1 00:00:00,346 --> 00:00:06,046 A hospital in Portugal gave every single employee doctor-level access. 2 00:00:06,916 --> 00:00:09,396 That means the janitor could read your medical chart. 3 00:00:10,036 --> 00:00:15,396 That cost them 400,000 euros in fines, and when they appealed, the 4 00:00:15,396 --> 00:00:19,476 court basically said they didn't even try the concept of least privilege. 5 00:00:20,136 --> 00:00:24,066 Today, that's what we're talking about, least privilege best practices. 6 00:00:24,586 --> 00:00:25,926 What does that mean exactly? 7 00:00:26,266 --> 00:00:31,406 And, and also, where do you start when everybody already has domain admin? 8 00:00:32,086 --> 00:00:34,796 Finally, we talk about role-based administration and why that's 9 00:00:34,816 --> 00:00:36,966 really the only realistic path here. 10 00:00:37,556 --> 00:00:41,526 We talk about privileged account inventories, uh, fire call accounts, 11 00:00:41,536 --> 00:00:46,236 segregation of duties, non-repudiation, and three backup roles that you should 12 00:00:46,236 --> 00:00:51,186 split apart before somebody quietly deletes your backup configuration. 13 00:00:52,116 --> 00:00:54,756 If this is your first time watching or listening to me, I'm 14 00:00:54,756 --> 00:00:57,376 W. Curtis Preston, AKA Mr. Backup. 15 00:00:57,826 --> 00:01:03,026 I've been obsessing over backup recovery, and now cyber recovery, for over 30 years. 16 00:01:03,416 --> 00:01:05,166 If that's your bag, I'm your guy. 17 00:01:05,636 --> 00:01:08,616 You're not gonna find anybody that cares about it more than me. 18 00:01:08,886 --> 00:01:13,166 Ever since 1993, when I had to tell my boss that there were no backups of 19 00:01:13,166 --> 00:01:14,736 the database that we had just lost. 20 00:01:15,386 --> 00:01:18,906 Now I've written five O'Reilly books, a blog, and now this podcast. 21 00:01:19,236 --> 00:01:23,296 Here, we turn unappreciated admins into cyber recovery heroes. 22 00:01:23,586 --> 00:01:25,676 This is the Backup Wrap-Up 23 00:01:34,181 --> 00:01:36,231 Hi, and welcome to The Backup Wrap Up. 24 00:01:36,231 --> 00:01:38,021 I'm your host W. Curtis Preston. 25 00:01:38,021 --> 00:01:44,841 I'm joined by the two greatest ever on the… I don't know. 26 00:01:45,081 --> 00:01:45,861 I don't know what I'm gonna say. 27 00:01:45,861 --> 00:01:47,651 Anyway, I'm joined with, 28 00:01:48,099 --> 00:01:48,999 Ever, Curtis? 29 00:01:49,049 --> 00:01:49,859 Ever, ever? 30 00:01:50,521 --> 00:01:53,831 Ever, ever, ever, at least this week on a Thursday, on a 31 00:01:53,831 --> 00:01:55,471 Tuesday or what- whatever it is. 32 00:01:55,471 --> 00:01:56,261 It's a Monday. 33 00:01:56,391 --> 00:01:57,801 I don't know what's going on in my head. 34 00:01:57,981 --> 00:01:58,711 Hi, Prasanna. 35 00:01:59,663 --> 00:02:00,333 Hi, Curtis. 36 00:02:00,333 --> 00:02:01,683 I have a question for you. 37 00:02:02,251 --> 00:02:02,681 Yeah 38 00:02:03,563 --> 00:02:08,873 Is your poster crooked with your latest book that you and Mike wrote? 39 00:02:09,619 --> 00:02:10,129 No, 40 00:02:10,189 --> 00:02:10,789 The angle 41 00:02:12,192 --> 00:02:13,742 It's the angle of the shelf. 42 00:02:14,472 --> 00:02:16,052 The shelf is a 43 00:02:16,269 --> 00:02:19,049 'Cause I was going off the right-hand side where the book 44 00:02:19,269 --> 00:02:20,489 meets up with the other two books. 45 00:02:20,759 --> 00:02:23,469 For those of you who don't know, you can watch us on YouTube. 46 00:02:23,479 --> 00:02:28,219 We do have the videos posted, and you can see the giant… Imagine 47 00:02:28,219 --> 00:02:29,809 if they made the book that size. 48 00:02:29,979 --> 00:02:31,099 That would be pretty awesome 49 00:02:32,872 --> 00:02:33,082 Does that 50 00:02:33,217 --> 00:02:33,997 It'd be heavy 51 00:02:34,282 --> 00:02:35,662 No, that makes it worse, didn't it? 52 00:02:37,522 --> 00:02:37,822 No? 53 00:02:38,992 --> 00:02:43,102 I literally think it's a, I think it's an optical illusion. 54 00:02:43,242 --> 00:02:43,812 But you know what? 55 00:02:43,812 --> 00:02:48,732 Just for you, I will go find a, a level and, we'll fix it in post. 56 00:02:49,042 --> 00:02:50,052 me happy, Curtis. 57 00:02:50,474 --> 00:02:51,034 yeah. 58 00:02:51,864 --> 00:02:56,134 you're… and then we have my co-author of this book that was hanging on the 59 00:02:56,134 --> 00:02:59,774 wall that seems to have gone back to its original position, which for the record 60 00:02:59,774 --> 00:03:03,524 would imply gravity and that it was in the right place in the first place. 61 00:03:04,814 --> 00:03:08,454 Learning Ransomware Response and Recovery, Mike Saylor. 62 00:03:08,454 --> 00:03:09,204 How's it going, Mike? 63 00:03:11,072 --> 00:03:13,922 Well, look forward to digging into another one with you guys 64 00:03:14,098 --> 00:03:14,358 Mike, 65 00:03:14,411 --> 00:03:14,881 So we're… 66 00:03:15,008 --> 00:03:16,238 I have a, question for you, Mike. 67 00:03:18,108 --> 00:03:19,418 Does it look crooked to you? 68 00:03:20,350 --> 00:03:20,820 That's… 69 00:03:21,198 --> 00:03:21,538 Okay. 70 00:03:24,881 --> 00:03:27,981 I've got a… Don't make me go downstairs and get a level. 71 00:03:29,181 --> 00:03:30,711 I don't think I have one over… wait. 72 00:03:30,741 --> 00:03:31,351 You know what? 73 00:03:31,978 --> 00:03:32,488 Your phone. 74 00:03:32,558 --> 00:03:32,618 Your phone 75 00:03:33,687 --> 00:03:35,117 I have my iPhone 76 00:03:38,024 --> 00:03:42,684 I think the bottom left corner for you, Curtis, when you face 77 00:03:42,684 --> 00:03:45,144 it, needs to go to the left 78 00:03:45,155 --> 00:03:48,555 put this right… Why is it beeping? 79 00:03:49,695 --> 00:03:50,955 I'm gonna put this right here 80 00:03:55,289 --> 00:03:58,689 It says 0% right now. 81 00:03:59,454 --> 00:03:59,894 Yes. 82 00:04:00,062 --> 00:04:00,652 it looks better 83 00:04:00,974 --> 00:04:01,864 Now it looks straight. 84 00:04:05,104 --> 00:04:05,724 Now it's crooked 85 00:04:05,835 --> 00:04:06,235 looks crooked. 86 00:04:07,525 --> 00:04:07,935 See? 87 00:04:08,812 --> 00:04:09,752 Look straight to us now 88 00:04:11,353 --> 00:04:11,973 See what I mean? 89 00:04:11,983 --> 00:04:13,173 I'm you. 90 00:04:13,553 --> 00:04:15,193 If it's off by 1%. 91 00:04:15,733 --> 00:04:16,373 I'm just saying. 92 00:04:17,620 --> 00:04:18,540 It's noticeable 93 00:04:18,873 --> 00:04:21,363 My God, we've already spent 20 minutes on this. 94 00:04:21,493 --> 00:04:26,393 So let's go, let- So we're, today we're gonna be talking about the concept of 95 00:04:26,393 --> 00:04:30,323 least privilege, and to illustrate the concept of least privilege, I'm gonna 96 00:04:30,343 --> 00:04:34,133 tell a story which I've mentioned a couple of times on the podcast, which 97 00:04:34,143 --> 00:04:41,053 is, this hospital in Portugal that is, that received a, a huge fine, 98 00:04:41,373 --> 00:04:42,993 back, let me just double-check here. 99 00:04:42,993 --> 00:04:45,083 Yeah, it was 2018, right? 100 00:04:45,083 --> 00:04:49,973 So this is the EU Data Protection Law, GDPR, the General Data Protection 101 00:04:49,973 --> 00:04:55,063 Regulations, and, they, require that you implement the concept of least 102 00:04:55,073 --> 00:04:57,963 privilege and among many other things. 