Table of contents exchange of letters with the minister executive summary


Server local administrator accounts must be centrally managed



Download 5.91 Mb.
View original pdf
Page249/329
Date27.11.2023
Size5.91 Mb.
#62728
1   ...   245   246   247   248   249   250   251   252   ...   329
Report of the COI into the Cyber Attack on SingHealth 10 Jan 2019
40.5 Server local administrator accounts must be centrally managed
across the IT network
893. A server local administrator account has access to every file and application on the server. If an attacker can get a foothold in a system, it often looks for this privileged local administrator account as part of its attack roadmap. It will then use these accounts as it starts moving laterally across the network.
894. In short, that attacker guesses or acquires the local administrator’s account password, grabs the hashes of domain-level users with password dumping tools, and then moves around the network.




COI Report – Part VII
Page 307 of 425

40.5.1
Establish clear policies in relation to the use and management of
server local administrator accounts
895. Server local administrator accounts area security problem because one set of login credentials is typically used by many IT administrators. This can make it difficult or even impossible to implement an identity-based access management policy because the specific person gaining access to a server cannot be tracked at any given time.
896. The password for the LA. account was compromised, with the same account and the same password being used across all Citrix servers. Such local privileged accounts must not be configured with the same credentials across systems. The use of the same local admin password on every server helped the attacker to move laterally within the network. One server ‘taken-over’ meant that all of them were owned by the attacker. Since the local administrator account can control everything that can be performed on a server, if the single password is compromised on any server, all systems are susceptible to compromise.
897. We note that HITSPS makes no express reference to account management or password policies specific to the management of local administrator accounts
(e.g. there is no policy that the same password cannot be used to local administrator accounts across multiple servers.
898. Specific policies addressing server local administrator passwords must be formulated, with the necessary tools put in place to enforce and ensure compliance with these policies. Examples of such policies include a) Change Default Usernames and Passwords - change all default usernames and passwords for local admin accounts These policies are drawn from the CIS Controls Version 7.



Download 5.91 Mb.

Share with your friends:
1   ...   245   246   247   248   249   250   251   252   ...   329




The database is protected by copyright ©ininet.org 2024
send message

    Main page