Database user management is complex and often not in regulatory compliance. User credentials can sprawl to the directory, application and database. Managing this requires extensive work. In this blog, we will discuss how the customer used the Heimdall Database PAM solution to fulfill regulatory compliance and federal mandates.
Challenge
This federal customer deployed Amazon RDS for Postgres for its ease of managenent and efficient cost per performance compared to commerical databases. There was a federal mandate that required all users to authenticate to the organization’s common active directory. This would unify all authentication and ensure onboarding and offboaring of users would be complete, minimizing data leakage.
To develop a home grown solution would take too much time and continued mainteance. They explored partners and vendors for an off-the-shelf solution.
Solution
The customer choose the Heimdall Database PAM solution to centralize all users to authenticate again the organization’s Active Directory in a Kerberos environment. Not only were the users authenticated, authorization was also acheived which associated user groups to database user roles. Included was a data access approval chain process whereby users, via self-service could request data table access via email and recieve approval from their manager. Access could be time based, all or none.
Integrating with AWS Services
While Amazon RDS provided the managed services for database maintenance, scalability, and availability; the Heimdall Proxy solution allowed the customer get the most out of Amazon RDS without application changes. Addition AWS services added to the overall security solution:
Customer Benefit
Fuflilled federal mandate in 2 months, which was lingering for years
-
- Fulfilled regulatory compliance standards (SOC2, SOX)
- Fulfilled SoD (Segregation of Duties) governance
- Prevented data leakage from the time a support ticket is submitted to when employee leaves the organization
- Saved enginerering resources maintaining a database by deploying Amazon RDS for Postgres.
