Implementing Privileged Access Management with CyberArk
Overview
Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, credential rotation policies, and integration with NIST 800-53 access control requirements.
Objectives
- Design CyberArk vault architecture with high availability
- Implement automated privileged credential discovery and onboarding
- Configure credential rotation policies for different account types
- Deploy Privileged Session Manager (PSM) for session isolation and recording
- Integrate CyberArk with SIEM for privileged access monitoring
- Implement just-in-time (JIT) privileged access workflows
Key Concepts
CyberArk Architecture Components
- Digital Vault: Encrypted credential storage with FIPS 140-2 validated encryption
- Central Policy Manager (CPM): Automated password rotation and verification
- Privileged Session Manager (PSM): Session isolation, recording, and keystroke logging
- Password Vault Web Access (PVWA): Web interface for credential management
- Privileged Threat Analytics (PTA): Behavioral analytics for privileged accounts
- Conjur Secrets Manager: Application identity and secrets management
Vault Security Model
- Master Policy: Global security settings (dual control, exclusive access, one-time passwords)
- Safes: Logical containers for credentials with granular permissions
- Platforms: Configuration profiles defining rotation, verification, and reconciliation
- Account Groups: Link accounts sharing rotation dependencies
Credential Lifecycle
- Discovery: Scan infrastructure for privileged accounts
- Onboarding: Import accounts into vault with platform assignment
- Rotation: Automated password changes per policy schedule
- Verification: Periodic validation that vaulted credentials work
- Reconciliation: Re-sync credentials when vault and target are out of sync
- Decommissioning: Remove accounts no longer needed
Implementation Steps
Step 1: Vault Architecture Design
- Deploy primary vault server in secured network segment
- Configure vault high availability with DR vault
- Harden vault server OS (remove unnecessary services, disable RDP)
- Configure firewall rules (only port 1858 from authorized components)
- Set up vault backup with encryption
Step 2: Safe and Policy Configuration
- Create safe hierarchy aligned with business units
- Define safe members with least-privilege roles:
- Safe Admins: manage safe membership
- Credential Managers: add/modify accounts
- Auditors: view audit logs only
- Users: retrieve/use credentials
- Configure Master Policy settings:
- Require dual control for credential retrieval
- Enable exclusive access (one user per credential at a time)
- Set one-time password mode for sensitive accounts
Step 3: Platform Configuration
- Windows Domain Admin: Rotate every 24 hours, verify every 4 hours
- Linux Root: Rotate every 72 hours with SSH key rotation
- Database Admin (Oracle, SQL Server): Rotate every 24 hours
- Network Devices: Rotate every 7 days
- Service Accounts: Rotate on schedule with dependency management
- Cloud IAM Keys: Rotate every 90 days with dual-key strategy
Step 4: Privileged Session Management
- Deploy PSM servers behind load balancer
- Configure session recording (video, keystroke, command logs)
- Set up session isolation (users connect through PSM, never directly)
- Define connection components for RDP, SSH, databases, web apps
- Configure live session monitoring and termination capabilities
- Set session recording retention (minimum 1 year for compliance)
Step 5: Integration and Monitoring
- Forward CyberArk audit logs to SIEM (CEF/Syslog format)
- Configure PTA for behavioral analytics:
- Detect credential theft indicators
- Alert on suspicious privileged session activity
- Monitor unmanaged privileged account usage
- Integrate with ticketing system for access request workflows
- Set up alerts for failed rotation, verification failures, policy violations
Security Controls
| Control |
NIST 800-53 |
Description |
| Privileged Access |
AC-6(7) |
Privileged account controls |
| Credential Management |
IA-5 |
Automated credential rotation |
| Session Recording |
AU-14 |
Session audit capability |
| Access Enforcement |
AC-3 |
Vault-enforced access policies |
| Separation of Duties |
AC-5 |
Dual control for sensitive operations |
Common Pitfalls
- Not configuring reconciliation accounts leading to lockouts after rotation
- Setting rotation schedules too aggressive for service accounts with dependencies
- Failing to test PSM connection components before production deployment
- Not establishing break-glass procedures for vault unavailability
- Overlooking network device credential management
Verification
1---2name: implementing-privileged-access-management-with-cyberark3description: Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, c4license: Apache-2.05---6# Implementing Privileged Access Management with CyberArk78## Overview9Deploy CyberArk Privileged Access Management to discover, vault, rotate, and monitor privileged credentials across enterprise infrastructure. This skill covers vault architecture, session isolation, credential rotation policies, and integration with NIST 800-53 access control requirements.1011## Objectives12- Design CyberArk vault architecture with high availability13- Implement automated privileged credential discovery and onboarding14- Configure credential rotation policies for different account types15- Deploy Privileged Session Manager (PSM) for session isolation and recording16- Integrate CyberArk with SIEM for privileged access monitoring17- Implement just-in-time (JIT) privileged access workflows1819## Key Concepts2021### CyberArk Architecture Components221. **Digital Vault**: Encrypted credential storage with FIPS 140-2 validated encryption232. **Central Policy Manager (CPM)**: Automated password rotation and verification243. **Privileged Session Manager (PSM)**: Session isolation, recording, and keystroke logging254. **Password Vault Web Access (PVWA)**: Web interface for credential management265. **Privileged Threat Analytics (PTA)**: Behavioral analytics for privileged accounts276. **Conjur Secrets Manager**: Application identity and secrets management2829### Vault Security Model30- **Master Policy**: Global security settings (dual control, exclusive access, one-time passwords)31- **Safes**: Logical containers for credentials with granular permissions32- **Platforms**: Configuration profiles defining rotation, verification, and reconciliation33- **Account Groups**: Link accounts sharing rotation dependencies3435### Credential Lifecycle361. **Discovery**: Scan infrastructure for privileged accounts372. **Onboarding**: Import accounts into vault with platform assignment383. **Rotation**: Automated password changes per policy schedule394. **Verification**: Periodic validation that vaulted credentials work405. **Reconciliation**: Re-sync credentials when vault and target are out of sync416. **Decommissioning**: Remove accounts no longer needed4243## Implementation Steps4445### Step 1: Vault Architecture Design461. Deploy primary vault server in secured network segment472. Configure vault high availability with DR vault483. Harden vault server OS (remove unnecessary services, disable RDP)494. Configure firewall rules (only port 1858 from authorized components)505. Set up vault backup with encryption5152### Step 2: Safe and Policy Configuration531. Create safe hierarchy aligned with business units542. Define safe members with least-privilege roles:55 - Safe Admins: manage safe membership56 - Credential Managers: add/modify accounts57 - Auditors: view audit logs only58 - Users: retrieve/use credentials593. Configure Master Policy settings:60 - Require dual control for credential retrieval61 - Enable exclusive access (one user per credential at a time)62 - Set one-time password mode for sensitive accounts6364### Step 3: Platform Configuration65- Windows Domain Admin: Rotate every 24 hours, verify every 4 hours66- Linux Root: Rotate every 72 hours with SSH key rotation67- Database Admin (Oracle, SQL Server): Rotate every 24 hours68- Network Devices: Rotate every 7 days69- Service Accounts: Rotate on schedule with dependency management70- Cloud IAM Keys: Rotate every 90 days with dual-key strategy7172### Step 4: Privileged Session Management731. Deploy PSM servers behind load balancer742. Configure session recording (video, keystroke, command logs)753. Set up session isolation (users connect through PSM, never directly)764. Define connection components for RDP, SSH, databases, web apps775. Configure live session monitoring and termination capabilities786. Set session recording retention (minimum 1 year for compliance)7980### Step 5: Integration and Monitoring811. Forward CyberArk audit logs to SIEM (CEF/Syslog format)822. Configure PTA for behavioral analytics:83 - Detect credential theft indicators84 - Alert on suspicious privileged session activity85 - Monitor unmanaged privileged account usage863. Integrate with ticketing system for access request workflows874. Set up alerts for failed rotation, verification failures, policy violations8889## Security Controls90| Control | NIST 800-53 | Description |91|---------|-------------|-------------|92| Privileged Access | AC-6(7) | Privileged account controls |93| Credential Management | IA-5 | Automated credential rotation |94| Session Recording | AU-14 | Session audit capability |95| Access Enforcement | AC-3 | Vault-enforced access policies |96| Separation of Duties | AC-5 | Dual control for sensitive operations |9798## Common Pitfalls99- Not configuring reconciliation accounts leading to lockouts after rotation100- Setting rotation schedules too aggressive for service accounts with dependencies101- Failing to test PSM connection components before production deployment102- Not establishing break-glass procedures for vault unavailability103- Overlooking network device credential management104105## Verification106- [ ] Vault accessible only from authorized components107- [ ] Credential rotation succeeds for all onboarded accounts108- [ ] PSM sessions recorded and searchable109- [ ] Dual control enforced for sensitive credential checkout110- [ ] SIEM receives CyberArk audit events111- [ ] Break-glass procedure tested and documented112- [ ] DR vault failover tested successfully