






Remote network monitoring is a technical specialty that was born almost at the same time as networks themselves. Since then, many strategies have emerged when it comes to monitoring network elements.
In this article we will talk about the current techniques based on SNMP polling and network statistic collection through Netflow, and we will also mention outdated systems such as RMON.
Most techniques are purpose-oriented, so they are especially useful. Some more modern ones use combined techniques to offer higher control and network knowledge.
What advantages does each one of them offer?
Remote network monitoring consists of detecting and knowing the status of any device connected to the network.
It can be network-specific hardware (such as a router, server, printer) or a specialized device (such as a probe or IoT element).
Simple, right?
Then let’s talk about the different techniques you have to monitor a network remotely.
Often this monitoring takes place through basic techniques.
With basic techniques we mean something as well known as pinging and checking whether the computer responds to the network.
What is pinging? It is a communication mechanism that allows you to find out whether a computer is connected and responds when you “knock” on its door.
To use it you just have to know its IP address.
Other basic techniques include measuring latency times (network lagging) or packet loss (network packet loss).
The most common and already much more network specific techniques include the use of the SNMP protocol (Simple Network Monitoring Protocol) that helps to obtain specific information from devices connected to the network: number of connections, incoming traffic through its network interface, firmware version, CPU temperature, etc.
Something that, if we use technical terms, is known as SNMP polling.
Other tools use protocols from the Netflow family (JFlow, SFlow, Netflow) to obtain statistical information about network usage.
This statistical information is incredibly useful to be able to analyze the use of the network, detect bottlenecks and, above all, to have a clear vision of what the communication flows between the different elements of a network are.
There is an almost obsolete protocol called RMON. However, it is worth mentioning, because we can still find it in some installations.
This protocol used a technology network monitoring technology that listened to the wire to obtain statistical information using a specific SNMP agent. Something like what Netflow does.
On the other hand, most devices still use SNMP TRAPS to report incidents in asynchronous mode.
Although it is a very old method, it is still used today as a monitoring method on almost all network devices.
Not to be mistaken with the SNMP Polling that we discussed at the beginning!
The most important and simple benefit is to find out the status of the network:
An example of a traffic flow diagram captured with Pandora FMS could be the following:

Most network management and monitoring systems automatically detect connected systems and draw a network map representing the network.
The most advanced tools allow you to update that map in real time and see even the physical connections between interfaces (known as a link-level topology or Layer 2).
For example, like this automatic network map generated with Pandora FMS:

Some systems incorporate what is known as IPAM (IP Address Management) and, at the same time, monitor the network status, allowing IP addressing to be mapped and controlled so that you know which networks are free and how they are used.
Generally, a tool like this one has a central server that allows you to detect systems and launch network tests (ping, icmp, snmp) to find out the status of each device.
To know the network in detail through its network flows in real time, you will need to configure the network routers and switches with the Netflow protocol and send that information to a Netflow collector. Although only professional medium/top-range network equipment supports the use of Netflow.
If you use an advanced monitoring tool, it will have its own Netflow collector.
Sometimes it is necessary to monitor devices that are in inaccessible networks, so intermediate polling servers, called proxies or satellites, are used.
These secondary servers perform network scans and monitoring on the devices nearby, and then send the collected data to a central system.
But what do we do with all this numerical data?
It is essential that the monitoring tool you use has graphs, reports and visual screens to display that data.
If we’re already talking about the top-of-the-range tools, those visual network maps will allow you to manually correct and add the details you need to manage those networks.
The professional tools that cover SNMP, Netflow, network maps and IPAM that work best today are:
Although they differ from each other in several respects, you may cover all your monitoring needs with any of them.
Would you like to know more about remote network monitoring tools? Then this will no doubt interest you:
Best network monitoring systems
Not all market tools cover these areas.
Some only support basic SNMP, but do not support Netflow. Others do not have good discovery or map editing capabilities and most of them do not have IPAM features.
The basic thing a good network monitoring tool should have is:
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About PandoraFMS
Pandora FMS is a flexible monitoring system, capable of monitoring devices, infrastructures, applications, services and business processes.
