COI Report – Part VII
Page
309 of
425 901. As
a more comprehensive solution, it is recommended that a solution such as an enterprise Password Vault should be implemented. Broadly speaking, this would prevent unauthorised users from accessing privileged account credentials, and still ensure that authorised users have the necessary access for legitimate purposes. A Password Vault serves to protect all privileged account passwords in a secure central repository to prevent the theft or unauthorised sharing of these credentials. Administrators will checkout server local administrator credentials each time access using such an account is required. Further, such a system would ensure that the credentials checked out would meet password length
and complexity requirements, be constantly changed, and be unique to each server.
902. Implementing such a solution would significantly reduce the risk of weak passwords leading to the compromise of local administrator accounts, and would slowdown lateral movement in
a network if a breach happens, as it would require each server to be compromised separately.
903. IHiS has in fact implemented a Password Vault solution in the wake of the Cyber Attack. As testified to by Woon Lan and Leong Seng, IHiS has procured a software to manage all local administrator accounts. This ensures that
IHiS is no longer reliant on the administrators to change the passwords themselves – the Password Vault mandates that it is constantly changed.
Share with your friends: