Hello Everyone,
I have a scenario(s) that I’d like to discuss options/thoughts on:
Tightening existing controls and SLAs is one thing but I need to balance security and reasonable controls. Note: this might be an environment that has 2000+ applications, 30,000+ users (this stat is useful as not all small environment solutions can be applied to larger organisations)
Scenario:
-
Disgruntled Admin Employee: An employee with access to a web application that lacks SSO (Single Sign-On).
-
Correlation Rule and Configuration: In IIQ, the correlation rule is based on the ‘email address’.
-
NCD is not applied on this application.
Risk:
-
Creation of Rogue Account:
-
The admin creates a rogue account with an email address that does not correlate with any existing identity in IIQ.
-
Termination of Employment:
-
The Admin employee is fired today.
-
Uncorrelated Account Visibility:
-
The uncorrelated account appears in in the uncorrelated accounts report
-
Potential Exploitation:
-
During the period before the uncorrelated account is deleted, the ex-employee could log into the web app portal using the rogue account.
-
Since the account is uncorrelated and not part of an automated leavers process, it wasn’t linked to any HR identity.
-
The ex-employee could:
- Delete numerous staff accounts.
- Cause an outage and business impact.
- Affect clients.
- Potentially lose historic data.
- Leak PII (Personally Identifiable Information) by downloading information onto a personal device.
-
-
-
-
-
Investigation:
-
Once the uncorrelated account is discovered, an investigation begins.
-
Often, the account is simply correlated to an existing old identity cube without checking the lifecycle status. In this scenario, they would delete the account as there is no HR record to link it to.
-
We have a UAM process removes old access linked to identity cubes it finds.
-
There is a window of a few days or potentially weeks where unauthorised access and malicious activities could continue.
________
Scenario 2:If I am a disgrunted admin of an application with no SSO who creates an additional account but uses an email address that correlates to an existing IIQ identity cube that has an inactive HR record) which is then missed until the next application user access review which is on a frequency based on the risk rating.
________
Scenario 3:
If I am a disgrunted admin of an application with no SSO who creates an additional account but uses an email address that correlates to an existing IIQ identity cube that has an active HR record) which is then only noticed in our reporting until the next application user access review which is on a frequency based on the risk rating.