by Glen Tindal, Co-Founder and Chief Technology Officer at Intelliden

Effectively Enforcing Password Policies and Audits

Opinion
Oct 2, 20093 mins

Traditionally security professionals have spent most of their time trying to prevent malicious attacks from outside the company. But what happens when the threat comes from trusted insiders with access to passwords?

According to the 2008 Global Information Security Workforce Study by Frost & Sullivan, 51% of IT executives and security professionals consider internal employees “the biggest threat” to security. Consider the case last year when a disgruntled San Francisco employee blocked access to the city’s entire network.

Continuous enforcement of effective password policies and regular security audits through sophisticated network configuration and compliance management solutions can go a long way to minimizing internal threats.

Routers, switches and other network devices offer both external and internal authentication mechanisms. The external solutions typically leverage common security servers (e.g., RADIUS, TACACS+ and Active Directory) and authenticate users and apply authorization privileges at device login time. Alternatively, if an external security server is unavailable, most network devices also support a local username and password solution. This internal solution, while not optimal, provides a basic username/password authentication and coarse authorization options.

While it sounds good on paper, this most fundamental of security measures quickly unravels given the fact that most help desk or support personnel regularly share username and password information (including admin, root and super-user) or they enable passwords.

The excuses range from “My login doesn’t have the privileges to fix the problem and someone else’s does”, to “I just went ahead and fixed the problem as opposed to calling someone else”, or “it’s too painful to change passwords, network-wide every month.” The result is a simple, but large security exposure which, if unmanaged, allows access to network devices for security changes, re-routing traffic, shutdown of voice calls and many other damaging scenarios.

The solution to mitigating internal security threats must begin with implementing appropriate access policies. This includes authentication and authorization policies to ensure network personnel have the right access privileges to perform their job.

But this is not sufficient. Strong password policies are an essential and powerful tool for dealing with the internal threat. This includes aging policies to ensure that passwords are regularly changed (e.g. every 90 or 120 days), policies for enforcing strong passwords, and clearly documented procedures for when an employee changes his role, moves to another department or leaves the organization.

Of course none of these prevent users from sharing their authentication details. That needs to be enforced through disciplined and documented change management processes with added measures for comprehensive logging as well as regular security audits. The enforcement of these processes and policies can be automated through state of the art network configuration and compliance management solutions that can support multiple policy types, continuous validation and immediate notifications upon failed policy checks.

Automated safety precautions are critical because network operations and support personnel come and go as the demands of the network change. This ebb and flow also means critical knowledge of network topology and the associated usernames and passwords leave the organization and an ever increasing internal security threat emerges.

It is only by combining disciplined change with configuration and compliance management solutions that the most simple, but potentially damaging internal security threat – that of ineffective password management for network devices — can be prevented.