On November 7, 2022, the national standard "Information Security Technology Critical Information Infrastructure Security Protection Requirements" (GB/T39204-2022) was released. As the basis for the critical information infrastructure security protection standard system, this standard will be officially implemented on May 1, 2023.
This standard proposes three basic principles for the security protection of critical information infrastructure: overall prevention and control with key businesses as the core, dynamic protection oriented by risk management, and collaborative joint defense based on information sharing. focuses on putting forward clear requirements for identity security authentication and authorization:
- should clarify important business operations, important user operations or abnormal user operation behaviors, and form a list;
- should deal with equipment For security management and control of users, services or applications, and data, for important business operations, important user operations, or abnormal user operation behaviors, establish a dynamic identity authentication method, or use multi-factor identity authentication and other methods;
- For operations on important business data resources, access control should be implemented based on technologies such as security tags.
Critical information infrastructure network security protection requirements framework
01 Critical information infrastructure, why is it so important?
The construction of critical information infrastructure is the core of network security protection.
Critical information infrastructure refers to information systems or industrial control systems that provide network information services to the public or support the operation of important industries such as energy, communications, finance, transportation, and public utilities. Once a network security incident occurs in these systems, it will affect the normal operation of important industries and cause serious losses to national politics, economy, science and technology, society, culture, national defense, environment, and people's lives and property.
For enterprises, the core key system within the enterprise is the main system that manages the resources required for the execution of core processes within the enterprise. Such as ERP, SCM, CRM, BPR, OMS, WMS and related control systems, etc. It is crucial to protect the safe and stable operation of these core critical systems. Against the background of normalization of epidemic prevention and control, normalization of remote working, and the obvious trend of enterprises moving to the cloud, protecting core critical systems is becoming more and more risk-based and identity-centric.
Based on the heightened attention to network security in recent years, Authing found that IAM identity and access management technology is the only way for to digitally transform into . It is mainly used to manage digital identities and user access to data, systems and resources within the organization. Through , we can break up the isolation between identity systems and connect isolated business system islands, greatly improving work efficiency and reducing identity-related access risks. The main implementation method for identity authentication and infrastructure in a multi-cloud environment is the IDaaS product based on the cloud native architecture.
02 How to establish a secure computing environment?
security protection is based on the identified key businesses, assets, and security risks, and implements security management and technical protection measures in the security management system, security management organization, security management personnel, secure communication network, secure computing environment, secure construction management, secure operation and maintenance management, etc., to ensure the safe operation of critical information infrastructure.
"Information Security Technology Critical Information Infrastructure Security Protection Requirements" mentions that a secure computing environment must be established, including seven aspects including identification and authorization, intrusion prevention, automation tools, security construction management, security operation and maintenance management, supply chain security protection, and data security protection.
Over the past few years, the identity ecosystem for managing access to enterprise resources has become more complex. The increasing number of identity and phishing attacks has caused enterprise cloud adoption to increase year by year.
According to the Yunxiu Capital survey "Identity Security Management Based on the Cloud Native Era", changes in the overall IT environment have given rise to the need for unified identity management based on cloud native identity security..
- Fundamental changes in IT architecture : With the popularization of mobile Internet, , and IOT devices, a large number of device accesses have expanded the identity trust boundary of enterprises. The traditional separation of internal and external networks and localized IAM solutions can no longer meet current needs.
- enterprise database migrated from IDC to cloud : With the wave of cloud computing, more and more enterprises choose to migrate their entire site to the cloud or 50% of their business to the cloud, resulting in changes in the protection environment.
- Enterprise SaaS service development : The development of enterprise SaaS services such as enterprise network disk, and DingTalk means that more and more enterprise workflows, data flows and identities are external, rather than fixed in the original isolation environment; a large number of SaaS service authentication credentials cannot be unified and effectively managed.
- multi-cloud further deepens , and there is an urgent need to reduce costs and increase efficiency: multi-application, hybrid cloud environment brings heavy management burden to enterprises. Enterprise IT administrators need to maintain each employee's account information between different systems, and perform log auditing and authorization management. When employees use internal AD domain accounts to access external systems, and when external systems need to log in to the internal AD domain through VPN, employees need to maintain a complex account and password system.
In short, as the number of identities managed by enterprises continues to increase, identity security protection has become a top priority . Identity security ensures that the right person accesses the right resource for the right reason at the right time.
CrowdStrike Overwatch research shows that 80% of cybersecurity attacks originate from identity attacks. Modern cybersecurity attacks often bypass traditional cyber kill chain defense models and directly exploit compromised credentials to launch larger cyberattacks. Unfortunately, identity-driven attacks are extremely difficult to detect. When a valid user's credentials are compromised and an attacker masquerades as that user, it is often difficult to distinguish the user's typical behavior from hacker behavior using traditional security measures and tools.
Identity security is an important aspect of Identity and Access Management (IAM) and is the cornerstone of any organization's security.. Gartner states: “The rise in digital business and cybersecurity threats is placing greater demands on IAM systems. Organizations must support a broader range of identity use cases and be able to adapt to new requests and threats more quickly and in near real-time. To address these challenges, organizations must adopt a new perspective on IAM How systems must operate and evolve. A new, dynamic, intelligent architecture augmented with advanced analytics is evolving to meet the needs of modern identity."
Today, enterprise IT departments are increasing their investment in IAM as an important component of the zero trust model to enable important functions such as identity management, authentication and authorization.