103 00:04:58,223 --> 00:05:05,053 And they discovered that this hospital, d- slightly didn't adhere to that, in 104 00:05:05,053 --> 00:05:10,873 that what they found was easier, in this hospital, was that all employees 105 00:05:10,873 --> 00:05:13,413 in the hospital got doctor-level access. 106 00:05:14,513 --> 00:05:19,373 So that way, everybody, including the janitor, had access to 107 00:05:19,373 --> 00:05:24,403 literally ev- the most private data, in, in the entire, hospital. 108 00:05:24,793 --> 00:05:26,593 And so they found that, 109 00:05:27,108 --> 00:05:28,308 including patient records 110 00:05:28,973 --> 00:05:31,323 including patient records and everything, right? 111 00:05:31,613 --> 00:05:36,143 And, the, and, th- there are different levels of access to patient records 112 00:05:36,143 --> 00:05:37,863 even withi- within a hospital, right? 113 00:05:37,863 --> 00:05:39,593 And then, and obviously there are people that don't need 114 00:05:39,593 --> 00:05:41,113 any access to patient records. 115 00:05:41,433 --> 00:05:43,213 And, why are you doing that thing? 116 00:05:43,223 --> 00:05:43,593 You're doing 117 00:05:43,726 --> 00:05:44,456 No, no, 118 00:05:44,613 --> 00:05:45,083 you agree 119 00:05:45,126 --> 00:05:45,186 a 120 00:05:45,263 --> 00:05:45,383 me 121 00:05:45,446 --> 00:05:49,076 qu- no, because it was going through my head, and maybe before we go onto 122 00:05:49,076 --> 00:05:56,076 the actual topic, is it worse to give everyone admin access or to just 123 00:05:56,076 --> 00:05:57,986 use the same password for everyone? 124 00:05:59,029 --> 00:06:04,139 it's roughly the same thing, I'm su- I'll say it's probably worse to get 125 00:06:04,139 --> 00:06:08,119 everybody the same password because, that means that if somebody does 126 00:06:08,129 --> 00:06:11,179 abuse their privilege, there won't be any logging of it whatsoever. 127 00:06:12,369 --> 00:06:18,339 the whole point, and by the way, they were fined 400,000 euro and, they appealed 128 00:06:18,339 --> 00:06:20,259 it, unsuccessfully they appealed it. 129 00:06:20,279 --> 00:06:25,859 And, the EU, courts found that, they d- it was like they didn't even try, 130 00:06:25,869 --> 00:06:29,789 was basically they're like, "You di- you guys didn't try and fail. You 131 00:06:29,789 --> 00:06:33,569 basically said, 'This sounds like a great concept. We're gonna completely 132 00:06:33,569 --> 00:06:38,119 ignore it altogether.'" and just think about the kinds of things that are in a 133 00:06:38,119 --> 00:06:42,839 medical record and, and thinking about the fact that the jan- that the janitor 134 00:06:43,169 --> 00:06:45,289 had access to your medical records, right? 135 00:06:45,456 --> 00:06:49,616 And Mike, have you, in all the consulting you've done in helping out 136 00:06:49,616 --> 00:06:54,476 all these other companies, have you ever encountered anything that bad? 137 00:06:55,596 --> 00:06:56,286 I hope not. 138 00:06:56,286 --> 00:06:58,996 I would hope that never, that you've never seen that, but 139 00:07:00,944 --> 00:07:00,984 Yeah. 140 00:07:01,194 --> 00:07:03,484 And I've even seen it in healthcare. 141 00:07:03,794 --> 00:07:08,524 and it wasn't just logical security, security was bad also 142 00:07:10,095 --> 00:07:11,195 Yeah, depressing. 143 00:07:11,385 --> 00:07:16,945 Yeah, you'd think that like with some, you would think s- with some, industries 144 00:07:16,965 --> 00:07:22,645 like medical or finance, I'd say those are two where you've got some really bad 145 00:07:22,645 --> 00:07:24,625 things will happen if the data gets out. 146 00:07:24,975 --> 00:07:27,635 You would think that they would know what they're hap- that they're doing, 147 00:07:27,915 --> 00:07:34,655 but again, I've also worked in, in finance and in, a number of areas where 148 00:07:35,455 --> 00:07:39,895 they should really know better, and they absolutely clearly did not know better. 149 00:07:40,775 --> 00:07:44,755 first off, d- Mike, do you wanna just define, Actually, we're g- 150 00:07:44,755 --> 00:07:47,165 we're gonna go, we're gonna go for you the, for the deeper stuff. 151 00:07:47,205 --> 00:07:50,725 Prasanna, I think you can define this for me. 152 00:07:50,895 --> 00:07:53,015 what is the concept of least privilege? 153 00:07:54,264 --> 00:07:59,434 It basically says if you are a user, you only have access to 154 00:07:59,474 --> 00:08:02,194 things that you need and that is it. 155 00:08:02,804 --> 00:08:07,084 So if you are a janitor, you don't need access to patient records. 156 00:08:07,364 --> 00:08:11,054 If you're never touching like backup systems, you probably shouldn't be able 157 00:08:11,054 --> 00:08:13,274 to go create delete backup policies. 158 00:08:13,694 --> 00:08:17,594 And making sure you scope your permissions such that you only get access to the 159 00:08:17,614 --> 00:08:19,444 things you need in order to do your job 160 00:08:20,449 --> 00:08:23,449 So you're given the least amount of privilege, which is 161 00:08:23,469 --> 00:08:24,859 too long to say that, right? 162 00:08:24,859 --> 00:08:28,139 You're given the least amount of privilege that you need in 163 00:08:28,139 --> 00:08:29,729 order to do your job, right? 164 00:08:29,729 --> 00:08:31,859 Which is where we get the concept of least privilege. 165 00:08:33,189 --> 00:08:37,229 and if we wanted to dig a little deeper in that, Mike, which we do, 166 00:08:37,519 --> 00:08:40,469 h- how do we go about doing this? 167 00:08:40,499 --> 00:08:42,239 Like, where do you start with this? 168 00:08:45,300 --> 00:08:46,910 there's a lot of different ways to go about it. 169 00:08:46,910 --> 00:08:50,800 It, company culture's gonna probably drive, what's most appropriate. 170 00:08:50,850 --> 00:08:54,530 so from a, just a normal especially if you're the new guy and you can just blame 171 00:08:54,530 --> 00:08:58,060 it on being new, just turn everything off and see who screams about access to what. 172 00:08:59,040 --> 00:08:59,930 so that's one way. 173 00:09:00,290 --> 00:09:03,640 the other way is a true analysis of job role. 174 00:09:04,170 --> 00:09:08,760 and so it's not just, the different areas that I have access to, it's the 175 00:09:08,760 --> 00:09:10,960 levels of access within each area. 176 00:09:11,420 --> 00:09:16,490 So you've got a data entry clerk that doesn't need to have the ability to 177 00:09:16,490 --> 00:09:20,710 approve a purchase order, but they still need access to the accounting system. 178 00:09:21,590 --> 00:09:24,410 But you've got people in marketing that don't need 179 00:09:24,420 --> 00:09:26,090 access to the accounting system. 180 00:09:26,370 --> 00:09:30,320 They need access to certain websites, maybe websites that other people in 181 00:09:30,320 --> 00:09:32,030 the company shouldn't be able to go to. 182 00:09:32,790 --> 00:09:36,020 so there's the, turn everything off and wait for people to ask. 183 00:09:36,460 --> 00:09:41,770 There is the, turn things off in a somewhat logical manner. 184 00:09:42,440 --> 00:09:46,960 And then there's the, let's start from scratch with understanding the 185 00:09:46,960 --> 00:09:50,830 different types of users and roles we have, and then work with those 186 00:09:50,830 --> 00:09:55,120 departments and people to define what access is appropriate for those users 187 00:09:55,815 --> 00:09:55,915 I 188 00:09:55,944 --> 00:09:56,524 That seems 189 00:09:56,715 --> 00:10:01,815 my, mom did medical transcription for, for many years, right? 