Last June, the Office of Personnel Management revealed a breach that would potentially impact more than 20 million individuals and was expected to have an impact on national security for years to come. The reason? The legacy systems that stored sensitive personal information weren’t capable of the necessary encryption to keep that data safe.
The challenge of legacy systems is gaining recognition with recent IT modernization bills seeking to fund upgrades and GAO testimonies noting the existence of important systems that are decades old. Yet the same types of legacy systems that left OPM vulnerable are still in use at agencies across government and in many cases play very important roles in achieving agency missions.
In an ideal world, agencies could modernize to a more secure infrastructure, but due to budgetary constraints, this is an unrealistic goal. Instead, agencies must seek an approach to security that bridges the gaps left open by outdated IT. One of the most applicable solutions may be starting from the inside with identity and access management (IAM).
The first component of IAM is multifactor authentication — a simple step that likely would have prevented an event like the OPM breach. PIV and CAC card usage was mandated more than a decade ago by Homeland Security Presidential Directive 12 (HSPD-12)and again highlighted in 2015 as a part of Tony Scott’s cybersecurity sprint. Multifactor authentication helps to overcome the insecurity of passwords by adding physical, biometric or other difficult to replicate components to the equation.
Unfortunately, legacy IT introduces a challenge here, with many applications unable to enable smartcard access. Enterprise single sign-on solutions can help agencies address this gap, better managing identities by storing credentials when physical cards are incompatible. By adopting security solutions that integrate with existing IT infrastructure, government can provide a solid defense against evolving security threats and reduce risk without a system overhaul.
Going a step further, agencies also should implement extra precautions with privileged accounts. Privileged accounts have access to a wealth of sensitive data that users may rarely or never need. Taking a least-privileged approach to these accounts can help mitigate this issue, providing access only to the information users need. For particularly sensitive information, privileged users should be granted temporary access limiting the information they can see, time during which they can see it and actions they can take on the system. This access should be fully auditable and tracked, to identify misuse and, in turn, mitigate potential damage.
These steps play an important role in protecting information, but there is a human factor involved as well. Agencies need to ease the burden on the user, with a recent report from NISTfinding that overwhelmed users tend to act recklessly and put their organizations at risk. A context-aware approach can perform real-time evaluation of the who, what, where, when and why of a user’s requests to determine legitimacy. With this in mind, users with a benign request at a predictable time and from an expected location will be permitted access without additional layers of security, making it easy for the user to do their job. When requests don’t follow typical patterns — perhaps a request is made from a foreign country when the user is expected to be at home — the request can be flagged and authentication requirements heightened.
By implementing security solutions that manage the user and the data they can access, agency doors aren’t open to theft just because they couldn’t install a lock on the front gate. While upgrading legacy technologies offers great benefits from a security standpoint, agencies don’t need to see aging systems as a barrier to a secure environment. By focusing on securing agency users and data, even yesterday’s technologies can be protected against the next big breach.
Andy Vallila leads Americas Sales and Marketing for One Identity, the security business under Quest Software. In this role, he is responsible for overseeing the go-to market functions for the robust One Identity portfolio of modular and integrated Identity and Access Management (IAM) solutions. Previously a part of Dell, Andy has served in a similar role since late in 2014, formerly leading security-focused sales teams at two industry-leading corporations.




