Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • FISMA 2016... The Best of Times, the Worst of Times current page
Link copied

FISMA 2016... The Best of Times, the Worst of Times

Mar 21, 2017
Author:
Slang
Scott Lang
Sr. Director, Product Marketing at BeyondTrust
Blog banner default
FISMA 2016... The Best of Times, the Worst of Times
Slang
Scott Lang
Sr. Director, Product Marketing at BeyondTrust

FISMA 2016

Depending on the news outlet you visit the 2016 FISMA report could signal the cyber apocalypse, with huge cybersecurity gaps and 16 major cyber incidents in the year. Or, it could be sunny skies with twice as many agencies meeting goals than in the year prior and considerable progress in increasing the cyber workforce. Whether optimistic or pessimistic in your view, the fact remains that nearly 50% of federal agencies reviewed didn’t make the grade; there were just short of 31,000 cyber incidents across thousands of aging IT systems. Federal IT is a complex risky environment that has some distance to go to be secure.

Privilege Abuse & Misuse was at the Center of Many Cyber Incidents

4,130 cyber incidents were the result of improper usage, the “violation of an organization’s acceptable usage policies by an authorized user”. Of the 16 major incidents, 11 involved employee improper usage and exfiltration of large amounts of highly sensitive data. We have two words for this problem... Least Privilege.

Called out in the Access Control Family of NIST SP800-53, and as part of the Protect functional area of the NIST Cybersecurity Framework, the principle of least privilege is based on mitigating risk from insider threats by limiting access to the lowest level user rights still allowing employees to do their jobs. This limits exposure of sensitive information or inappropriate access to privileges that would allow unauthorized changes within the information system.

Steps to Balancing Security and Productivity

Some are resistant to implementing least privilege for a variety of reasons, but often it is to avoid slowing down the business at hand, or to avoid overburdening an already stretched IT team. But, folks, if you were one of those agencies reporting the 16 major incidents, I’ll guarantee that’s far more inconvenient than an occasional call about user access. Here are a few steps to take to mitigate the majority of incidents described in the FISMA report:

  • To support efficiencies, grant privileges to applications and tasks, not users. This means the user is never granted administrator credentials but has access to the applications needed.
  • To gain a full picture of privilege activity, analyze privilege password, user and account behavior. This is the key to uncovering emerging privilege escalation threats, pinpointing and reporting on at risk systems, then actively removing the threat. Least privilege doesn’t just mitigate insider threats; it also prevents lateral movement within a system should a breach occur.

Don’t be one of the over 30,000 incidents reported in the next FISMA report. Check out these great resources to start on the path to locking down your agency privileges today.

[Blog] What Is Least Privilege & Why Do You Need It?

When your agency is ready to explore options to mitigate Federal data breach risks, contact us for a strategy session. BeyondTrust has the experience and solutions to help.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Implementing User Account Control (UAC) Best Practices with Endpoint Privilege Management
    Dec 1, 2022 Implementing User Account Control (UAC) Best Practices with Endpoint Privilege Management
    Blog
    1m
  • UK Parliament Cyber Attack - Potential Ramifications
    Jun 26, 2017 UK Parliament Cyber Attack - Potential Ramifications
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.