Privileged access is essential to configure, operate, and maintain IT applications and infrastructure because it enables capabilities and data access that normal users cannot obtain. Systems commonly include built-in privileged accounts to enable this elevated access, but these accounts and their usage must be tightly managed. Privileged access is no longer limited to IT administrators: business users and non-employees may also receive elevated access to sensitive assets such as HR records, payroll, financial information, intellectual property, and social media accounts. Digital transformation has expanded the privileged user population further, driven by cloud service delivery models and practices such as DevOps that require privileged capabilities.
Because privileged access can be abused with high impact, organizations must ensure trust through controls that address malicious abuse, unauthorized misuse (including privacy violations), and harmful mistakes. Privileged accounts are prime targets for cyber-adversaries because they can enable system takeover and unrestricted data access. Core controls include applying the Principle of Least Privilege, avoiding shared privileged accounts (or mitigating them via password vaulting), enforcing segregation of duties, using strong authentication, and continuously monitoring privileged activity to detect and respond to anomalies.
Symantec Privileged Access Management (PAM), now marketed by Broadcom following its acquisitions of CA Technologies (2018) and Symantec (2019), is presented as a mature PAM suite with roots going back to 1996 and additional capabilities via the Xceedium acquisition (2015). It provides credential vaulting, session recording, threat analytics with machine learning, host-based server control, and application-to-application password management to secure both human and non-human privileged actors across physical, virtual, and cloud environments. The platform emphasizes lifecycle governance, shared account controls, just-in-time provisioning integrations, fine-grained OS-level command control, and behavioral analytics, while noting challenges around DevOps maturity and potential acquisition-related continuity risks.
See All Locations
See All Locations