Quantcast
Channel: THWACK: All Content - All Communities
Viewing all articles
Browse latest Browse all 20518

Need New User Role - Separation of Duties for Better Security and Operation Management (case #526663)

$
0
0

Hello!

Currently Security Engineers/Administrators are usually assigned with LEM Administrator role and responsible for creating and managing those security /correlation rules. LEM Administrator role has the power to create LEM rules with actions like Shutting down or restarting servers. This generates a big issue, actually a show stopper at implementation. Shutting down or restarting servers are really System Administrator's duty, not Security Administrator's. With FISMA, PCI compliance and SANS top 20 security controls, separation of duties is a must requirement. Think if you were Windows Admin who is responsible for Windows Domain controller, you wouldn’t want to be called midnight because a LEM Security Admin's rule that shut down his domain controller.

 

Thanks,

Lucy


Viewing all articles
Browse latest Browse all 20518

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>