Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response...

32
Fission & Fusion with Identity & Security New Opportunities for Advanced Incident Response Joe Gottlieb

Transcript of Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response...

Page 1: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Fission & Fusion with Identity & SecurityNew Opportunities for Advanced Incident Response

Joe Gottlieb

Page 2: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 2Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 2

Page 3: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 3Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 3

Context…

-1+1

=0

+92

=146-2 -8 -18 -32 -21 -9 -2

Page 4: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 4

We are

the

new

attack

vector

Page 5: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 5

Social

Engineering

Page 6: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 6

Phishing

Page 7: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 7

Employee

Negligence

Page 8: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 8

BIG DATA! ANALYTICS! AUTOMATION!

the technology

isn’t ready…

not enough

people…

automate

what?

Page 9: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 9

OVERWHELMED

Page 10: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 10

Lessons Learned

Page 11: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 11Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 11

We enable enterprises to govern

all of their digital identities and access rights,

across all applications and all data,

through the deployment of their choice

Page 12: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 12Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 12

Identity Governance:

continuous management of who has access to what

according to

job roles, life cycle, context and business rules,

with clear paths for workflow, approvals and exceptions

Page 13: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 1313Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

from

outdated and

manual

processes

to

a $1 million

ROI in the

first year

Page 14: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 14Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 14

Identity vs. Security

Why? Reduce Risk

What? Control Access

How? Approval Workflow

Why? Reduce Risk

What? Detect/Block

How? Analytics/Algorithms

Page 15: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 15

Endpoint

Security

Page 16: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 16

Network

Security

Page 17: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 17

Data

Security

Page 18: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 18Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 18

ENDPOINT SECURITY (e.g., ANTI-MALWARE)

NETWORK SECURITY (e.g., FIREWALLS)

DATA SECURITY (e.g., DATA LOSS PREVENTION)

(ALGORITHMIC/PROBABILISTIC)

<EXPERTISE>

Page 19: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 19Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 19

IDENTITIES

ACCOUNTS

ENTITLEMENTS

(DETERMINISTIC)

<APPROVAL MANAGEMENT>

Page 20: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 20Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 20

Identity+ Security

Why? Reduce Risk

What? Identity-defined Security

How?

Page 21: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 21

Three Opportunities

• Situational Awareness via Serialized Identity

• Context Verification via Organizational Hierarchy

• Automation Confidence via Patterned Workflows

Page 22: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 22Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 22

Page 23: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 23Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 23

Page 24: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 24Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 24

SailPoint Actions supported in Splunk Adaptive Response

• Disable or delete a single account on an identity

• Disable or delete all accounts on an identity

• Remove an entitlement from an identity

• Remove all entitlements from a given application on an identity

• Remove all entitlements from all applications on an identity

• Force password reset on all applications for a single identity

• Generate a manager certification for a specific account on an identity

• Generate a manager certification for all accounts belonging to an identity

• Remove entitlement from all identities and make it non-requestable

• Delete or disable all accounts on an application

• Perform an entitlement owner certification on the specified group

• Perform an application owner certification

Page 25: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 25Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 25

Page 26: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 26

Gartner SOAR – simple enough?

Source: Gartner (November 2017)

Page 27: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 27

Gartner SOAR – hmm…

SOA: security operations automation; TVM: threat and vulnerability management

Source: Gartner (November 2017)

Page 28: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 28

Five Questions

• Are my identity and security solutions open enough to integrate?

• Are my identity and security teams open to collaborating?

• Am I ready to iterate in pursuit of automation pattern confidence?

• Can I pursue all of this in the context of risk management?

• Can I advance my board’s confidence in our posture?

Page 29: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 29

We are

the

new

attack

vector

Page 30: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Copyright © SailPoint Technologies, Inc. 2018. All rights reserved. 30

We are

the

necessary

solution

vector

Page 31: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

Thank You

Page 32: Identity is Security - CSO50 Conference · SailPoint Actions supported in Splunk Adaptive Response •Disable or delete a single account on an identity •Disable or delete all accounts

32Copyright © SailPoint Technologies, Inc. 2018. All rights reserved.

Questions?