{"id":44733,"date":"2020-01-08T16:02:15","date_gmt":"2020-01-08T16:02:15","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/2020\/01\/08\/a-single-security-recommendation-to-solve-an-age-old-problem\/"},"modified":"2020-01-15T14:14:40","modified_gmt":"2020-01-15T14:14:40","slug":"a-single-security-recommendation-to-solve-an-age-old-problem","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2020\/01\/08\/a-single-security-recommendation-to-solve-an-age-old-problem\/","title":{"rendered":"A single security recommendation to solve an age-old problem"},"content":{"rendered":"\n<p><em>Password management is undoubtedly one of the most basic security practices yet it is one that people struggle with the most when it comes to operating securely. Morey Haber, CTO &amp; CISO, BeyondTrust, offers his advice to ensuring a best practice approach to password security.<\/em><\/p>\n\n\n\n<p>In the cyber world, we\u2019re exposed to an onslaught of recommendations and top lists for improving IT security. They may have some universal characteristics, but are infrequently not relevant for adoption by everyone, everywhere and at every time. In fact, can you guess what the number one, universal and best security recommendation is for everyone to embrace? Here\u2019s a hint, it is related to passwords.<\/p>\n\n\n\n<p>To further set the stage for this recommendation, let\u2019s consider all the infosec recommendations we experience on a daily basis. These include everything from security skills and cyber-awareness training to&nbsp;patch management. They target problems from&nbsp;phishing&nbsp;to&nbsp;vulnerability management, but are not necessarily relevant to every employee within an organisation, nor are they necessarily relevant to each person on their personal devices at home.<\/p>\n\n\n\n<p>While it is common knowledge to\navoid email spam, and employees are often trained on how to identify suspicious\nemails and advised not to click on suspicious links, it is interesting\nthat&nbsp;younger generations are far less likely to embrace email&nbsp;outside\nof the corporate enterprise. Instant messaging and other forms of social media\nare their tools of choice, which suggests that traditional email may slowly\nfade away like postal correspondence, or the fax machine. The demise of email\nmay take a few more decades to transpire, but this downshift is well underway.<\/p>\n\n\n\n<p>All of this helps further refine the\nsingle best recommendation. Remember, we need to consider a universal security\nrecommendation that translates to everyone.<\/p>\n\n\n\n<p><strong>Fixing an age-old security issue<\/strong><\/p>\n\n\n\n<p>Regardless of persona at home or at work, the one thing everyone uses are passwords. We use passwords for work, for resources on the Internet, for social media and for our applications. We use them in the form of passcodes and PINs for banking, mobile devices and for office and home alarm systems. Passwords are ubiquitous and we use them constantly \u2014 even on newer systems that ironically claim to be &#8216;password-less&#8217;. In these instances, a mechanism under the hood is still identifying your access rights and storing that &#8216;somehow&#8217;.<\/p>\n\n\n\n<p>The most common storage of any password is within a single human brain. We assign a password to a system or application, recall it when it needs to be used and hopefully remember it each time we change it. Our brains are full of passwords and often we forget them, reuse them, need to share them and are forced to document them on post-it notes, spreadsheets and even communicate them via email or SMS text messages (a very poor security practice).<\/p>\n\n\n\n<p>These insecure methods for creating, sharing and reusing passwords are responsible for the types of data breaches that routinely make the front-page news, serving as cautionary tales of what is at high-risk of happening when good password management strategies are not adhered too. The ramifications crisscross both our professional and personal lives.<\/p>\n\n\n\n<p>Passwords literally can be found everywhere and we need at least one basic tenant to help fix a thousand-year old problem. Therefore, the most important security recommendation for everyone is to ensure that every password you use is unique and not shared with any other resource (including people) at any other time.<\/p>\n\n\n\n<p>While there is no denying that remembering an already considerable and ever-expanding list of passwords (an average of 120 for the modern-day corporate user) is improbable for most humans, there are&nbsp;password management&nbsp;tools, solutions and techniques for making this a reality, thereby going a long way towards reducing password-related threats.<\/p>\n\n\n\n<p>Modern operating systems, browsers and applications can help create unique passwords for every resource, and securely store them for retrieval in lieu of a human having to remember every single one. The passwords are basically stored behind one unique &#8216;master&#8217; password (it may also be referred to as a &#8216;key&#8217; or &#8216;secret&#8217;) that only the individual knows. While this is good solution for home and small business users (to a limited degree), it does not scale to most businesses that need to share accounts (due to technology limitations) and automatically generate unique passwords, such as to keep up with employee changes or to meet regulatory compliance guidelines.<\/p>\n\n\n\n<p>Another security best practice to be mindful of \u2014 a password alone should never be the only&nbsp;authentication&nbsp;mechanism for critical data, sensitive systems and potentially daily operations into those resources.&nbsp;Multi-factor authentication (MFA)&nbsp;or two-factor authentication (2FA) should be layered on top to ensure a unique password, per account, is actually being used by the correct identity when authentication is required.<\/p>\n\n\n\n<p>One key merit of this universal\nsecurity recommendation is that it ensures that if your password is stolen,\nleaked, or inappropriately used, it can only be leveraged against the\ncorresponding resource assigned (if MFA or 2FA is not present). If passwords\nare unique, a&nbsp;threat actor&nbsp;cannot use one compromised account and\npassword to attack other resources. The attacker\u2019s options and movement are\nsignificantly limited, though they could try to leverage advanced techniques to\nsteal other credentials from the system they have compromised, such as by\nscraping passwords from memory. In that case, not only generating unique\npasswords, but also&nbsp;rotating passwords&nbsp;frequently will help mitigate\nthe attack. <\/p>\n\n\n\n<p>Solutions for&nbsp;privileged password management&nbsp;across an organisation\u2019s entire information and security infrastructure can help. Advanced tools provide automated management for sensitive accounts and passwords (including&nbsp;SSH key management), such as shared administrative accounts, application accounts, local administrative accounts and service accounts, across nearly all IP-enabled devices. <\/p>\n\n\n\n<p>This helps ensure this top\nsecurity recommendation can be implemented across any organisation to enforce\nstrong&nbsp;enterprise password security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Password management is undoubtedly one of the most basic security practices yet it is one that people struggle with the most when it comes to operating securely. Morey Haber, CTO &amp; CISO, BeyondTrust, offers his advice to ensuring a best practice approach to password security. In the cyber world, we\u2019re exposed to an onslaught of [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":44734,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,6,4115,3629,13,79],"tags":[1102,4853,99],"class_list":["post-44733","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-insights","category-intelligent-technology-newsletter","category-newsletter","category-top-stories","category-used","tag-beyondtrust","tag-morey-haber","tag-password-security"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/44733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=44733"}],"version-history":[{"count":5,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/44733\/revisions"}],"predecessor-version":[{"id":44799,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/44733\/revisions\/44799"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/44734"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=44733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=44733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=44733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}