Of course, one of the things that Pandora FMS can control is the hard disks of your computers.






Given the current context, post-covid-19, talking about cloud security with CIEM has become essential. This is because the pandemic motivated the adoption of remote work by most organizations, which resulted in a significant increase in the adoption of cloud-based infrastructure.
As you can imagine, this feature presents particularities when it comes to cybersecurity. To get a sense, Gartner predicts that companies will suffer at least 2,300 violations of privilege policies annually by 2024.
Also according to Gartner, multi-cloud environments introduce a large cyberattack surface that can be exploited by malicious agents. Thus, incorrectly configuring security and identity tools in cloud environments may have violations as a consequence. Therefore, it is not recommended that the settings and maintenance in the access policy be performed manually.
Added to this is the fact that conventional solutions, such as IGA and PAM, may not be efficient to manage this demand. In addition, with infrastructure as a service (IaaS), access management is the responsibility of the client company. According to Gartner, 99% of data breaches occurring in a cloud environment are the responsibility of the customer, not the Cloud Service Provider (CSP).
In this article, we share everything you need to know about cloud security with CIEM. To make our text more understandable, we divided the content by topics. These are:
Follow our text to the end!
In the 1950s, computers were very expensive and companies had access to few machines. For this reason, in the following decade, cloud computing began to be discussed by experts.
The first person to suggest shared use of computers was American computer scientist John McCarthy, who named this concept Utility Computing.
In the following years, Joseph Carl Robnett Licklider studied different ways to use the computer and the Network of Advanced Research Project Agencies (Arpanet), which he helped develop, enabling two or more computers to share data, even in different locations, according to the principles of accessibility and availability.
But the term “cloud computing” was only used for the first time in the second half of the 1990s, in an academic lecture given by the professor of information systems, Ramnath Chellappa. This expression is based on the symbol of the internet: the cloud.
Today, we also have the concept of multi-cloud, which consists of the use of various cloud services. These services can be provided by third-party providers or include a private cloud, whose technology is in the organizations’ own data center.
This type of solution enables IT teams to perform individual operations efficiently, while companies reduce costs.
There is also the hybrid cloud concept, which unites public cloud services with a private cloud, simplifying remote cloud operations and providing more flexibility for businesses.
However, unlike cloud environment management, which must be managed in isolation, hybrid cloud management needs to be based on a unique strategy.
With the evolution of technology, cloud computing has become accessible, and remote work, adopted by many organizations after the beginning of the covid-19 pandemic, has made this resource widely used.
The big issue is that the larger the company, the more people will have access to cloud-based environments. Moreover, many permissions are granted to applications and machines that connect to other applications and databases to exchange information.
Thus, it is necessary to have a strategy that limits unnecessary access and prevents inadequate sharing of information, which can be achieved through CIEM.
Cloud Infrastructure Entitlements Management (CIEM) has the function of managing access in cloud and multi-cloud environments.
This is possible through the access principle of least privilege, which contributes to companies that need to avoid risks such as attacks by malicious users and information leaks, problems generated by excessive permissions on this type of infrastructure.
Thus, a CIEM solution allows you to remove these excessive permissions and centralize the visibility and control of permissions of a cloud environment.
Through the use of artificial intelligence, a CIEM solution is also able to analyze exposure levels of a company’s cloud environments, enabling the identification and reduction of cybersecurity risks.
. Why Are CIEM Solutions Important?
Using cloud resources is very beneficial for businesses, as it allows them to simplify their operations and save time.
However, traditional identity and access management (IAM) tools are aimed at protecting static applications and structures rather than cloud infrastructure, which is extremely dynamic.
So, cloud providers have launched their own resources to ensure cybersecurity in this type of environment. Despite this, the dynamism and diversity of cloud environments continue to pose challenges to ensure data protection and compliance with security policies.
After all, it is necessary to keep in mind that when a company uses the cloud to become more efficient, it can increase its attack surfaces with the excess of permissions in that environment. To make things worse, in such cases, it may not have the visibility and control necessary to apply the principle of least privilege.
In this sense, CIEM solutions are essential to improve visibility, identify and correct incorrect access-related settings with minimal privileges in cloud and multi-cloud infrastructures, and thus ensure the organization’s cybersecurity.
