Educause Security Discussion mailing list archives

Re: Restricting PC Admin Rights


From: randy <marchany () VT EDU>
Date: Mon, 13 Aug 2018 18:44:09 -0400

Interesting thread. I have a couple of questions:

1. What is the problem we're trying to solve?
    a. Seems to me the problem isn't a user having admin rights, rather,
it's a poorly trained user with admin privs that' the problem. So, why not
create a training program for people who want admin privs? Seems to me
that's a win-win. We get an extra set of eyes to help spot problems, users
get the flexibility they want/need. I saw an earlier post saying you need a
highly responsive support infrastructure to *help users do their job*. If
your IT staff can't handle immediate requests for users, then we get in the
way of their job.
    b. What about BYOD? I'm sure most of us are heavily into BYOD which
means those users already have admin privs. Which brings me back to
training.

2. Are there metrics showing the ratio of breaches caused by misuse of
admin privs vs other vectors? Whether a user has admin privs isn't going to
affect their files being hit by a ransomware attack.

Just curious.....
-Randy Marchany
VA Tech IT Security Office and Lab

Current thread: