System administration control
Even a king is a human being...
Now a system administrator - carrying too far a bit - has full powers over all of the IT systems. Generally the IT and the system administrators' activities are significant parts of the daily business: we can issue invoices, our document are in secure, and our stock information is available by their help. If the systems are extended so that a team handle them, the companies try to answer to this challenge with process-based operation. The process-based operation guarantees that all persons in the team know the own and the others' tasks and who is responsible for what. In most cases, in practise, this process description cannot be adopted to the real IT operation. In the meantime, exposure of the system to the human resources is dramatic. Then new tasks come: audits, updates, new systems, preparation for a heralded powercut. In an overcharged team a mistake can happen easily: misconfiguration, unauthorized database modification, accidental delete, file moving, modification, forgotten task.
In case of trouble...
|
|
We take the availability and expected operation of the systems for granted until a sort of stoppage happens. Until a system operates well, we feel that is in the course of nature, and it is familiar idea all of us. But, when the system stops by a sort of error, we live through it like a disaster. Of course, every system stoppage can be come through awhile, but every stoppage can cause discomfort, at worst, property damage for our company. In this case, a software help may come in handy, in order to find out that who, when and how made a mistake, where can we fix or recover it. So, we can recover our system as soon as possible. If we reach it, the analysis is the next step:
|
Whole establishment of the process-based operation can present some difficulties, that's why in some cases it means quicker solution if we use specific tools to explore, prevent or handle problems.
The solution is Balabit Shell Control BoxBalabit Shell Control Box (SCB) is a tool for administration checking, monitoring and auditing servers and network appliances. We can check the encrypted connections with it, so we can control the system administration activities and processes. SCB is independent from the clients and servers, an outside appliance focusing the administrative traffic. The advantages can be reached using it are:
Balabit SCB solution records all activities of system administrators as a film: we can look the issued orders, which systems were modified and how. In case of incident, the circumstances can be reached in the SCB audit trail files. So the cause of the incident can be described easily. Entire control of the administrative channelsSCB is for control the SSH, RDP5, RDP6, VNC, X11 Telnet -s TN3270 channels used to reach servers and network appliences. We can determine that who, when and from where can connect to a given server (e.g. from inside only), which channels can be used for in SSH and RDP connections. We can disable the needless channels (e.g. SSH port forward, RDP file sharing), so our systems will become more secure. By control the SSH keys, we can prevent man-in-the-middle attacks. The regulation established via SCB is obligatory and cannot be bypassed in the whole network for all system administrators. A higher responsibility level comes into being, without so much as any server- or client-side applications must be modified. System implementationWeb interface of SCB and role-based administration make possible the compliance to the security purposes and use of full functionality of the system. Implementation of the system guarantees immediate results: implementation should be started with default system configuration, then pushing on with the security consciousness SCB can be customized following the projects and purposes. So every functionality of it can serve the company security easily, step-by-step. |
Audit
Beyond the incident handling, you can audit the channels used to administer servers and network appliances by the help of SCB. The whole traffic (including the configuration modifications, executed commands etc.) can be logged and archived encrypted and digitally signed audit trail format, so there is no possibility to manipulate and modify data.
IdM - Identity Management
Nowadays, essence of IdM projects is not the technology, but business approach via surveying, modifying, establishing, automatizing workflows across the company. More
SaaS - Software as a Service
Using a software as a service, the SaaS model - can give a new vision for the IT operation. Advantages of the SaaS comparing with the traditionally licensed software are cost decreasing, quick return on investment, and lower risk. More