A CIEM solution can generate several benefits for an organization. Check out the main ones below:
In the following topic, we approach these benefits from another perspective: by showing how CIEM can be used to ensure more cybersecurity for companies.
Good IT security requires discovering and classifying identities and recognizing permissions granted to people and machines in order to prevent data leaks and breaches. In this sense, CIEM can be used to:
CIEM enables continuous monitoring of identities and permissions, including changes in rights;
For DevOps teams, managing cloud computing while maintaining information security can be challenging, after all, their priorities are speed and innovation rather than security.
This is because the services must be launched or provisioned with agility, which ends up causing an excessive granting of permissions. However, the manual blocking of these rights is complex and compromises the fundamental speed for this type of operation.
With CIEM, one can eliminate excessive permissions automatically, without interrupting developers, who can deploy code quickly and securely.
Check out the advantages of contracting the senhasegura CIEM service below:
By reading this article, you saw that:
Did you like our article on CIEM solutions? Share it with someone who can benefit from this knowledge.
ALSO READ IN SENHASEGURA’S BLOG
How to Create a Secure Password Policy?
Learn All About Passwordless Authentication
Password Strength: How to Create Strong Passwords for Credentials?
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.



DevsecOps is the abbreviation for development, security, and operations and has gained a lot of attention among the best methodologies for software development. According to Gartner, by the end of 2021, DevSecOps practices will be implemented in 60% of agile Development teams, compared to 20% in 2019. DevSecOps practices prioritize cooperation, collaboration, and responsibility-sharing among information security teams.
Privileged access management (Pam), on the other hand, obeys the principle of least privilege, avoiding cyberattacks carried out through privileged credentials, such as breaches and data leaks, and can help achieve DevSecOps throughout software development.
In this article, we cover these concepts and their implications more deeply. To make your understanding easier, our text is divided by topics:
DevSecOps is a way to integrate security practices into the DevOps process, which provides launch engineers and security teams working collaboratively through agile software development methodologies.
DevSecOps aims to develop new solutions for complex software development processes in an agile and secure way.
It is a solution to the old security methodologies in the continuous delivery pipeline nowadays, which aims to promote the fast and secure delivery of codes. In this case, silo thinking is replaced by a process that favors communication, cooperation, and sharing of security tasks during the stages of the delivery process.
In DevSecOps, it is possible to bring together two seemingly opposite purposes, secure code and speed of delivery, through a facilitated process.
Aligned with the mechanisms of Agile, security tests, in this case, are performed in iterations, avoiding delaying delivery. In this way, security problems can be solved as soon as they are identified, even before compromising the results.
In DevSecOps, it is possible to bring together two seemingly opposite purposes, secure code and speed of delivery, through a facilitated process. Thus, one can take advantage of the resources of agile methods and create secure codes.
According to an EMA report released in 2017, the two biggest advantages of security operations are improved operational efficiency in IT, including security, and improved ROI in security infrastructure.
The same study found another important benefit: the possibility of using 100% of cloud services. Other known advantages of DevOps that are inherited by DevSecOps:
Privileged access management (Pam) has the function of protecting organizations against threats such as theft of credentials and misuse of privileges.
It consists of an information security strategy that involves users, as well as processes and technology to monitor, protect, control, and audit the privileged activities in the IT structure of a company.
Also known as privileged access security (PAS) and privileged identity management (PIM), PAM considers the principle of least privilege, respected when users receive only the credentials necessary to perform their corporate tasks.
This cybersecurity practice is of paramount importance for protecting privileged access to valuable data. With it, you can reduce the attack surface and minimize the risk of data breaches.
One of the biggest vulnerabilities for IT structures is human action, including privileged users who go beyond their access level and invaders who appropriate these privileges to operate.
In this sense, the importance of PAM for organizations is to enable the identification of malicious actions by security teams and ensure employees have only the required access to perform their work, as mentioned in the previous topic.
Thus, companies that adopt PAM as a cybersecurity mechanism achieve several advantages, such as minimizing security risks, reducing their surface area of cyberattacks, reducing operating costs, and achieving compliance with strict data protection policies, such as the LGPD.
