The purpose of this article is to discuss the differences between PAM and IAM.
PAM vs IAM – They Represent Different Goals
Privileged Access Management is a subset of Identity and Access Management, however, it could be argued to be more important because of the risk profile of the accounts that PAM manages versus the risk profile of the accounts that IAM typically manages. The type of accounts managed by PAM solutions have access to sensitive data and has the capability to make powerful changes. IAM’s focus however, is to focus on driving operational efficiency and cyber security for general users and the applications and data they use.
If a breach happens where a single user’s credentials have been compromised, an attacker would have access to their data and applications. The attack is silo’d to that specific user, unless the attacker can move around by phishing or some other method. If a breach happens where the credentials to a privileged account has been compromised, then the attacker has access to everything for which a privileged account has access.
What is a Privileged Account?
What classifies a privileged account? A privileged account is any account that has administrative privileges for servers, network infrastructure, security tools, database servers, applications, and local administrator accounts. These types of accounts have the ability to create credentials, remove/add/change permissions, access file shares, and change configuration settings. They are essentially the keys to the kingdom. Privileged Users are typically IT admins but also may include third party vendors, and applications (think WebEx having API integration to e-mail).
Challenges with PAM (or Privileged Accounts)
The challenges around privileged account management is that it has typically not been done. Passwords to privileged accounts have been stored in excel files in plain text. Switch and router passwords have not been changed in years because there is no governance dictating a need. There are accounts that have been created for vendors that have been left open and turnover in IT so these accounts are not known about and IT is nervous to remove them. IT doesn’t even know who to talk to about some of the accounts or have the skill set or knowledge base to understand how to find outlying accounts. There is no life-cycle management happening to accounts with privileged access. There is no monitoring or auditing to accessing accounts with privileges. There is no monitoring or auditing of what happens during the session that a privileged account is making changes to the environment.
Conclusion
Arguably, protecting privileged accounts has the greatest impact on any cyber security strategy. There are several tools available to help an organization with their privileged accounts and they refer to their solutions as Privileged Access Management, Privileged Account Management, and Privileged Identity Management among others. These tools can help operationalize and automate the management of accounts and access with privileges by creating workflows, automatically rotating passwords that are not found within Active Directory, and monitoring and auditing past activity those accounts have had.
Ultimately PAM solutions can help an organization with security, compliance and automation. PAM solutions mitigate the threat of pass the has attacks, implement the principle of least privilege, remove default passwords, control the user of privileged accounts, and mitigate the risk of insider threats.