Privileged Account and Session Management is the same as Privileged Access Management (PAM). It specifically includes shared account and password management, and privileged session management. It can also include Application-to-Application Password Management (AAPM).
Discovering, monitoring, and managing privileged accounts is a vital part of maintaining a strong security posture. To meet these demands, many organizations look to PASM solutions. These tools are a subclass of privileged access management tools and provide protection by vaulting account credentials and enabling full session recording at the vault/gateway level. In their most sophisticated manner of use, the solutions broker access for users, services, and applications.
According to Gartner (Magic Quadrant for Privileged Access Management, August 2020):
“Privileged Session Management (PSM) functions establish sessions with possible credential injection, and full session recording. Passwords and other credentials for privileged accounts are actively managed, such as being changed at definable intervals or upon occurrence of specific events. PASM solutions can optionally also provide application-to-application password management (AAPM), and/or zero-install remote privileged access features for IT staff and third parties that do not require a VPN.”
Privileged credentials are worth their weight in gold for cybercriminals—they offer the potential for persistent network access and data theft.
It is not uncommon for threat actors to use administrator-level permissions to deepen their compromise by spreading to systems throughout the network and even creating user accounts to help them go undetected for an extended period. Insider attacks are also a threat to organizations. Without the ability to monitor and manage privileged accounts, any malicious activity may go undetected.
These capabilities are also critical for supporting compliance efforts. Government regulations and industry standards such as the Health Insurance Portability and Accountability Act (HIPAA) and the Payment Card Industry Data Security Standard (PCI DSS) require the ability to audit the activity of privileged accounts.
While some organizations may want to manage passwords for privileged accounts manually, that approach does not scale as businesses grow. It also does not deliver the audit trail organizations need to pass a compliance audit.
Though different vendors may offer different capabilities, some key elements of a PASM solution include:
In addition, PASM solutions might provide the following additional capabilities:
Modern Privileged Account and Session Management solutions are characterized by being delivered as a cloud-architected, highly scalable offering to meet the increasing needs of the digitally transformed enterprise. By offering PASM-as-a-Service, these cloud-ready solutions can be up and running in under an hour. In turn, customers avoid a complicated and protracted IT project along with the hassles of designing a complex PAM architecture with failover and disaster recovery and acquiring and building out the infrastructure.
Ultimately, Privileged Account and Session Management solutions help organizations reduce the number of privileged accounts. However, it does not reduce the risk associated with users or machines having too much privilege. That objective is achieved by adding privilege elevation and delegation management (PEDM) capabilities to the equation.
More PASM Resources:
eBooks
Privileged Access Management for Dummies
Free Tools
Privileged Access Management Checklist
Free Privileged Access Security Toolkit