pre-con ed: privileged access management for hybrid enterprises

12
World ® ’1 6 Privileged Access Management for Hybrid Enterprises Shawn W. Hank, Sr. Principal Consultant, Security CA Technologies SCX04E SECURITY

Upload: ca-technologies

Post on 08-Jan-2017

181 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

World®’16

PrivilegedAccessManagementforHybridEnterprisesShawnW.Hank,Sr.PrincipalConsultant,SecurityCATechnologies

SCX04E

SECURITY

Page 2: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

2 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

©2016CA.Allrightsreserved.Alltrademarksreferencedhereinbelongtotheirrespectivecompanies.

Thecontentprovidedinthis CAWorld2016presentationisintendedforinformationalpurposesonlyanddoesnotformanytypeofwarranty. The informationprovidedbyaCApartnerand/orCAcustomerhasnotbeenreviewedforaccuracybyCA.

ForInformationalPurposesOnlyTermsofthisPresentation

Page 3: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

3 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Abstract(inonlineagenda)

Privilegedaccountsareacoreattackvectorincountless,devastatingdatabreachesandareincreasinglythefocusofdemandingcompliancemandates.ThissessionwillprovideanoverviewoftheCATechnologiesstrategyforprivilegedaccessmanagement,includinganin-depthexplorationofthekeycapabilitiesofCAPrivilegedAccessManager,suchasforcredentialmanagement;strongauthentication;role-based,leastprivilegeaccesscontrol;commandfiltering,andsessionmonitoringandrecordingfromasinglepointofcontrolacrosstheentirehybridenterprise.You’llalsolearnhowCAPrivilegedAccessManagerprovidestruedefense-in-depthandgreatersecurityforprivilegedaccountsbyseamlesslyworkingwithotherkeyenterprisesolutionsincludingCAPrivilegedAccessManagerServerControl,migrationpathsforCAPrivilegedIdentityManagercustomerstoCAPrivilegedAccessManagerandCAPrivilegedAccessManagerServerControl,andhelpdesksolutionsforprivilegedaccessservicemanagement.

ShawnHank

CATechnologiesSr.PrincipalConsultant,Presales

Page 4: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

4 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Abstract

§ Privilegedaccountsareacoreattackvectorincountlessdevastatingdatabreaches,andareincreasinglythefocusofdemandingcompliancemandates.ThissessionwillprovideanoverviewofCATechnologiesstrategyforprivilegedaccessmanagement,includinganin-depthexplorationofthekeycapabilitiesofCAPrivilegedAccessManager,CATechnologiessolutionforprotectinganddefendingprivilegedaccountsandcredentialsfromattack,andmanaging,controlling,andauditingtheactivitiesofprivilegedusers

Page 5: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

5 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

TheCASolutionPortfolioComprehensivePrivilegedAccessManagement

§Ac

cessre

quests

§Ce

rtificatio

Riskana

lytic

s

§ Strongauthentication,includingMFA§ Credentialmanagement§ Policy-based,leastprivilegeaccesscontrol§ Commandfiltering§ Sessionrecording,auditing,attribution§ Applicationpasswordmanagement§ Comprehensive,hybridenterpriseprotection§ Self-contained,hardenedappliance

§

§ In-depthprotectionforcriticalservers§ Highly-granularaccesscontrols§ Segregateddutiesofsuper-users§ Controlledaccesstosystemresourcessuchas

files,folders,processesandregistries§ SecuredTaskDelegation(sudo)§ EnforceTrustedComputingBase

IDENTITY-BASEDSECURITY HOST-BASEDSECURITY

DEFENSEINDEPTH

CAPrivilegedAccessManager CAPrivilegedAccessManagerServerControl

CAID

ENTITYSUITE

Page 6: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

6 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

CAPrivilegedAccessManagerPrivilegedAccountManagementfortheHybridEnterprise

HYBRIDENTERPRISETraditionalDataCenter

Mainframe,Windows,Linux,Unix,Networking

EnterpriseAdminTools

SoftwareDefinedDataCenter

SDDCConsoleandAPIs

PublicCloud- IaaS

CloudConsoleandAPIs

SaaSApplications

SaaSConsolesandAPIs

HardwareAppliance AWSAMIOVFVirtualAppliance

IdentityIntegration Enterprise-ClassCore

CAPrivilegedAccessManager

§ VaultCredentials§ CentralizedAuthentication§ FederatedIdentity§ PrivilegedSingleSign-on

§ Role-BasedAccessControl§ MonitorandEnforcePolicy§ RecordSessionsandMetadata§ FullAttribution

ANewSecurityLayer- ControlandAuditAllPrivilegedAccess

UnifiedPolicyManagement

Page 7: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

7 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

HYBRIDCLOUDENVIRONMENT

IntegratedControlsandUnifiedPolicyManagement

Positively

Authen

ticateUsers

Vault&

Manage

Cred

entia

ls

RestrictA

ccessto

Authorize

dSystem

s

Fede

rateIden

tity

andAttributes(SSO

)

Mon

itora

nd

EnforcePo

licy

RecordSessio

ns

andMetadata

AttributeIden

tity

forS

haredAccoun

ts

TraditionalDataCenter

PrivateCloud

PublicCloud

CAPrivilegedAccessManagerinaction

Page 8: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

8 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Demonstration

Page 9: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

9 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

ResultsCAPrivilegedAccessManagerisacentralcomponentofCATechnologiesportfolioofprivilegedaccessmanagementsolutions.Itdeliverscomprehensivefunctionality,spanningtheentirehybridenterprise,inaformfactorthat’sfastandeasytodeployandavoidsadditionalhiddencosts.

SummaryAFewWordstoReview

Page 10: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

10 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

RecommendedSessions

SESSION# TITLE DATE/TIME

SCX15E MeettheCAPrivilegedAccessManagerTeam 11/14/2016at11:00am

SCX29E DeepDive:CAPrivilegedAccessManager 11/14/2016at1:00pm

SCT22S CARoadmap:PrivilegedAccessManagement 11/16/2016at4:30pm

Page 11: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

11 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Don’tMissOurINTERACTIVESecurityDemoExperience!

SNEAKPEEK!

11 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Page 12: Pre-Con Ed: Privileged Access Management for Hybrid Enterprises

@CAWORLD#CAWORLD ©2016CA.AllRIGHTSRESERVED.12 @CAWORLD#CAWORLD

Security

FormoreinformationonSecurity,pleasevisit:http://cainc.to/EtfYyw