Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 20, 2006

Access Levels for Security Administrators


RSS
View this exclusive article with VIP access -- click here to join |
See More Active Directory (AD) Articles Here | Reprints | Or sign up for our VIP Monthly Pass!
Main Article    Access Denied

I was recently hired as a security administrator responsible for overall information security, including log management and access review. Software I'm testing to review user and group access require me to have administrative access to run the discovery tasks, but I don't have administrative access and have to ask someone who does to install and run the discoveries for me. Log management tools also require me to have administrative access. However, from an auditing standpoint, I shouldn't have administrative access; although I should be able to monitor changes that administrators make, I shouldn't be able to make changes myself. Another example is setting Group Policy in Active Directory (AD): I shouldn't be able to go into AD to set policies, but I should be able to view security policies. Do you have recommendations about the type of access someone in my position should have?

Ideally, organizations should employ someone to be responsible for assessing and monitoring security, but that person shouldn't be responsible for actually administering systems. Monitoring and administrative responsibilities should be divided to serve as a separation-of-duty control.

There are two risks when the same individual or group performs both types of duties. First, there's tension between security and system support, and a busy administrator who has no one looking over his or her shoulder will often shortcut security policies and procedures to solve problems. Second, employees—even administrators—can sometimes become malicious and turn into rogues. Having a dedicated security person reviewing employee actions is an effective deterrent.

In your position, you shouldn't have administrative authority because no one reviews what you do. As you've discovered, however, many reporting programs that provide useful information for someone in your position aren't designed with the concept of least privilege in mind, so an administrator must supervise the execution of such programs.

As for log management, many log monitoring solutions let you collect security logs from systems on your network and put them into a separate log management server under your control. Some of the solutions I recommend are Secure Vantage Technologies' Security Control Management Pack for MOM 2005, TNT Software's ELM Log Manager, Prism Microsystems' EventTracker, GFI Software's GFI LANguard Security Event Log Monitor, and Quest Software's InTrust. After supervising the installation of the collection agent on each system by an administrator, you shouldn't need further access to the systems being monitored. It's important that the log management server be in a separate forest or be a standalone server. The server shouldn't be in a forest administered by typical IT administrators because it would be subject to tampering by the employees the server is monitoring.

To view Group Policy, all you need is Group Policy Management Console (GPMC) and a simple, unprivileged user account located somewhere in the AD forest. The Authenticated Users special principal, to which all users in the forest belong, has read access to Group Policy Objects (GPOs) and almost everything else in AD. However, when all you have is read access, only GPMC will let you view a GPO.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

SET Options and Recompilation

Learn how to tweak your server's SET options so that you don't have to constantly recompile. ...


Active Directory (AD) Whitepapers Sustainable Compliance: How to reconnect compliance, security and business goals

Managing Unix/Linux with Microsoft System Center Operations Manager 2007 Cross Platform Extensions Beta

Addressing the Insider Threat with NetIQ Security and Administration Solutions

Related Events SQL Server 2008 – Can You Wait? | Philadelphia

SQL Server 2008 – Can You Wait? | Atlanta

SQL Server 2008 – Can You Wait? | Chicago

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing