VIDEO:
Securing shared user accounts with DUO
CMMC control 3.3.2 (Audit & Accountability) requires that actions be logged and traceable to a specific user. But what to do about shared accounts sometimes used in manufacturing and other specialized environments?
ENC Director of Technology Thomas Kinsinger explains how Duo, Cisco’s 2FA solution, can be used to meet this requirement while enhancing the security of environments uisng shared accounts. Kinsinger is a Registered Practitioner with The Cyber AB, which validates his expertise as a CMMC consultant.
Visit our Learning Center for more CMMC compliance tips, or contact us today to get help with your compliance requirements.
Transcript
Hey, I’m Thomas Kinsinger, director of technology at E-N Computers.
Today we are talking to those who are working to achieve CMMC compliance. What we are looking at today is a product that will help achieve some of the requirements in the control family 3.3 Audit and Accountability.
One of the challenges for many organizations who are looking to become CMMC compliant is the management of shared accounts. Generally, using shared accounts should be avoided. But, particularly in manufacturing, some computers will have a shared user account that runs a program.
The problem arises when multiple people use the program and computer. And CMMC Control 3.3.2 requires that organizations be able to audit logs of access by a specific user or person for each device.
For these situations, Cisco DUO with a YubiKey is a perfect solution. Each MFA key will be associated with a user. This will ensure that each person’s access is logged.
You can have multiple YubiKeys or tokens associated with one shared account using DUO. This will produce a record of each person accessing the shared account in compliance with CMMC requirements.
I hope you have found this helpful. If you would like to schedule a consultation for getting started with DUO or if you would like a quote, please visit our website at encomputers.com and fill out the contact form and someone from our team will be in touch.
Take the IT Maturity Assessment
Is your business ready to weather changes, including employee turnover? Find out by taking our IT maturity assessment.
You’ll get personalized action items that you can use to make improvements right away. Plus, you’ll have the opportunity to book a FREE IT strategy session to get even more insights into your IT needs.
Industries
Locations
Waynesboro, VA
Corporate HQ
215 Fifth St.
Waynesboro, VA 22980
Sales: 540-217-6261
Service: 540-885-3129
Accounting: 540-217-6260
Fax: 703-935-2665
Washington D.C.
1126 11th ST. NW
Suite 603
Washington, DC 20001-4366
Sales: 202-888-2770
Service: 866-692-9082
VA DCJS # 11-6604
Locations
Harrisonburg, VA
45 Newman Ave.
Harrisonburg, VA 22801
Sales: 540-569-3465
Service: 866-692-9082
Richmond, VA
3026A W. Cary St.
Richmond, VA 23221
Sales: 804-729-8835
Service: 866-692-9082