In The Spotlight
The main reason for installing a PAM system is to provide greater security to the granting of access to systems at a specialist functionality level.
by Graham Williamson
Editor’s note: This chapter is excerpted from chapter 4 of Identity Management: A Business Perspective.
Benefits
There are some added side benefits:
- Logging and monitoring of access to systems at a privileged level can be enabled. If a user remains online for extended periods of time, an alert can be raised and action taken. While this might not indicate nefarious activity, limiting access and returning users to a lower privileged account can minimize the opportunity for mistakes that might inadvertently cause business disruption.
- PAMs can be configured to automatically notify a manager whenever a privileged account has been accessed. This provides an extra level of monitoring that lessens the likelihood of privileged account abuse.
- PAMs can also be used to provide additional protection to relying systems. For instance, if system administration work is undertaken only in business hours, the PAM system can restrict access to elevated privilege accounts outside business hours.