Cyber-Ark Publishes Steps to Implement NIST 800-53 Controls and Continuous Monitoring with a Special Focus on Privileged Account Management
| Copyright: | Copyright Business Wire 2011 |
| Source: | Business Wire, Inc. |
| Wordcount: | 828 |
Whitepaper Outlines the Recommended Security Controls for Federal Information Systems and Organizations and Related Steps Toward Gaining FISMA Compliance
NIST 800-53 provides federal information systems and agencies with the recommended security controls to ensure ongoing situational awareness of the security of their IT systems. Cyber-Ark’s whitepaper was developed in conjunction with the increased focus that NIST 800-53 has placed on instilling controls to combat insider threats and the abuse of privileged accounts, while drawing attention to some of the shortcomings of traditional encryption-based approaches. In particular, it focuses on steps organizations can take to better manage across the privileged account management lifecycle, gain better control over shared accounts and institute real-time continuous monitoring solutions as part of a comprehensive risk management framework.
An Overview of Primary Security Controls and the Privilege Connection
While some aspects of Privileged Identity Management may be addressed procedurally, the majority of the necessary security controls outlined in NIST 800-53’s recommendations require a dedicated solution for the proactive management and audit of privileged users. Cyber-Ark’s Privileged Identity Management Suite and Privileged Session Management Suite enable an organization to execute the following controls to securely provide users and applications with the privileges needed in order to complete their role—and their role only:
- Access Control:
As the foundation for the management of users and accounts, this control addresses the creation and assignment of privileges. According to NIST 800-53’s recommendations, particular attention must be paid to privileged accounts and their elevated access rights to the sensitive information stored in a variety of information systems. Cyber-Ark emphasizes the importance of controlling access across the privileged account lifecycle, encompassing steps for auto-discovery, management, policy definition and monitoring.
- Audit and Accountability:
As NIST 800-53 suggests, this set of controls is critical when establishing a proactive approach to audit compliance and accountability. As detailed in the guidelines, auditable information must be available on demand. Without these built-in controls to continuously access sensitive information, log and monitor privileged actions, organizations will sacrifice accountability and fail to satisfy compliance requirements. Cyber-Ark’s Digital Vault provides tamper proof audit and log retention which is critical for ensuring the authenticity and safe keeping of all privileged audit information.
- Identification and Authentication:
This control, according to NIST 800-53, asserts that “the information system uniquely identifies and authenticates organizational users.” This is especially critical for privileged and shared accounts—commonly utilized among the IT staff, diminishing an organization’s accountability while exposing password vulnerabilities. This control will establish a more effective password management program and accountability for shared accounts.
“With each release, NIST guidelines detail the most critical security controls that must be implemented to mitigate security vulnerabilities. With NIST 800-53, it is clear that privileged account management is moving to the top of the risk assessment priority list for many organizations,” said
The NIST 800-53 whitepaper also describes applicable Cyber-Ark solutions to establish NIST 800-53 controls through a preventative approach to information security. Cyber-Ark provides several federal agencies with industry-leading solutions that protect critical assets, identify potential security vulnerabilities and mitigate risks by proactively managing and monitoring privileged accounts and activities.
About Cyber-Ark
Cyber-Ark® Software is a global information security company that specializes in protecting and managing privileged users, applications and sensitive information to improve compliance, productivity and protect organizations against insider threats and advanced external threats. With its award-winning Privileged Identity Management, Sensitive Information Management and Privileged Session Management Suites, organizations can more effectively manage and govern data center access and activities, whether on-premise, off-premise or in the cloud, while demonstrating returns on security investments. Cyber-Ark has become the best practice standard by many federal organizations, military and government agencies around the world, and all of its products are approved for listing in both the
Copyright © 2011 Cyber-Ark Software. All Rights Reserved.All other brand names, product names, or trademarks belong to their respective holders.
fama PR
[email protected]
or
[email protected]
Source: Cyber-Ark



Wells Fargo Insurance Services Names John P. Grotts Managing Director for San Francisco Operations
Advisor News
- What advisors need to know about the life settlement boom
- Report: Many Americans paying up to 45% of annual income on auto loans
- Latest state budget raises taxes on Californians, ignores voter priorities
- What advisors and clients must know about Roth conversions
- Worker retirement confidence dips to lowest level in a decade
More Advisor NewsAnnuity News
- Globe Life Inc. (NYSE: GL) Making Surprising Moves in Tuesday Session
- Why annuities are gaining traction with younger investors
- Best’s Special Report: U.S. Life/Annuity Industry Sees Bottom-Line Growth Despite 18% Decline in Total Income in First-Quarter 2026
- Globe Life Inc. (NYSE: GL) Records 52-Week High Thursday Morning
- Fortitude Re Completes $500 Million FABN Issuance
More Annuity NewsHealth/Employee Benefits News
- While Mainers still reeling from health insurance hikes, insurers propose more
- Change to Florida Medicaid leads to lawsuit. How it could affect kids’ checkups
- Manistee County adopts self-funded health plan
- CALIFORNIA'S BUDGET: MORE SPENDING, HIGHER COSTS FOR TAXPAYERS
- US: Millions Lost Health Insurance When Subsidies Expired
More Health/Employee Benefits NewsLife Insurance News
- Avoid the ‘summertime slump:’ Strategies to remain productive
- Globe Life Inc. (NYSE: GL) Making Surprising Moves in Tuesday Session
- Symetra Partners with PlanSource to Streamline Workforce Benefits Administration
- Royal Neighbors of America achieves record growth
- Only 1 in 4 Americans Think Now Is A Good Time To Invest, Allianz Life Study Finds
More Life Insurance News