BeyondTrust > 实例探究 > DCI Exceeds Compliance Requirements for Privilege & Password Management

DCI Exceeds Compliance Requirements for Privilege & Password Management

BeyondTrust Logo
公司规模
200-1,000
地区
  • America
国家
  • United States
产品
  • PowerBroker for Unix & Linux
  • PowerBroker Password Safe
  • iCore360® software
技术栈
  • Unix
  • Linux
  • Solaris
  • Ubuntu
  • SUSE
实施规模
  • Enterprise-wide Deployment
影响指标
  • Cost Savings
  • Customer Satisfaction
  • Digital Expertise
技术
  • 网络安全和隐私 - 数据库安全
  • 网络安全和隐私 - 身份认证管理
适用行业
  • 金融与保险
适用功能
  • 离散制造
  • 质量保证
用例
  • 网络安全
  • 基础设施检查
服务
  • 软件设计与工程服务
  • 系统集成
关于客户
DCI is a premier developer of core banking software and technologies, including the award winning iCore360® software used by hundreds of community banks nationwide to securely manage all aspects of bank operations, transaction processing and account information. DCI is an independent, privately-owned company with several bank clients serving as owners, board members and user-group leaders. For over 50 years, this bank-driven ownership and collaborative relationship has differentiated DCI through a more personal approach to technology development and customer care. As a result DCI boasts an impressive track record of technical innovation and client satisfaction.
挑战
In 2010, DCI expanded the scope of their internal auditing requirements to include access related areas such as user privileges, password rotation policies, review of access sessions, and access history. To address compliance requirements, the team also decided to lock down the development, test and internal business servers to protect vast amounts of sensitive data. This meant that they had to fully restrict root access, reset all passwords after each use, and periodically rotate them — whether they were used or not. Even SSH access had to be limited. To fulfill these needs, DCI required a procedure to delegate and authorize specific limited functions on each server, when access was required. They also wanted different login IDs for different functions on each server, plus a workflow whereby two managers could grant access to specific functions at particular times. Activity on the servers also had to be tracked by ID, including the functions allowed by each ID.
解决方案
DCI sought a privilege and password management solution that they could efficiently deploy to meet immediate compliance needs, while future-proofing their processes for upcoming financial services regulations. They also required a solution that could accommodate 1,500+ users and support a multitude of access rules and policies across the entire IT environment. DCI selected BeyondTrust PowerBroker for Unix and Linux to delegate portions of privileged accounts on the Solaris, Ubuntu, and SUSE servers, as well as PowerBroker Password Safe to manage the approval process and rotate server passwords. PowerBroker for Unix and Linux has flexible policies that enabled delegation and enforcement of the different IDs, each for a portion of the privileged account functions on each server. A master server handles password requests and updates passwords on all systems. Loggers record all activity on each server. Since the initial policies were established, maintaining the PowerBroker solution has required minimal effort and only occasional updates. PowerBroker Password Safe provided the key to managing privilege passwords at DCI. The appliance was easy to deploy, and the solution now encrypts and rotates all passwords at DCI. It also audits all password use and records all privileged sessions for replay when needed. Password Safe’s workflow capabilities enable IT administrators to schedule and submit requests for passwords required to conduct server maintenance. The required two managers receive alerts and can approve password requests at their convenience. In the end, DCI’s IT administrators can be confident that they will have access to the systems they requested during their maintenance windows.
运营影响
  • All server access is limited — even via SSH.
  • The auditors can easily see that procedures are being followed and our IT employees are able to remain productive.
  • Today we are working with our internal auditors to become PCI DSS 3.0 compliant, as requirements and customer needs continue to increase. BeyondTrust continues to facilitate these compliance efforts.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

相关案例.

联系我们

欢迎与我们交流!
* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

感谢您的信息!
我们会很快与你取得联系。