Identity Management Controls in the Cyber Kill Chain
Morey J. Haber, Darran Rolls · Apress eBooks · 2019
Managing and appropriately governing identities using an Identity Governance solution can make a big difference to the security posture of an organization. To best understand how, we must first learn from our collective past mistakes and omissions. Looking back over recent data breach reports and examining the forensic and post-incident analysis, we notice two things relative to the discussion on identity management controls. The first is that threat sophistication is increasing at a furious rate. The adversary is persistent and well funded and knows where best to attack and pursue persistence. The second is that these forensic reports clearly show that identity management mistakes and weaknesses are the common faults in many breaches. These identity management mistakes and process weaknesses are things like poor account controls; weak passwords; orphan, dormant, and rogue accounts; weak inventory of entitlements; and the over-assignment of user privileges. These mistakes and management missteps tend to be spread across the Cyber Kill Chain.