Next-generation protection for the federal hybrid Cloud

October 11, 2013 Off By David

Grazed from GSN Magazine. Author: Dale R. Gardner.

Hybrid-Cloud computing, the combination of private, community and public Cloud infrastructures, delivers advantages. But it also introduces risks, particularly around privileged users and trusted insider threats. Agencies already routinely develop plan of action and milestones (POAMs) to address audit findings on shared administrative accounts, weak and default passwords, and other privileged risks. And regulations mandating tighter privileged user controls have also emerged.

Most recently, an updated release of NIST Special Publication 800-53 brought new requirements. More are found in Presidential CAP goals and long-standing programs, such as HSPD-12 and OMB 11-11, which reinforce the requirement for PIV card controlled logical access to systems, particularly for privileged accounts…

As a consequence of all these demands, organizations have begun to move to more modern privileged identity management systems combining privileged password management, access control, monitoring and other capabilities. These solutions attempt to combine disparate functions, replacing the assemblage of home-grown and point products with which organizations have attempted to manage privileged users in the past…

Read more from the source @ http://www.gsnmagazine.com/node/33662?c=it_security