190 00:10:02,155 --> 00:10:07,135 And she therefore had technically had access to patient records, 191 00:10:07,165 --> 00:10:12,265 but literally one patient at a time and only to that record. 192 00:10:12,405 --> 00:10:16,625 So d- they could have given her access to the entire, that patient, but she 193 00:10:16,625 --> 00:10:21,445 literally had access to that patient at that time to create that patient's record, 194 00:10:21,455 --> 00:10:23,385 which was then put into the system. 195 00:10:23,635 --> 00:10:27,425 She wasn't given access to access all of… So that's a perfect example 196 00:10:27,425 --> 00:10:32,155 of where she does need access to, the type of information, but she 197 00:10:32,155 --> 00:10:33,575 doesn't need access to all of it. 198 00:10:33,575 --> 00:10:35,245 Now Prasanna, about to ask something 199 00:10:36,710 --> 00:10:39,250 W- d- you actually brought up a great example, Curtis. 200 00:10:39,300 --> 00:10:40,930 she had access to that system. 201 00:10:41,280 --> 00:10:45,470 But now if I think about, an enterprise or an organization, they probably have 202 00:10:45,480 --> 00:10:50,000 hundreds of applications out there, hundreds of systems, each using their 203 00:10:50,000 --> 00:10:53,740 own different, potentially different role and permission-based systems. 204 00:10:54,700 --> 00:10:59,060 Eh, how do you even go about doing the, options two or three, 205 00:10:59,090 --> 00:10:59,930 Mike, that you talked about? 206 00:10:59,980 --> 00:11:04,320 turning everything off just seems so much easier until someone complains 207 00:11:04,670 --> 00:11:08,130 than trying to do, this fine-grain mechanisms, like either of the 208 00:11:08,130 --> 00:11:09,650 fine-grain mechanisms you talked about 209 00:11:12,154 --> 00:11:15,634 Well, use- user access management is, resource intensive regardless 210 00:11:15,634 --> 00:11:16,964 of which way you go about it. 211 00:11:17,644 --> 00:11:20,914 if you turn everything off, you should have a good help desk, right? 212 00:11:20,934 --> 00:11:22,004 'Cause you're gonna get phone calls. 213 00:11:22,481 --> 00:11:22,951 Now, Mike, 214 00:11:22,994 --> 00:11:23,484 If, if- 215 00:11:23,601 --> 00:11:28,591 to that, you really need support from on high if you're gonna do that method, 216 00:11:28,702 --> 00:11:28,722 Yeah, 217 00:11:28,791 --> 00:11:29,391 Because you're 218 00:11:29,562 --> 00:11:30,032 for sure 219 00:11:30,391 --> 00:11:33,021 you're going to impact services, right? 220 00:11:33,721 --> 00:11:34,841 the… Yeah, go ahead 221 00:11:35,528 --> 00:11:39,678 and I've got a story about a disgruntled desk person that was berated by an 222 00:11:39,678 --> 00:11:41,608 executive for that very reason, and it 223 00:11:41,646 --> 00:11:41,986 Oh, no 224 00:11:42,058 --> 00:11:42,348 well. 225 00:11:43,118 --> 00:11:45,818 then, all right, so then, options two and three, where you're going 226 00:11:45,828 --> 00:11:49,818 about it a little more methodically, there's resources not only up front 227 00:11:49,878 --> 00:11:54,808 to go and define all these things, but in all three cases, how are we 228 00:11:54,808 --> 00:11:56,648 gonna manage this going forward? 229 00:11:56,958 --> 00:12:01,098 Bob doesn't… Bob transferred from accounting to HR or from marketing 230 00:12:01,098 --> 00:12:05,678 to sales or from IT some other role. 231 00:12:06,038 --> 00:12:09,568 We've gotta make sure there's a way of communicating those changes so that 232 00:12:10,018 --> 00:12:12,948 changes to their access, follows them. 233 00:12:13,688 --> 00:12:16,218 there are ways that there's human ways of doing that, so every 234 00:12:16,218 --> 00:12:21,248 month I'm running a, an analysis or we implement tools to do that. 235 00:12:21,278 --> 00:12:26,488 A, a lot of HR systems as a person's job role changes or their status 236 00:12:26,488 --> 00:12:28,988 changes, there's a workflow for that. 237 00:12:29,368 --> 00:12:33,928 there's automation in Microsoft products, that you can define workflows 238 00:12:33,928 --> 00:12:40,778 f- for, but it all takes a, a bit of strategy and resource planning, and a 239 00:12:40,778 --> 00:12:42,458 lot of organizations just don't do it 240 00:12:43,763 --> 00:12:44,173 Yeah. 241 00:12:44,173 --> 00:12:46,613 and, and they suffer as a result, right? 242 00:12:46,643 --> 00:12:51,593 and so th- there's a word that's come up a lot in your, in your answer, 243 00:12:51,973 --> 00:12:53,883 which is the word role, right? 244 00:12:53,913 --> 00:12:57,953 R- R-O-L-E, role, and which brings up a, a very related 245 00:12:57,953 --> 00:13:02,063 topic was, which is role-based administration controls, or RBAC. 246 00:13:03,293 --> 00:13:08,503 I think that's really the only way that you can get… if you're gonna, if you 247 00:13:08,503 --> 00:13:13,383 have any hope of getting this done, it's y- it's by defining roles of the 248 00:13:13,383 --> 00:13:17,203 different organizations, different parts of the organizations, different levels 249 00:13:17,213 --> 00:13:20,713 within the organizations, and then saying, "This person has moved from A to 250 00:13:20,723 --> 00:13:25,253 B. They're no longer in A, they're now in B," and you give them this new role. 251 00:13:25,553 --> 00:13:26,473 any thoughts on that? 252 00:13:27,940 --> 00:13:28,680 Completely agree. 253 00:13:28,680 --> 00:13:31,880 And that's something that you can do over time as new users come in. 254 00:13:32,950 --> 00:13:38,300 Bob needs access to X, Y, and Z. Was that consistent with Bob's coworkers? 255 00:13:38,300 --> 00:13:41,060 If so, I can save that as a profile for that role. 256 00:13:41,510 --> 00:13:45,510 So now when Bob leaves and Susan comes in, I don't have to go 257 00:13:45,510 --> 00:13:47,540 reassess what Susan needs access to. 258 00:13:47,540 --> 00:13:51,890 I just apply a role to her and then address any exceptions. 259 00:13:51,900 --> 00:13:56,330 She needs access to the check printer or a certain website or… 260 00:13:56,480 --> 00:13:59,230 So those are one-off exceptions, and you'd wanna document those. 261 00:13:59,230 --> 00:14:02,740 But for the most part, you can define roles that way and simply assign 262 00:14:02,740 --> 00:14:07,370 them to people as they fill that role or as that role becomes defined. 263 00:14:08,000 --> 00:14:11,990 And then maybe Bob didn't leave the company, Bob went to another department. 264 00:14:12,000 --> 00:14:13,130 is there already a role for that? 265 00:14:13,130 --> 00:14:17,860 And if not, I'll define one or save whatever I create for Bob as that role. 266 00:14:18,370 --> 00:14:19,500 so there are ways to do it. 267 00:14:19,540 --> 00:14:21,960 You just need to do it 268 00:14:22,299 --> 00:14:24,459 it does start with that mindset, right? 269 00:14:24,539 --> 00:14:27,149 That you're like, that this is a good thing, that we're gonna do 270 00:14:27,149 --> 00:14:30,559 least privilege, that we're gonna do, and the, and that the vehicle 271 00:14:30,559 --> 00:14:34,239 through which we're gonna do least privilege is role-based administration. 