By reading the previous topics, you can see the importance of PAM for cybersecurity. Here’s how this approach can contribute to DevSecOps throughout the software development cycle:
In our article, you learned that:
Was this content useful for you? Share it with someone else who may also be interested in the topic.
ALSO READ IN SENHASEGURA’S BLOG
Learn All About Passwordless Authentication
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.


BRATISLAVA, KOŠICE — April 6, 2022 — ESET researchers have analyzed three malicious Android applications targeting customers of eight Malaysian banks. To make a profit off customers who have increasingly turned to online shopping during the pandemic, cybercriminals are tricking these eager shoppers into downloading malicious applications. In an ongoing campaign, the threat actors are trying to steal banking credentials by using fake websites that pose as legitimate services, sometimes outright copying the original. These websites use similar domain names to the services they are impersonating.
“To make the already couch-friendly approach of online shopping even more convenient, people are increasingly using their smartphones to shop. Smartphone purchases make up the majority of online shopping orders – most of them from vendor-specific applications,” says ESET researcher Lukáš Štefanko, who analyzed the malicious applications.
This campaign was first reported at the end of 2021, with the attackers impersonating the legitimate cleaning service Maid4u. Distributed through Facebook ads, the campaign tempted potential victims to download Android malware from a malicious website. In January 2022, MalwareHunterTeam identified three more malicious websites and Android trojans attributed to this campaign. Recently, ESET researchers found four additional fake websites. All seven websites impersonated services that are only available in Malaysia.
The copycat websites do not provide an option to shop directly through them. Instead, they include buttons that claim to download apps from Google Play. However, clicking these buttons does not actually lead to the Google Play store, but to servers under the threat actors’ control. To succeed, this attack requires the intended victims to enable the non-default “Install unknown apps” option on their devices. When the time comes to pay for the order, the victims are presented with payment options – they can pay either by credit card or by transferring the required amount from their bank accounts. At the time this research was active, it was not possible to select the credit card payment option.
After picking the direct transfer option, victims are presented a fake FPX payment page and asked to choose their bank out of the eight Malaysian banks provided, and then enter their credentials. The targeted banks are Maybank, Affin Bank, Public Bank Berhad, CIMB bank, BSN, RHB, Bank Islam Malaysia, and Hong Leong Bank. After the victims submit their banking credentials, they receive an error message informing them that the user ID or password they provided was invalid. At this point, the entered credentials have been sent to the malware operators. To make sure the threat actors can get into their victims’ bank accounts, the fake e-shop applications also forward all SMS messages received by the victim to the operators in case they contain Two-Factor Authentication (2FA) codes sent by the bank.
“While the campaign targets Malaysia exclusively for now, it might expand to other countries and banks later on. At this time, the attackers are after banking credentials, but they may also enable the theft of credit card information in the future,” adds Štefanko.
ESET Research has found the same malicious code in all three analyzed applications, leading us to conclude that they can all be attributed to the same threat actor.
To protect yourself against this type of threat, first, try to ensure that you are using legitimate websites to shop:
For more information, check out the blogpost “Fake e-shops on the prowl for banking credentials using Android malware” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.


Bratislava, April 5th, 2022 – ESET, a global leader in cybersecurity, and Borussia Dortmund are continuing their successful collaboration for at least two more seasons. As in the past three years, ESET will remain a Champion Partner of BVB.
Football is a constantly progressing sport, where tactics evolve, the game speeds up, new tricks appear. But one insight outlasts all developments: strong defense must stand. Technology is also ever-evolving, enabling progress on its way. With its brand message “Progress. Protected.” ESET makes the promise to protect this progress with its IT security products and services. ESET is not only one of the major sponsors of the successful German football club, but is also an IT security partner and is responsible for securing BVB’s IT infrastructure.
“From the very beginning, we believed that Borussia Dortmund was a natural fit for ESET because we stand united by our common values of courage, passion, integrity and reliability.” said Richard Marko, CEO at ESET. “After three compelling seasons, our partnership with Borussia Dortmund is entering its prime and we are delighted that this success story will continue for at least two more seasons.”