As a cloud-based unified identity authentication system, IAM must implement the following four functions:
First, unified user management (Identification) . Tenant account numbers, passwords and other information are stored centrally and managed in a unified manner. Second, identity authentication (Authentication) . When a tenant wants to log in to an application system, verify whether his ticket or identity is legal. Third, authority control (Authorization) . Specify what operating permissions tenants allowed to log into the system have. Fourth, operation log registration (Accountability) . Record the tenant's operating behavior for subsequent responsibility tracing.
In a cloud secure computing environment, permission management and authorization are very important, that is, enterprises need to control users' behavior after logging in based on pre-defined permissions and policy plans, that is, stipulate what he can and cannot do, and prevent the risk of data leakage caused by certain employees being given too many irrelevant permissions or too high permissions, which leads to the spread of permissions. At the same time, it must also emphasize the separation of duties and multi-person control to prevent one employee from having too many permissions, which will lead to criminals attacking one ID and cracking the entire identity system.
In the background management of the application system, several functions are required for identity:
- Identity uniqueness, with automatic deduplication verification
- Mandatory application function for password complexity
- With login failure function
- With remote access encrypted transmission
- With more than two identity authentication methods
03 How does Authing ensure identity security?
Authing provides "high security, high availability, high performance" identity security infrastructure, ensuring corporate identity security through multi-factor authentication, permission management and audit log functions.
(1) Multi-factor authentication MFA
Multi-factor authentication MFA is a very simple security practice that can add another layer of protection in addition to user name and password. After enabling multi-factor authentication, in addition to providing a username and password (first authentication), users also need to perform a second authentication. The combination of multi-factor authentication will provide higher security protection for your account and resources.
MFA creates a multi-layered defense that makes it more difficult for unauthorized persons to gain access to a computer system or network. MFA is verified by 2 or 3 independent credentials. These credentials mainly include the following three elements:
- What you know: the content that the user has currently memorized, the most common such as username and password;
- Items owned: the identity authentication certificate owned by the user, the most common methods are ID card, U Shield , magnetic card, etc.; features of
- : unique biological characteristics of the user, such as the user's fingerprint, iris, etc.
Using MFA has become an essential means for enterprises to prevent data leaks, reduce the risk of security breaches, and ensure data security. In the past, requiring a static username and password to access an account seemed like enough security. However, weak or stolen passwords, when used as a form of unique authentication, can be used to perform fraud attacks, resulting in data breaches. At the 2020 RSA security conference, Microsoft engineers mentioned that 99.9% of compromised accounts tracked by Microsoft each month do not have multi-factor authentication enabled.
Through research on data security supervision and other technologies, Authing has improved its monitoring, discovery and processing capabilities for security risks such as illegal data flows, and uses global MFA to improve overall security. Authing multi-factor authentication empowers Authing applications, instantly improving application authentication and access security levels. **Authing ** can provide a variety of authentication methods including mobile phone tokens, SMS/email verification codes, compatible third-party authenticators, biometrics, graphic locks, mini-program authentication, etc. to improve corporate identity security.
permission management
Authing supports the traditional permission management model of RBAC. At the same time, through OPA as the underlying engine, it supports ABAC's dynamic permission management , including dynamic authorization based on the attributes of the subject and object and the dynamic attributes of the user agent context, and supports strategic authorization capabilities. It also provides developer-friendly API/SDK for quick access to permission data, helping the company achieve efficient, flexible and fine-grained permission management and allocation. Unify the opening and closing of system permissions when employees are transferred in and out, reducing the risk of confidential data leakage.
Specifically, Authing Provide unified permission entrance, unified permission model, unified authorization, permission life cycle automated management, permission compliance analysis, permission portrait and other services to help solve the problems that enterprises currently face in identity permission management, such as difficulty in opening, unification, authorization, tracing, querying, recycling, and supervision. It creates a scientific permissions governance system, integrates bank resources, and makes the permissions of users, applications, devices, servers, operating systems, and APIs manageable, controllable, and visible.
In addition, Authing has just launched an advanced permission management function to help developers control resource access permissions within applications, helping enterprises reduce 80% of data leakage risks: to avoid the problem of R&D personnel deleting libraries and running away, and resigned personnel still retaining key system permissions, strengthen the control of the enterprise's core resources, and protect the security of the enterprise's core data and resource assets.
audit log
audit log can be used to conduct timely audit operations on the system, achieve early warning for sensitive operations such as unauthorized access control, and feedback abnormal situations to the system administrator or relevant users . The audit function provided by Authing strengthens the unified audit of enterprise resources, promotes the refined management of enterprise and , and helps enterprises to efficiently analyze user behavior and data information of the entire business system, identify potential risks in advance, and reduce the risk of malicious attacks inside and outside the enterprise.
is mainly divided into two aspects:
- Operation log of administrator behavior : You can get the behavior of all administrator users through the identity management platform
- Log of user behavior : It can clearly restore the user's behavior in the platform to support the enterprise's compliance management , and it can also be used to trace back and determine responsibility after the incident.
About Authing
Authing is not only a customer supporter, but also a customer's product expert and strategic advisor, and a trustworthy partner. We offer a global team of identity experts, 7*24 hours a day, 24 hours a day, online or by phone. Authing's Help Center provides an up-to-date technical knowledge base, business cases, and opportunities to connect with your peers and Authing experts. No matter when you need us, Authing's support team is always quick to respond.
Currently, Authing Identity Cloud has helped 30,000+ companies and developers build standardized user identity systems. Thanks to Coca-Cola , Yuanqi Forest , PetroChina , Samsung Group , CSDN and other customers for choosing and implementing Authing. Solution