272 00:14:34,239 --> 00:14:38,499 And so when you have a new user, when you have a change in your user, like you 273 00:14:38,499 --> 00:14:41,079 said, you don't just go and add them. 274 00:14:41,149 --> 00:14:44,259 You go and you create a role, for that user. 275 00:14:44,259 --> 00:14:47,749 Even if it's just one, at least at that point it's just one. 276 00:14:47,799 --> 00:14:52,069 when that person leaves or that person gets promoted and you put another person 277 00:14:52,069 --> 00:14:56,259 in, theoretically you should then be able to just assign that role to them. 278 00:14:56,599 --> 00:15:02,479 Prasanna, you've been, I think in your career you've been on the vendor side, 279 00:15:02,912 --> 00:15:03,072 Yep. 280 00:15:03,552 --> 00:15:03,782 Yep 281 00:15:04,429 --> 00:15:08,559 I'm sure you've seen issues like this, on the vendor side 282 00:15:09,178 --> 00:15:09,888 Oh, yeah. 283 00:15:09,988 --> 00:15:14,958 as users transition in and out of roles, like we talk about 284 00:15:14,958 --> 00:15:16,148 backup apps all the time, right? 285 00:15:16,148 --> 00:15:18,198 You have different levels even within backup apps. 286 00:15:18,198 --> 00:15:23,048 You have the person who's responsible for restoring, right? 287 00:15:23,108 --> 00:15:25,138 Being your sort of tier one support, right? 288 00:15:25,138 --> 00:15:28,568 And then as you look up to, the people who are managing 289 00:15:28,568 --> 00:15:30,898 policies and super admin, right? 290 00:15:30,908 --> 00:15:32,008 All those different roles. 291 00:15:32,428 --> 00:15:35,588 But then also within organizations themselves, like when I was 292 00:15:35,598 --> 00:15:37,328 working at a vendor, right? 293 00:15:37,368 --> 00:15:39,808 It's not oh, I had an individual role for me. 294 00:15:39,808 --> 00:15:43,548 It was like, oh, I'm part of product org, or I'm part of the engineering org. 295 00:15:43,878 --> 00:15:46,868 I'm gonna be assigned to that role, and whatever they get 296 00:15:46,888 --> 00:15:48,348 is the access that I needed. 297 00:15:48,948 --> 00:15:51,538 And one question I know, Curtis, you made at the point about yes, 298 00:15:51,538 --> 00:15:55,288 you should go create a role for an individual if it didn't exist before. 299 00:15:56,088 --> 00:16:00,808 But I think you have to also ask yourself, is creating a role the right thing to do? 300 00:16:01,468 --> 00:16:05,008 Because if you go down that path, there is a possibility that you 301 00:16:05,008 --> 00:16:08,968 could say, "Okay, Curtis, you need this extra role or privilege. 302 00:16:09,288 --> 00:16:13,438 Mike needs this other privilege," even though, 99% they might be the same. 303 00:16:13,758 --> 00:16:16,898 And so I think you also need to worry about the sprawl in terms of 304 00:16:16,908 --> 00:16:19,708 the number of roles, managing the roles, and everything else like that. 305 00:16:19,708 --> 00:16:20,708 So just the… 306 00:16:20,838 --> 00:16:21,178 Creek 307 00:16:21,578 --> 00:16:21,858 Yeah. 308 00:16:23,401 --> 00:16:28,371 Yeah, I think the way to do that is at least, in my thoughts, the way to do that 309 00:16:28,371 --> 00:16:30,861 is to find out what's the 90%, right? 310 00:16:30,861 --> 00:16:32,221 The 80/20 rule, right? 311 00:16:32,531 --> 00:16:36,191 To find the roles that, Mike works in IT, right? 312 00:16:36,201 --> 00:16:40,671 Mike works in this part of IT, and therefore he needs these privileges that 313 00:16:40,711 --> 00:16:43,271 everyone who works in IT works in, right? 314 00:16:43,471 --> 00:16:47,301 or that every wo- everyone who works in IT has, right? 315 00:16:47,461 --> 00:16:54,811 and even if you have… I don't think it's a good idea to create a role… I 316 00:16:54,811 --> 00:16:59,311 just said create a role for one person, but what I mean here is I don't think 317 00:16:59,311 --> 00:17:03,211 it's idea to create a custom role for each person in the organization, right? 318 00:17:03,221 --> 00:17:03,641 To create… 319 00:17:03,641 --> 00:17:07,301 You wanna create a role that fits the most people, and then you add 320 00:17:07,301 --> 00:17:10,431 exceptions, to that, to that role. 321 00:17:10,441 --> 00:17:11,621 Maybe that's another role. 322 00:17:11,621 --> 00:17:13,591 Maybe it's just another, what do you call that? 323 00:17:13,641 --> 00:17:14,281 ad hoc. 324 00:17:14,741 --> 00:17:17,501 Maybe it's just another ad hoc permission that you're added on. 325 00:17:18,381 --> 00:17:24,271 again, this is one of those things where it's like a lot of other things that it 326 00:17:24,281 --> 00:17:27,971 does require a lot of work upfront, and I think that's a really good question 327 00:17:27,971 --> 00:17:32,701 that you ask, Prasanna, is that we don't want… Not everybody does an I- not 328 00:17:32,701 --> 00:17:37,681 everybody in IT does the same thing, and so we don't wanna create 37 roles. 329 00:17:38,871 --> 00:17:44,901 I think we can create roles that are really important and that really 330 00:17:44,901 --> 00:17:49,981 need to be reserved, and that we only give those permissions those people. 331 00:17:50,381 --> 00:17:51,211 a domain admin? 332 00:17:53,075 --> 00:17:53,265 What's… 333 00:17:53,265 --> 00:17:53,635 Yeah. 334 00:17:54,445 --> 00:17:56,085 Everyone gets domain admin. 335 00:17:56,895 --> 00:17:57,575 What do you think, Mike? 336 00:17:58,197 --> 00:17:58,967 or local admin. 337 00:17:59,367 --> 00:18:03,407 But yeah, lowest common denominator per role is a great, is a good approach. 338 00:18:03,907 --> 00:18:08,877 and what's interesting is, from a… and so acc- access and access, the 339 00:18:08,877 --> 00:18:12,917 appropriateness of an access, of access, and the process that you go 340 00:18:12,917 --> 00:18:18,717 through to and assign that access is what we would call a control from 341 00:18:18,717 --> 00:18:20,937 an audit and governance perspective. 342 00:18:21,677 --> 00:18:26,157 if you look at the business side, accounting, finance as an example, have 343 00:18:26,177 --> 00:18:28,407 controls called segregation of duties. 344 00:18:28,837 --> 00:18:32,217 So I can't be a requester and an approver in the accounting system. 345 00:18:32,897 --> 00:18:37,497 So the accounting system itself already has roles defined that address 346 00:18:37,497 --> 00:18:40,477 segregation of duties, concerns, controls. 347 00:18:41,467 --> 00:18:46,147 We've tried over the years to apply that to IT, but we s- we 348 00:18:47,087 --> 00:18:50,587 sh- as IT practitioners, we so fight, wanting anything to do 349 00:18:50,587 --> 00:18:52,117 with how business does its thing. 350 00:18:52,557 --> 00:18:55,107 quite similarly, they don't wanna do anything… they try. 351 00:18:55,377 --> 00:18:58,767 But they wanna be separate from IT, The pretty people wanna be 352 00:18:58,777 --> 00:19:02,637 separate from the geeks, as we used to say at one of the telecoms. 353 00:19:02,667 --> 00:19:10,577 But if we could better adopt, and maybe it just takes a culture, a, a leadership 354 00:19:10,577 --> 00:19:15,067 culture to start that is a- adopt that segregation of duties mindset. 355 00:19:16,357 --> 00:19:20,647 as a… E- even if I had a privileged account, I should not be running my 356 00:19:20,647 --> 00:19:24,687 privileged account while I'm surfing the internet or checking my Gmail, right? 357 00:19:25,167 --> 00:19:29,067 I should only be using my admin account when I'm doing administrative things. 358 00:19:29,807 --> 00:19:32,667 so that's actually a segregation of duties, and I think one of the 359 00:19:32,677 --> 00:19:36,597 topics we may touch on is, then how do I tell what Mike did when Mike 360 00:19:36,597 --> 00:19:39,787 was an admin and what Mike did when Mike was using his normal account? 361 00:19:40,677 --> 00:19:41,627 that's important, too. 362 00:19:41,845 --> 00:19:42,115 Which 363 00:19:42,127 --> 00:19:43,557 Much like on the business side 364 00:19:44,425 --> 00:19:44,745 go ahead 365 00:19:46,265 --> 00:19:49,635 Much like on the business side from a transaction perspective, if I log 366 00:19:49,635 --> 00:19:54,405 in as, just some generic accounting clerk and I'm doing transactions, I'm 367 00:19:54,405 --> 00:19:59,925 entering deposits or I'm paying bills, and there comes an issue with those 368 00:19:59,935 --> 00:20:05,645 transactions, fraud or miscalculation or I miskeyed how am I gonna know who did it? 369 00:20:08,533 --> 00:20:15,093 And if I'm a, an accounting system admin and I can add new users or change 370 00:20:15,373 --> 00:20:20,563 payees, and I do it accidentally, I make a mistake, but I'm logged 371 00:20:20,563 --> 00:20:22,143 in as accounting system admin, 372 00:20:23,775 --> 00:20:24,185 Yeah. 373 00:20:24,335 --> 00:20:24,545 And 374 00:20:24,753 --> 00:20:27,403 where's the accountability or the traceability of that 375 00:20:27,403 --> 00:20:28,533 transaction to a person? 376 00:20:28,937 --> 00:20:33,297 And when I go back to my early days, literally just everybody had root 377 00:20:33,367 --> 00:20:33,867 day 378 00:20:34,767 --> 00:20:38,607 What's back in the day, everybody had root, and then, when we needed 379 00:20:38,607 --> 00:20:42,617 Oracle, I just logged in as root and then I SU'd Oracle, right? 380 00:20:42,647 --> 00:20:44,377 Because we were big at Oracle environment. 381 00:20:44,787 --> 00:20:49,007 And th- we did not have a culture of logging in as yourself 382 00:20:49,007 --> 00:20:50,727 and becoming root, right? 383 00:20:50,787 --> 00:20:55,497 or, using, I think sudo was a thing back then. 384 00:20:55,497 --> 00:21:00,927 I think I remember, I was at a bank and we had a regulation that required 385 00:21:00,937 --> 00:21:05,727 all… There was this thing that said all software wi- will be purchased from 386 00:21:05,727 --> 00:21:09,557 an established vendor, which meant that open source software wasn't a thing. 387 00:21:09,647 --> 00:21:13,437 And at the time, sudo, the only time you could get sudo was open source. 388 00:21:14,447 --> 00:21:17,447 so I don't think we had sudo, which for those of you, if you're not 389 00:21:17,447 --> 00:21:23,307 a Unix person, s- SU is the thing to become super user, AKA root. 390 00:21:23,687 --> 00:21:26,647 And, sudo was like SU do, right? 391 00:21:26,647 --> 00:21:33,377 it was like a do this thing as me, using my account, but do it as root. 392 00:21:33,407 --> 00:21:37,407 And you could do it in such a way that stay in your account. 393 00:21:37,417 --> 00:21:41,917 You don't even ever become root or administrator, but it runs that particular 394 00:21:41,917 --> 00:21:44,507 command as root or administrator. 395 00:21:44,857 --> 00:21:49,137 and so yeah, that, that idea, Mike, of not logging in as… Because 396 00:21:49,137 --> 00:21:53,387 if you, if everybody logs in as root or Oracle or administrator, 397 00:21:53,757 --> 00:21:56,217 you've got no accountability. 398 00:21:56,267 --> 00:21:59,287 by the way, that, I'm gonna go over- There was a word, Mike, that was 399 00:21:59,287 --> 00:22:01,677 used in this thing, non-repudiation. 400 00:22:02,717 --> 00:22:04,047 that's a big word for me. 401 00:22:04,127 --> 00:22:07,607 I'm gonna ask you, can you define that word or is it comp- 402 00:22:08,323 --> 00:22:12,383 So you can't, you, so non-repudiation means you can't say you didn't do it 403 00:22:13,075 --> 00:22:13,415 Okay. 404 00:22:13,455 --> 00:22:13,705 All right. 405 00:22:13,705 --> 00:22:15,345 I'm, so I'm gonna ask you that on the record. 406 00:22:15,375 --> 00:22:18,875 That was more me asking you if you could, if you were comfortable. 407 00:22:19,315 --> 00:22:19,565 Yeah. 408 00:22:19,615 --> 00:22:19,925 Okay. 409 00:22:20,155 --> 00:22:20,505 All right. 410 00:22:20,855 --> 00:22:24,785 So Mike, th- this, we've been talking about not logging in as 411 00:22:24,825 --> 00:22:30,135 admin and, staying, do- doing things as you as much as possible. 412 00:22:30,405 --> 00:22:33,985 and one of the words that comes up, in that, when we talk about that is 413 00:22:33,985 --> 00:22:37,275 this cons- concept of non-repudiation. 414 00:22:37,595 --> 00:22:38,595 you wanna talk about that? 415 00:22:40,331 --> 00:22:43,591 Yeah, it's, so essentially it just means that there's this transaction 416 00:22:43,601 --> 00:22:49,161 log, so it could be an event log or, a log out of a, a financial system that 417 00:22:49,161 --> 00:22:51,171 says you can't say you didn't do it. 418 00:22:52,591 --> 00:22:56,241 it says M Saylor, time, date stamp, did these things. 419 00:22:56,961 --> 00:22:58,231 can't repudiate that. 420 00:22:58,381 --> 00:23:01,631 So having a control in place for non-repudiation. 421 00:23:02,171 --> 00:23:04,701 and if you say it in German, it sounds really aggressive 422 00:23:05,859 --> 00:23:07,089 what's the word in German? 423 00:23:08,241 --> 00:23:10,851 I don't know, but just if you say it with a German accent, 424 00:23:10,851 --> 00:23:11,981 it almost sounds threatening 425 00:23:14,689 --> 00:23:18,569 yeah, which, also brings up this idea, if we're gonna do least privilege, 426 00:23:18,939 --> 00:23:22,279 if we're going to, have this culture where everybody's logging in as 427 00:23:22,279 --> 00:23:25,639 themselves as much as possible, and when they need administrator, they're 428 00:23:25,639 --> 00:23:29,229 going to become administrator rather than logging in as administrator. 429 00:23:29,649 --> 00:23:32,009 and, I like that word of non-repudiation. 430 00:23:32,339 --> 00:23:32,839 then 431 00:23:33,553 --> 00:23:33,893 There… 432 00:23:33,979 --> 00:23:34,299 that we need 433 00:23:34,343 --> 00:23:34,593 wait. 434 00:23:34,823 --> 00:23:35,143 For… 435 00:23:35,259 --> 00:23:35,489 ahead 436 00:23:36,283 --> 00:23:42,023 Wait, before you go on, but in order for those logs to be like my Msaylor 437 00:23:42,033 --> 00:23:47,983 did X, Y, and Z, those also need to be protected, immutable, right? 