security and trust with minimal disruption to the end user. You may choose to “always verify” external user identities (by requiring credential sign-in and multifactor authentication (MFA) or biometrics) and grant trust to internal users on known devices.

Manage

Discovering privileged accounts and defining policies are ongoing processes. Least privilege in a dynamic enterprise environment requires a continual effort to apply controls based on actual risk by auditing behavior for anomalies and adopting controls that identify potential abuse.

Orchestration and automation are key to making ongoing management efforts seamless. Solutions that help to orchestrate least-privilege security can remove potential points of exposure in ways that are invisible to users by elevating and removing privileges in real time. In other cases, you can establish trust quickly for legitimate access attempts by requiring one-time passwords to protect the most business-critical assets.

The management stage of the life cycle involves ongoing efforts to discover privileged accounts, audit usage and apply new security controls and policy. Automation and orchestration efforts can help the enterprise elevate user privileges on-demand and increase or decrease identity privileges based on emerging risks or threats. In practice, the principle of least privilege means limiting overprivileged accounts and providing seamless access to trusted users.

Detect and Respond

Least privilege implementation requires continual detection of unnecessary privilege, compliance issues or risky behavior. Ongoing detection efforts may reveal and resolve instances where an identity no longer needs privileged access. Behavioral analytics are key to detecting anomalies without disrupting end users.

The principle of least privilege allows organizations to respond to a user’s context or unusual behavior. Sign-in attempts from a new location or device could trigger a requirement for identity verification, while high-risk behavior results in the immediate quarantine of a user account or application.

Detection and response are highly contextual, and data is needed to balance user requirements with risk. Orchestration and automation solutions can escalate privileges seamlessly during legitimate access attempts and immediately respond to risks, such as user attempts to download blacklisted applications.

Review and Audit

Protecting your assets requires a clear audit trail of applications, identities and response activities, and successful adoption of the least privilege principle is a moving target. Reviewing audit trails is necessary for compliance, and it can reveal progress toward putting minimal trust to work.

Review and audit activities should tell a clear story about your organization’s compliance and success at contextual privileged account management, such as instances where a graylisted application was quarantined in a sandbox environment. Review key metrics over time to monitor privileged account ownership or policy-based application controls and use this intelligence to refine the life cycle.

Balance Risk, Security and Trust

Effective enforcement of the principle of least privilege requires a life cycle mindset and coordinated efforts between security, IT, risk and compliance leadership. Minimal trust in practice requires effective policy and solutions that help orchestrate and automate IAM. Balancing security with trust requires ongoing monitoring and response across identities, endpoints and environments.

More from Identity & Access

CISA, NSA Issue New IAM Best Practice Guidelines

4 min read - The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) recently released a new 31-page document outlining best practices for identity and access management (IAM) administrators. As the industry increasingly moves towards cloud and hybrid computing environments, managing the complexities of digital identities can be challenging. Nonetheless, the importance of IAM cannot be overstated in today's world, where data security is more critical than ever. Meanwhile, IAM itself can be a source of vulnerability if not implemented…

4 min read

The Importance of Accessible and Inclusive Cybersecurity

4 min read - As the digital world continues to dominate our personal and work lives, it’s no surprise that cybersecurity has become critical for individuals and organizations. But society is racing toward “digital by default”, which can be a hardship for individuals unable to access digital services. People depend on these digital services for essential online services, including financial, housing, welfare, healthcare and educational services. Inclusive security ensures that such services are as widely accessible as possible and provides digital protections to users…

4 min read

What’s Going On With LastPass, and is it Safe to Use?

4 min read - When it comes to password managers, LastPass has been one of the most prominent players in the market. Since 2008, the company has focused on providing secure and convenient solutions to consumers and businesses. Or so it seemed. LastPass has been in the news recently for all the wrong reasons, with multiple reports of data breaches resulting from failed security measures. To make matters worse, many have viewed LastPass's response to these incidents as less than adequate. The company seemed…

4 min read

Cybersecurity in the Next-Generation Space Age, Pt. 3: Securing the New Space

8 min read - View Part 1, Introduction to New Space, and Part 2, Cybersecurity Threats in New Space, in this series. As we see in the previous article of this series discussing the cybersecurity threats in the New Space, space technology is advancing at an unprecedented rate — with new technologies being launched into orbit at an increasingly rapid pace. The need to ensure the security and safety of these technologies has never been more pressing. So, let’s discover a range of measures…

8 min read