“We are very pleased that the cooperation between Borussia Dortmund and ESET will continue. This is a meeting of two strong and international brands that absolutely fit together,” said Carsten Cramer, Managing Director at Borussia Dortmund. “With great campaigns for fans, ESET has repeatedly put exclamation points behind the past three seasons and drawn attention to its goals of bringing digital security to everyone. I am convinced that we will continue achieving great things together with ESET in the next two seasons.”
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.



After the successful launch of its business-oriented siblings, ESET has extended its latest technology to home users/consumers and stands ready to protect their Windows on Arm-based devices with our award-wining full-featured products. Our development teams put a lot of effort into reengineering ESET’s already mature security technology for ARM-powered devices, which are increasingly used in both business and home applications.
Thanks to its multilayered approach to protection, ESET Smart Security® Premium, ESET Internet Security and ESET NOD32 Antivirus products for Windows on ARM offer a slew of prevention and detection technologies. A key contribution to extending these functionalities was the invaluable feedback of the ARM64 beta products’ home testers. Their insights mean you will enjoy our well-regarded user experience and the same award-winning protection ESET customers are used to.
Just like the award-wining Windows-based product, the version for ARM64 also includes ESET LiveGuard, which provides an additional proactive layer of protection against never-before-seen types of threats, protecting users before the malware has a chance to execute its action. Another feature is the addition of Password Manager, which has been completely redesigned for improved security and an even more user-friendly experience.
Underlying these key improvements is the ESET Home platform, which is designed for on-the-go security management. The platform enables users to add, manage and share licenses with family and friends, and to manage Anti-Theft, Parental Control, and Password Manager via a web portal. ESET Home directly supports ARM64 users who’ve opted to protect the progress enabled by mobile-centric “always on” devices.
With so many of us experiencing crossover use of our work and personal devices in the current work from home/hybrid work regime, ESET technologies now better reflect the extra protection that highly mobile users and their computing needs demand. Whether moving between multiple public and private networks, or managing devices visiting your home network, our new products recognize that “Always On” also risks “always” being vulnerable. The risks are backed up by considerable research showing that threats targeting employees working remotely from home have vastly increased. And, via customer research conducted by ESET showing that households often have a single person who takes care of IT security for everyone, having a solution that provides easy-to-use security management at the home admin’s fingertips is crucial.
Hence, a critical part of your move to ARM should undoubtedly be security provided by a mature consumer security solution. To find out more about the new features and improvements in the latest version of our consumer offering, head to www.eset.com.
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About ESET
For 30 years, ESET® has been developing industry-leading IT security software and services for businesses and consumers worldwide. With solutions ranging from endpoint security to encryption and two-factor authentication, ESET’s high-performing, easy-to-use products give individuals and businesses the peace of mind to enjoy the full potential of their technology. ESET unobtrusively protects and monitors 24/7, updating defenses in real time to keep users safe and businesses running without interruption. Evolving threats require an evolving IT security company. Backed by R&D facilities worldwide, ESET became the first IT security company to earn 100 Virus Bulletin VB100 awards, identifying every single “in-the-wild” malware without interruption since 2003.



Our research team has put together all of the most relevant news topics in the ICS, IT, Ransomware & OT security fields, as well as their impacts and their expert recommendations:



Secrets like passwords and ssh keys are scattered throughout the software development process. However, few people can access this data. Controlled access is still a major challenge for development teams, due to difficulties in managing this information and adopting non-recommended standards.
The standards that can compromise the security of a system include weak passwords, a topic already addressed here in senhasegura‘s blog.
However, in this article, we will bring more details about the management of secrets in development processes. To facilitate your understanding, we divided our text into the following topics:
Follow our text to the end!
All authentication credentials used in applications and services in an IT structure are considered secrets. This includes passwords, ssh keys, API keys, OAuth tokens, and configuration files.
Secrets management can be viewed as enhanced password management, which includes creating, rotating, revoking, and storing credentials.
After all, the scope in this case is broader, but the purpose remains to protect against unauthorized access to data and systems, data losses, and breaches.