438 00:23:48,013 --> 00:23:51,123 All the things that we've talked about to ensure they can't be changed 439 00:23:51,701 --> 00:23:54,371 And that's, and we've talked, I'm pretty sure we've talked about that 440 00:23:54,371 --> 00:23:57,781 on other episodes, but the idea that logs should be immediately sent to 441 00:23:57,781 --> 00:24:02,451 some sort of log gathering system, would this… it always escapes me. 442 00:24:02,461 --> 00:24:05,001 is this EDR, ACR, SOAR? 443 00:24:05,141 --> 00:24:05,621 What are we looking 444 00:24:05,917 --> 00:24:06,237 Fem 445 00:24:06,281 --> 00:24:06,641 Mike? 446 00:24:06,803 --> 00:24:07,033 Tim 447 00:24:07,851 --> 00:24:08,171 What? 448 00:24:08,221 --> 00:24:08,621 Oh, SIEM. 449 00:24:08,651 --> 00:24:09,001 Okay. 450 00:24:09,105 --> 00:24:09,475 Siem. 451 00:24:10,035 --> 00:24:10,345 Yep. 452 00:24:10,461 --> 00:24:10,991 So the, the 453 00:24:11,345 --> 00:24:12,235 S-I-E-M 454 00:24:13,311 --> 00:24:18,341 the logs need to be immediately sent to a SIEM tool, which is, 455 00:24:19,231 --> 00:24:21,811 me, information… God dang it. 456 00:24:21,911 --> 00:24:23,671 What does SIEM stand for? 457 00:24:25,271 --> 00:24:25,581 It's 458 00:24:25,631 --> 00:24:26,331 S-I-E- 459 00:24:26,439 --> 00:24:26,869 security 460 00:24:27,061 --> 00:24:28,071 event management 461 00:24:28,943 --> 00:24:29,353 There we go. 462 00:24:29,403 --> 00:24:29,833 Okay. 463 00:24:29,993 --> 00:24:33,523 SIEM, which is not pronounced seam, who, 464 00:24:33,613 --> 00:24:34,443 Depends on where you're from 465 00:24:35,051 --> 00:24:35,801 Australians 466 00:24:36,232 --> 00:24:41,132 SIEMonster, that's why they called the company SIEMonster because where 467 00:24:41,132 --> 00:24:44,922 they're from, it's pronounced seam, and they had no idea that the rest 468 00:24:44,922 --> 00:24:46,292 of the world pronounces it SIEM. 469 00:24:46,672 --> 00:24:51,202 Anyway, just a little bit of, We had their CEO on here a while ago. 470 00:24:51,592 --> 00:24:54,572 it seems like it was yesterday, but my goodness, that's probably five years ago. 471 00:24:55,062 --> 00:24:59,042 so yeah, th- that has to happen because again, with- without that, 472 00:24:59,392 --> 00:25:02,922 you don't have the non-repudiation, and without that, you can't have this 473 00:25:02,922 --> 00:25:07,812 ability to do, to regularly do an audit, to then go in and say, "Was 474 00:25:07,812 --> 00:25:09,462 anybody logging in as administrator? 475 00:25:09,462 --> 00:25:12,882 Was administrator doing some things that where people were logging in?" 476 00:25:13,072 --> 00:25:16,462 And by the way, another thing that you can do is you can prevent the 477 00:25:16,462 --> 00:25:21,642 direct logging in of administrator, especially via remote, sessions, right? 478 00:25:21,672 --> 00:25:26,282 you can say that this can only happen on the console, and then you control 479 00:25:26,282 --> 00:25:27,972 that in a number of different ways. 480 00:25:28,322 --> 00:25:30,502 so let's talk about some action items, Mike. 481 00:25:31,682 --> 00:25:35,472 this first idea and, i- is this idea of an inventory. 482 00:25:36,042 --> 00:25:37,692 h- what are we talking about there? 483 00:25:39,869 --> 00:25:44,939 So what, what accounts, so those could be accounts that people log 484 00:25:44,939 --> 00:25:50,229 in with, could be service accounts, it could be support accounts, and 485 00:25:50,229 --> 00:25:53,609 they're also called, there, there are accounts we call fire call accounts. 486 00:25:54,049 --> 00:25:58,219 So we-- those are admin accounts that break glass in the event of fire. 487 00:25:59,769 --> 00:26:03,289 we need to inventory all of those and maintain some awareness of 488 00:26:03,289 --> 00:26:04,729 which ones are still active. 489 00:26:05,499 --> 00:26:09,179 and that should happen as often as it makes sense for your environment. 490 00:26:09,189 --> 00:26:10,569 Once a year at least. 491 00:26:11,699 --> 00:26:16,049 is, would be better, but if your environment experiences turnover, and 492 00:26:16,049 --> 00:26:21,549 that turnover could be third parties, vendors, support, new applications, new 493 00:26:21,559 --> 00:26:26,469 projects that, some big implementation or migration, or just normal employee 494 00:26:26,469 --> 00:26:31,729 turnover, you need to do an assessment of that, as often as it makes sense 495 00:26:32,171 --> 00:26:33,781 Are there tools to help with that, Mike? 496 00:26:33,781 --> 00:26:38,061 Because I could imagine it could get very gnarly in a large organization 497 00:26:38,061 --> 00:26:41,261 or a, an organization with a lot of these systems in place 498 00:26:42,425 --> 00:26:43,845 There are, and it doesn't… 499 00:26:45,975 --> 00:26:49,775 there, there's an IT tool for everything, and some of them are pretty pricey. 500 00:26:50,555 --> 00:26:54,365 today with the evolution of Python and PowerScript, there… and there's so many 501 00:26:54,365 --> 00:26:58,555 forums out there of admins that just wanna share knowledge and support each other. 502 00:26:59,305 --> 00:27:03,525 are free open source scripts and tools all day long. 503 00:27:04,635 --> 00:27:07,875 you just need to put the effort into finding one and testing it, 504 00:27:08,185 --> 00:27:10,105 and do test it before you use it. 505 00:27:11,015 --> 00:27:14,715 even Microsoft has free training on how to use the tools that come 506 00:27:14,715 --> 00:27:17,625 with Active Directory as an example. 507 00:27:17,895 --> 00:27:21,645 And then for those environments where there's some, it's a hybrid of, 508 00:27:21,755 --> 00:27:29,585 Windows, Linux, Unix, or even macOS, both Microsoft and these open source 509 00:27:29,615 --> 00:27:35,125 communities have and documentation on how to implement either scripts or 510 00:27:35,525 --> 00:27:40,595 middleware third-party tools, to pull that information into one, one report 511 00:27:41,702 --> 00:27:45,472 No, I would add to that inventory, you talked about mainly about 512 00:27:45,592 --> 00:27:47,802 particular accounts, right? 513 00:27:48,122 --> 00:27:53,262 I would add to that inventory the idea of, critical roles, right? 514 00:27:53,292 --> 00:27:56,162 Because for example, and again, I'll speak specifically from 515 00:27:56,162 --> 00:27:57,692 the backup software side. 516 00:27:58,132 --> 00:28:03,402 we… A long time ago, we got away from having to run the backup as root, right? 517 00:28:03,422 --> 00:28:07,042 Everyone's logging into the backup system as themselves, and they're 518 00:28:07,042 --> 00:28:08,252 doing everything that they have. 519 00:28:08,332 --> 00:28:11,722 the backup system itself is all-powerful, but when they're logging into the backup 520 00:28:11,762 --> 00:28:13,612 system, they're logging in as themselves. 521 00:28:13,792 --> 00:28:20,122 But in the backup world, I can think of, three, main roles that I would want to. 522 00:28:20,132 --> 00:28:22,732 You, earlier you talked about the idea of segregation. 523 00:28:22,792 --> 00:28:25,362 If possible, I would like to segregate these. 524 00:28:25,412 --> 00:28:28,842 One of is the ability to the backups, right? 525 00:28:28,842 --> 00:28:32,352 To configure the backups, which would mean adding things to 526 00:28:32,352 --> 00:28:35,832 the backups, more importantly, taking things out of the backups. 527 00:28:36,132 --> 00:28:40,592 also extending retention, reducing retention, right? 528 00:28:40,872 --> 00:28:43,612 the, just, or just completely deleting an entire configuration 529 00:28:44,352 --> 00:28:45,432 from the backups, right? 530 00:28:45,442 --> 00:28:46,162 that's one. 531 00:28:46,632 --> 00:28:52,432 The second would be like running the backups, like making sure that the backups 532 00:28:52,432 --> 00:28:56,862 are running, the ability to run one if it's not, if it didn't work last night. 