Info Security Memo
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org

Build Confidence

Focusing on Information Security 

Info Security Notes

Thycotic Secret Server Best Practice

10/2/2021

0 Comments

 
Thycotic Secret Server Best Practice

 






Secret Rotation

Secret template - Password requirements

STANDARD SECURITY                        Setting

Is Default                                            True

Prevent Username in Password        True

Length between (x) and (x)               12 & 12

Using Characterset                            Default

Minimum 1 Uppercase                       (A-Z)

Minimum 1 Lower Case                     (a-z)

Minimum of 1 Symbol

Require Exclusive Account Usage

 

HIGH SECURITY                                       Setting

Is Default                                            False

Prevent Username in Password        True

Length between (x) and (x)               20 & 20

Using Character set                            Default

Minimum 1 Uppercase                       (A-Z)

Minimum 1 Lower Case                     (a-z)

Minimum of 1 Numeric                     (0-9)

Minimum of 1 Symbol

Require Exclusive Account Usage

Require Comment & (Change or Incident Ticket)


After you created a new Secrete Template, assign a password requirement to it.


Secret Rotation


Standard Security        Rotate every 90 days

High Security               Rotate every 30 days

Custom Security          Rotate when checking in


Create a secret policy for different situation's combination. Auto Change schedule after expiration can be set in the secret policy.


High security - auto change with heartbeat - 90 days
Standard security - auto change with heartbeat - 30 days
Low security - no auto change - no heartbeat 

Launchers

PowerShell
MS SQL Server
SecureCRT
Puty
RDP
WinSCP
Web Password Filler
Web Launcher






Folders


Standardization Example
Example1:
Company Name - Department Name - Location - Device Types / Account Types



This design (above) is useful when utilizing Distributed Engines with Sites that are different physical locations within your environment and you explicitly want to align a Secret Policy with a specific Site. You have a couple of different locations (Dorval and Wynford), by enforcing or by defaulting the “Site” selection for Secrets to a specific physical location and then aligning that Site specific folder to that Secret Policy, you can ensure that when secrets are created under that specific physical location, you ensure that those secrets will utilize the correct Distributed Engine for that location. For accounts/secrets where it does not make sense to organize them based on any particular “Site” we often suggest creating a “Non-Site Specific” folder that exists on the same sub-folder level as your other sites.

Folder permissions for this type of folder structure will typically have a Secret Server application specific Administrators group as the owner of the top-level folder. Other departments should require “view” only permissions for this top-level folder. For your departmental folders, they may or may not also include the Secret Server application specific Administrators group as owner. Typically, during initial deployment, we see Secret Server Administrators as owners for departmental folders to assist the department with getting everything setup. Alternatively, they may only contain the departmental specific groups with Owner permission. For very large departments, we recommend having multiple groups for each department. One group may be a departmental administrator’s group and another may be a departmental members group. With this kind of group configuration, the departmental administrators group can have “Owner” permissions over the departmental folder and all subfolders. Then the departmental members group can have either “Edit” or “View” permissions for the departmental folder and all subfolders. At the site or device type level of subfolders, this is where you might consider breaking inheritance to allow “Owner” permissions for the departmental member group.


Other Examples:

Secret Server is very flexible and can accommodate many different organization styles.  Below are some other folder organizational examples and ideas for a smaller folder structure footprint

1. Department > Device/Account Types

2. Location > Device/Account Types

3. Device/Account Types 


Restricted Secrets


Shared Secrets



Unlimited Administration Mode







































via Blogger http://blog.51sec.org/2021/10/thycotic-secret-server-best-practice.html
October 02, 2021 at 08:37PM Thycotic
0 Comments



Leave a Reply.

    Categories

    All
    Architecture
    Blog
    Checkpoint
    Cisco
    Cloud
    CyberArk
    F5
    Fortigate
    Guardium
    Juniper
    Linux
    Network
    Others
    Palo Alto
    Qualys
    Raspberry Pi
    Security
    SIEM
    Software
    Vmware
    VPN
    Wireless

    Archives

    March 2024
    February 2024
    January 2024
    December 2023
    November 2023
    October 2023
    September 2023
    August 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    February 2023
    January 2023
    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    October 2019
    September 2019
    June 2019
    July 2018
    May 2018
    December 2017
    August 2017
    April 2017
    March 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015

    Print Page:

    RSS Feed

    Email Subscribe
Powered by Create your own unique website with customizable templates.
  • Blog
  • Sitemap
    • Categories
  • Contact
  • About
  • Resources
  • Tools
  • 51sec.org