Skip to main content

Heimdall Data

Database user management is complex and often not in regulatory compliance. User credentials can sprawl to the directory, application and database. Managing this requires extensive work. In this blog, we will discuss how the customer used the Heimdall Database PAM solution to fulfill regulatory compliance and federal mandates.

 

Challenge

This federal customer deployed Amazon RDS for Postgres for its ease of managenent and efficient cost per performance compared to commerical databases. There was a federal mandate that required all users to authenticate to the organization’s common active directory. This would unify all authentication and ensure onboarding and offboaring of users would be complete, minimizing data leakage. 

To develop a home grown solution would take too much time and continued mainteance. They explored partners and vendors for an off-the-shelf solution.

 

Solution

The customer choose the Heimdall Database PAM solution to centralize all users to authenticate again the organization’s Active Directory in a Kerberos environment. Not only were the users authenticated, authorization was also acheived which associated user groups to database user roles. Included was a data access approval chain process whereby users, via self-service could request data table access via email and recieve approval from their manager. Access could be time based, all or none.

Integrating with AWS Services

While Amazon RDS provided the managed services for database maintenance, scalability, and availability; the Heimdall Proxy solution allowed the customer get the most out of Amazon RDS without application changes. Addition AWS services added to the overall security solution:

AWS Secret Manager:  Store fixed passwords (such as for service accounts), and allowed upstream applications to both connect to the Heimdall, and Heimdall to connect to back-end services using the stored secrets.  This included the rolling of passwords in conjunction with Amazon RDS, when accounts are configured in Secrets Manager. 
 
AWS Directory Service and Active Directory: Easy management of users in a corporate directory for personal accounts (and service accounts if desired).  This was primarily focused on the users connecting through the Heimdall Proxy, and then using the directory to provide guidance on provisioning the user in a JIT (Just-In-Time) manner on the database, simplifying user management.  This can be done with either Kerberos or LDAP. In this case, Kerberos was implemented.
 
AWS IAM Identity center: Enabled users using the Heimdall PAM to do privilege escalation requests in an SSO type setup, simplifying user access for these advanced features. 
 
Amazon CloudWatch:  Logging of audit trails, the customer for logs and metrics, allowing for alerts to be automated within AWS.

 

Customer Benefit

Fuflilled federal mandate in 2 months, which was lingering for years  

    • Fulfilled regulatory compliance standards (SOC2, SOX)
    • Fulfilled SoD (Segregation of Duties) governance
    • Prevented data leakage from the time a support ticket is submitted to when employee leaves the organization
    • Saved enginerering resources maintaining a database by deploying Amazon RDS for Postgres.

Leave a Reply

Your email address will not be published. Required fields are marked *