533 00:28:56,992 --> 00:29:00,622 Also, the ability to report on those backups to figure out, what's working 534 00:29:00,622 --> 00:29:01,902 or what worked or didn't work. 535 00:29:02,332 --> 00:29:05,482 And by the way, going back to that, the reason why it's really important, 536 00:29:05,532 --> 00:29:10,602 if possible, to segregate that, the editing from the running is that, 537 00:29:11,062 --> 00:29:18,792 and, is that when someone, takes something out of the backups, person 538 00:29:18,792 --> 00:29:23,362 running the backups quite possibly is not going to a- ever see that, right? 539 00:29:23,392 --> 00:29:26,372 because what happens is they get exception reporting. 540 00:29:26,382 --> 00:29:28,882 They don't… and even if they get success reporting, they generally 541 00:29:28,882 --> 00:29:32,102 ignore the exis- all the successes because they get thousands of those 542 00:29:32,102 --> 00:29:37,752 a night, and they don't get a failure something didn't run anymore, right? 543 00:29:37,752 --> 00:29:39,062 They don't see that, right? 544 00:29:39,082 --> 00:29:42,922 And so we wanna have that, the idea of editing the backups be a very 545 00:29:42,922 --> 00:29:46,002 big thing and that's logged anytime, when it goes into that role and 546 00:29:46,002 --> 00:29:47,492 does anything, so that gets logged. 547 00:29:47,752 --> 00:29:51,682 And then the third would be, of course, restores, right? 548 00:29:51,792 --> 00:29:56,192 If possible, if we can segregate those three different roles, because why are 549 00:29:56,192 --> 00:29:59,652 restores, a po- a, an issue, especially when we're talking about the kinds 550 00:29:59,652 --> 00:30:00,932 of things we talk about, Prasanna? 551 00:30:02,051 --> 00:30:05,891 Because you can have a bad actor who restores data to some 552 00:30:05,891 --> 00:30:08,301 location or other things like that 553 00:30:09,054 --> 00:30:09,374 Yeah. 554 00:30:09,634 --> 00:30:12,004 Remember, our friend, Mr. Red Hat, 555 00:30:12,474 --> 00:30:12,884 Yes 556 00:30:12,938 --> 00:30:13,708 Dwayne LaFlotte. 557 00:30:14,108 --> 00:30:17,608 Remember he talked about he restored an active directory server, an 558 00:30:17,608 --> 00:30:21,958 active directory, a domain controller to some other area, and then he 559 00:30:21,958 --> 00:30:25,058 had all the time in the world to hack against that thing, right? 560 00:30:25,308 --> 00:30:29,158 and of course, it can also be used to exfiltrate just anything 561 00:30:29,478 --> 00:30:31,558 if you're able to do a restore. 562 00:30:31,558 --> 00:30:34,758 Because the, the other thing, one of the real concerns with 563 00:30:34,768 --> 00:30:39,148 backups and with restores is that they fall under the radar. 564 00:30:39,228 --> 00:30:44,098 a restore isn't gonna set off an alarm, quite possibly in, some 565 00:30:44,098 --> 00:30:45,588 sort of, event management tool. 566 00:30:45,588 --> 00:30:48,348 It's not gonna… It's gonna, it's gonna show up as regular. 567 00:30:48,608 --> 00:30:49,418 and maybe it should. 568 00:30:49,418 --> 00:30:53,198 maybe all restores should trigger some sort of report so that at least we 569 00:30:53,198 --> 00:30:56,258 know, somebody can double-check and make sure that we did the right thing. 570 00:30:56,258 --> 00:30:58,298 But, but that's the issue with restore. 571 00:30:58,298 --> 00:31:02,448 So my point, all of that was to just say we need to inventory these roles. 572 00:31:02,448 --> 00:31:06,538 There are dozens of those roles throughout the environment, 573 00:31:06,588 --> 00:31:07,948 not just the backup stuff. 574 00:31:08,028 --> 00:31:14,298 application access, records access, access to things like security controls, 575 00:31:14,338 --> 00:31:16,578 network controls, server controls. 576 00:31:16,618 --> 00:31:21,148 All of these things have roles that you can define them and segregate those, 577 00:31:21,198 --> 00:31:23,078 or inventory those as much as possible. 578 00:31:24,436 --> 00:31:24,756 So 579 00:31:25,058 --> 00:31:25,448 the, 580 00:31:25,448 --> 00:31:26,028 I think… 581 00:31:26,231 --> 00:31:26,321 go 582 00:31:26,321 --> 00:31:26,601 ahead 583 00:31:26,818 --> 00:31:27,028 wait. 584 00:31:27,408 --> 00:31:28,398 I have one thing, sorry. 585 00:31:28,608 --> 00:31:31,498 Going back to Mike, I know you mentioned you wanna periodically 586 00:31:31,498 --> 00:31:32,908 inventory these things, right? 587 00:31:32,908 --> 00:31:34,278 Or audit, right? 588 00:31:34,288 --> 00:31:39,888 To make sure that people have the right roles and you're doing the right things. 589 00:31:41,058 --> 00:31:46,878 I'm wondering though, as you start to tie roles with, Curtis, what 590 00:31:46,878 --> 00:31:48,348 did you say the other thing was? 591 00:31:48,348 --> 00:31:53,108 Roles with… You had another piece that you put in there. 592 00:31:53,125 --> 00:31:54,285 administrative accounts? 593 00:31:54,528 --> 00:31:58,998 Yeah, with the accounts, which I think you should also bring in, the 594 00:31:58,998 --> 00:32:02,138 resource themsel- or itself, right? 595 00:32:02,148 --> 00:32:06,598 Like for instance, if it's this role with this type of account accessing, 596 00:32:06,598 --> 00:32:10,548 say, an AWS resource, right? 597 00:32:10,708 --> 00:32:12,498 and looking at it end to end. 598 00:32:13,008 --> 00:32:16,878 I think those are the sort of things you probably wanna have, like some sort 599 00:32:16,878 --> 00:32:21,638 of automation, because resources might get spun up quickly or brought down, 600 00:32:21,638 --> 00:32:26,928 or even virtualization environments, to always make sure that what is actually 601 00:32:26,928 --> 00:32:32,108 getting assigned matches, like what should be there, rather than just looking at 602 00:32:32,108 --> 00:32:36,858 it more from an auditing perspective, but like an ongoing running basis. 603 00:32:37,828 --> 00:32:38,848 What do you think of that, Mike? 604 00:32:39,286 --> 00:32:41,406 th-there are tools for that. 605 00:32:41,556 --> 00:32:45,686 a lot of the, a lot of the implementation of those tools I've seen fall off 606 00:32:45,726 --> 00:32:47,946 over time because it's just more work. 607 00:32:48,796 --> 00:32:49,906 you've got a tool. 608 00:32:50,436 --> 00:32:54,716 The tool populates based on Active Directory primarily, unless you've 609 00:32:54,716 --> 00:32:57,926 got something like Samba or some other middleware that's pulling out 610 00:32:57,926 --> 00:33:01,806 of the Unix and other environments, you're not gonna see that in the tool. 611 00:33:01,806 --> 00:33:04,046 So there's something else that just complexity. 612 00:33:04,746 --> 00:33:07,976 right, then, if you don't have the tool that consolidates that into 613 00:33:07,976 --> 00:33:12,536 one view from a user perspective, then you've gotta log in to or at 614 00:33:12,536 --> 00:33:14,056 least review each one of these. 615 00:33:14,066 --> 00:33:18,516 You've gotta review in Active Directory all these different accounts, to see if 616 00:33:18,516 --> 00:33:21,076 there's notes or expiration or whatever. 617 00:33:21,816 --> 00:33:28,696 so long story short, however you decide to do the inventory, to your point, 618 00:33:28,706 --> 00:33:33,316 it needs more than just, "Here's the name of the account and the level of 619 00:33:33,316 --> 00:33:38,896 privilege." It also needs to include, why did, why was this, created? 620 00:33:38,906 --> 00:33:39,786 What's the description? 621 00:33:39,786 --> 00:33:40,616 What's the reason? 622 00:33:41,166 --> 00:33:42,456 Who's the stakeholder? 623 00:33:42,466 --> 00:33:43,286 Who owns this? 624 00:33:43,316 --> 00:33:45,026 Is IT, cis admin? 625 00:33:45,026 --> 00:33:45,836 Is it networking? 626 00:33:45,836 --> 00:33:47,606 Is it the security guys? 627 00:33:47,876 --> 00:33:48,986 Is it the business? 628 00:33:49,596 --> 00:33:51,096 'cause it, it could be anybody. 629 00:33:51,396 --> 00:33:56,706 So when we're doing this review, again should happen as often as necessary 630 00:33:56,866 --> 00:34:01,326 or appropriate, I'm reviewing this particular account to determine if that 631 00:34:01,326 --> 00:34:06,946 role is still appropriate and then who has access to this, to this account. 632 00:34:08,286 --> 00:34:12,326 There could be any number of other fields to track, when's the last time 633 00:34:12,326 --> 00:34:14,206 this account's password was changed? 634 00:34:14,606 --> 00:34:18,016 is there a defined expiration for this account? 635 00:34:18,036 --> 00:34:23,066 'Cause maybe it's something I set up for a, a vendor to do an implementation 636 00:34:23,066 --> 00:34:27,606 or help me, do whatever, and, I'm gonna auto-expire it 90 days from 637 00:34:27,606 --> 00:34:30,606 now just so that I don't have to worry about it between now and then. 638 00:34:31,386 --> 00:34:34,456 when's the last time someone reviewed this account? 639 00:34:34,466 --> 00:34:35,796 So there's a lot you could track. 640 00:34:36,076 --> 00:34:40,086 And if you do that in one place, and even in small environments, 641 00:34:40,086 --> 00:34:43,026 you've probably got a dozen or more of these privileged accounts. 642 00:34:44,176 --> 00:34:48,376 If you didn't have a good way of tracking and inventorying and man-managing all 643 00:34:48,376 --> 00:34:52,996 of those, you've gotta go into each one of those accounts manually to review 644 00:34:52,996 --> 00:34:55,066 notes and settings and other things 645 00:34:57,446 --> 00:34:59,766 this, still just call it a spreadsheet for now. 646 00:35:00,556 --> 00:35:04,226 you mana- as you manage the spreadsheet, you're only having to manage changes to 647 00:35:04,226 --> 00:35:06,986 one or m-more, not all of them probably. 648 00:35:07,686 --> 00:35:10,176 And then you just go back into your Active Directory or your 649 00:35:10,176 --> 00:35:12,786 system to update that vice versa. 650 00:35:13,839 --> 00:35:14,069 Yeah. 651 00:35:14,479 --> 00:35:17,489 and you touched on one final thing that we were gonna talk about, 652 00:35:17,489 --> 00:35:20,969 and that is this idea of expiring accounts that aren't being used. 653 00:35:21,199 --> 00:35:25,309 because th-there was a story that we covered a little while ago 654 00:35:25,309 --> 00:35:29,299 where somebody used an account that hadn't been used in a long time. 655 00:35:29,299 --> 00:35:30,559 Do you remember that, Prasanna? 656 00:35:31,299 --> 00:35:36,149 and we said, if they just had, automatic expiration of accounts, have happened. 657 00:35:36,209 --> 00:35:36,499 But, 658 00:35:37,769 --> 00:35:38,349 that one 659 00:35:38,781 --> 00:35:39,081 yeah. 660 00:35:39,431 --> 00:35:42,531 and that, that's true of a, of special account or that's true of a special 661 00:35:42,531 --> 00:35:45,851 privilege that you one-off that you gave somebody like you, Mike, you talked about 662 00:35:45,851 --> 00:35:50,411 with the vendor, that things like that should definitely have an expiration date. 663 00:35:51,341 --> 00:35:54,671 All right, so the idea of least privilege, good, right? 664 00:35:54,701 --> 00:35:57,751 you should have the least amount of privilege you need to do your job, 665 00:35:57,871 --> 00:36:02,511 and you should, inventory this as much as possible, inventory the accounts 666 00:36:02,511 --> 00:36:05,201 that have these special privileges, inventory the special privileges 667 00:36:05,201 --> 00:36:10,471 and different functionality that you have and where all of that, is used, 668 00:36:10,621 --> 00:36:11,911 and then put all of that together. 669 00:36:12,631 --> 00:36:16,911 And then, slo- it can start with a simple, inventory and that 670 00:36:16,911 --> 00:36:18,851 inventory can be a mess, right? 671 00:36:18,921 --> 00:36:23,111 Here's Curtis and here's the 1,700 different things that he has access to. 672 00:36:23,531 --> 00:36:25,791 and then you start putting, trying to put that together 673 00:36:25,851 --> 00:36:29,731 to, to move towards role-based administration and least privilege. 674 00:36:30,061 --> 00:36:34,791 it's going to be an effort, but, I would say one that's well worth it. 675 00:36:34,901 --> 00:36:36,041 Any final thoughts on that? 676 00:36:37,535 --> 00:36:42,505 I'll add real quick that if you're in an environment where admins are 677 00:36:42,525 --> 00:36:47,395 against this idea of least privilege and against the idea of inventorying 678 00:36:47,395 --> 00:36:50,485 accounts for… If you're getting any pushback at all, you should be concerned 679 00:36:51,375 --> 00:36:52,155 Go to a new company? 680 00:36:54,701 --> 00:36:55,071 Yeah. 681 00:36:55,101 --> 00:36:58,151 it's like in, in the backup world, like if you're having to argue with senior 682 00:36:58,151 --> 00:37:02,531 management that RAID is not a backup, maybe you should be somewhere else. 683 00:37:03,201 --> 00:37:03,641 all right. 684 00:37:03,671 --> 00:37:07,311 or if they're pushing for, RDP really needs to be, internet facing. 685 00:37:07,833 --> 00:37:08,713 Accessible from the internet? 686 00:37:08,763 --> 00:37:09,013 Yeah. 687 00:37:09,021 --> 00:37:09,911 yeah, exactly. 688 00:37:10,721 --> 00:37:11,121 All right. 689 00:37:11,121 --> 00:37:12,451 that is, Oh, wait a minute. 690 00:37:12,681 --> 00:37:14,761 so again, thanks for coming on, Mike 691 00:37:16,601 --> 00:37:17,101 Anytime 692 00:37:17,683 --> 00:37:19,543 And, Prasanna, thank you too as well 693 00:37:21,241 --> 00:37:21,721 Thanks, Curtis. 694 00:37:21,721 --> 00:37:25,261 I think after this, if you can adjust the poster, I wanna say 695 00:37:25,261 --> 00:37:27,811 it's like a millimeter maybe. 696 00:37:28,161 --> 00:37:30,871 Your bottom left corner needs to go left about a millimeter 697 00:37:30,929 --> 00:37:31,729 I'm American. 698 00:37:31,799 --> 00:37:33,479 I do inches and s- 699 00:37:33,583 --> 00:37:35,033 Oh, sorry, the bottom right corner. 700 00:37:35,363 --> 00:37:35,563 Yes 701 00:37:35,819 --> 00:37:36,209 okay. 702 00:37:36,269 --> 00:37:37,379 I'll see what I can do there. 703 00:37:37,729 --> 00:37:37,999 All right 704 00:37:38,029 --> 00:37:39,139 Thanks for listening, folks. 705 00:37:39,289 --> 00:37:40,319 That is a wrap. 706 00:37:43,478 --> 00:37:48,178 The Backup Wrap Up is written, recorded, and produced by me, W. Curtis Preston. 707 00:37:48,768 --> 00:37:53,528 If you need backup or DR consulting, content generation, or expert witness 708 00:37:53,528 --> 00:37:56,328 work, check out backupcentral.com. 709 00:37:56,838 --> 00:37:59,898 You can also find links for my O'Reilly books on the same website. 710 00:38:00,628 --> 00:38:04,598 Remember, this is an independent podcast, and any opinions that 711 00:38:04,598 --> 00:38:08,568 you hear are those of the speaker and not necessarily an employer. 712 00:38:09,438 --> 00:38:10,098 Thanks for listening