Effective Management of Shared Account CredentialsRequest, Approve, Issue, and ResetQuest SafeKeeping delivers a powerful solution for the management of shared administrative account credentials. When an administrator needs the administrative credential, SafeKeeping ensures security and manageability by providing a secure, automated mechanism for the request, authorization, release, and change of these administrative account logins.
Administrative passwords—whatever the platform, application, or appliance—present a unique set of management challenges. Because, by their very nature, these credentials tend to be role-based there is a tendency for them to be shared between multiple individual users. This sharing inevitably opens up the potential for mismanagement, abuse, or inefficiency.
Although many organizations have procedural controls and policies governing the use of these credentials, in large highly diverse environments enforcing and monitoring these controls can be a time-consuming exercise. And what about those organizations or individuals who simply cannot or will not follow the procedures and policies?
In many cases organizations are left to simply ignore the risks, and hope nothing bad will ever happen to them. The days of an envelope containing the credentials locked away in the fire safe are simply past. These credentials must be available at the point-of-need—such as when rebuilding mission-critical infrastructure; and at the time-of-need even after hours or on weekends. But security, tracking of activity, and controls must still be in place.
Quest SafeKeeping delivers a powerful solution for the management challenges presented by these shared account credentials. SafeKeeping provides a secure, automated mechanism for the request, authorization, release, and change of shared credentials.
One a shared account is designated as a SafeKeeping-managed account, a password change for administrative credentials on that account is initiated according to an administrator-definable schedule. The new password will be selected in accordance with SafeKeeping’s administrator-defined strong-password policies. The resulting password will not be known to anyone until it is issued following a successfully authorized release request. The product provides a fully-automated, auditable, and secure request-approval-issuance workflow. The following illustrates a typical SafeKeeping workflow:

In addition, all actions performed with or by SafeKeeping are fully audited to ensure control and help satisfy compliance demands.
|