Secrets management contributes to cybersecurity in three instances. They are as follows:
Another advantage of secrets management is to help bring organizations into compliance with the requirements of demanding cybersecurity standards, such as FIPS, NIST, and HIPAA.
Secrets management involves some difficulties. Next, let’s point out the most common ones. Check it out:
Lack of Visibility
With the migration of IT infrastructure to the cloud, the number of resources, systems, applications, and accounts changes frequently. As a consequence, the places where secrets are stored also change.
Therefore, for an organization to remain secure, it is essential to know clearly where this information is stored. What’s more: A lack of visibility can also create obstacles to managing these resources, or when going through an audit.
Lack of Management Policies
To meet the criteria of security regulations and facilitate the control of the life cycle phases of a secret, companies must define rules in security policies, which does not always occur.
Manual Management
Most organizations do not use automated secret management capabilities to manage their digital credentials yet. In this way, they delay the management process and make the storage of secrets more vulnerable.
Many organizations still have non-recommended standards in their password management routine. Here are a few:
Weak Passwords
Due to the difficulty in memorizing complex passwords, many people adopt simple and easy-to-remember codes. However, this is one of the main vulnerabilities when it comes to password management. After all, easy-to-remember passwords are just as easy to crack.
Also, malicious agents can discover embedded and encoded passwords with the help of verification tools, by performing a brute force attack or simply guessing.
Password Sharing
Many companies use shared accounts and passwords to manage their systems, making it impossible to identify who performed each action within an online environment in the event of an incident.
In addition, their employees can share passwords with co-workers or others, facilitating the action of attackers interested in sensitive organization data.
Storing Secrets in Plain Text
It is common for employees in a company’s department to use text files that contain all passwords for critical situations or forward messages to colleagues with the necessary secrets to access a resource.
Nevertheless, these practices pose risks to the cybersecurity of organizations: attackers only need to obtain a file, message, or email to have tools to hack a system.
Reuse of Secrets
It is also very common to reuse secrets for different services in order to facilitate their memorization and save time. However, if one malicious user discovers one code, the others will also be compromised.
Unrevoked Secrets
NIST has as a criterion the revocation of user credentials when necessary. This should occur in the event an employee is fired or a contract with a third-party supplier is terminated, for example. However, this security procedure is not followed by all organizations.
Secrets Without Rotation
Various security standards dictate that passwords be changed within a given time frame, as do application keys and other types of secrets. Once again, it is not all companies that follow this recommendation.
Five Key Practices for Secret Management
There are several ways to provide a secure method for protecting secrets. The following are five important steps to achieve this goal:
Centralized Secrets Management
First, you should centralize your secrets in one place to ensure more security and facilitate their management. This makes it easier to build governance, security, and auditing to know who accesses this information and when it is accessed.
ACLs (Access Control Lists)
Once you have your secrets centralized in one place, make sure the right people have access to them. To do this, you can create human, machine, and application ACLs that give you control of that access.
Temporary Credentials
The third and fourth actions must occur simultaneously: they consist of having dynamic secrets. In practice, to ensure dynamic secrets, individuals and entities must be given temporary credentials to access the systems.
Encryption
As mentioned, it is important that data in transit or at rest can be encrypted, with encryption keys centralized in secrets management.
Audit
Now, you might be wondering how to audit your secrets management and know what was accessed by which user.
Each dynamic secret can be used by a single user, who is properly authenticated when retrieving this information, and encryption as a service allows you to know who accessed an encryption and decryption operation. All of this can give you a complete picture of everything that happens in your IT infrastructure.
Conclusion
By reading this article you have learned what secrets are, how they should be managed, and what are the biggest challenges in managing this information. You were also able to understand which standards are not recommended in password management, such as:
In addition, we presented five fundamental practices for good secrets management.
Did you like our text? Share it with someone interested in this information.
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.
About Segura®
Segura® strive to ensure the sovereignty of companies over actions and privileged information. To this end, we work against data theft through traceability of administrator actions on networks, servers, databases and a multitude of devices. In addition, we pursue compliance with auditing requirements and the most demanding standards, including PCI DSS, Sarbanes-Oxley, ISO 27001 and HIPAA.