Skip to main content

Risk Register

Risk Register

Risk Register

Below are a list of potential failures that could impact the running of Privilege Secure. The mitigations suggested are approaches to resolve Privilege Secure utilization if the primary failure point is not able to be resolved in a timely manner.

Risk descriptionImpact descriptionMitigation
Hardware failure on appliance node (cluster environment)Failure of hardware within a single node would not directly impact Privilege Secure functionalityPrivilege Secure functionality would not be impacted. Dell support is available
Hardware failure on appliance node (single node environment)Failure of hardware within a single node would impact Privilege Secure functionalityFailover over to DR instance following predetermined procedure.
Load balancer failureUsers unable to access Privilege Secure through load balancer VIPAccess can be obtained by directly connecting to a node. The DNS entry could be re-routed if necessary
DNS failurePrivilege Secure URL would not work and some scans would fail if IP addresses change before resolution of DNSDirect access to Privilege Secure via IP. Privilege Secure would fail to connect to the end points via DNS resolution, but would fall back to the last known IP address
Failure on VM node (cluster environment)Failure of a single VM node would not directly impact Privilege SecurefunctionalityPrivilege Secure functionality would not be impacted.
Failure on VM node (single node environment)Failure of a single VM node would affect Privilege Secure accessUtilize a snapshot or failover to a DR instance. Starting services on a DR instace would take only a few minutes along with a DNS change
Network issue to Privilege SecureAll access to Privilege Secure impactedBreak glass scenario, use a service account if the network outage is unable to be resolved timely. Rotate the credentials of the service account once access is restored
Network issue connecting to end pointNo JITA to the endpointUse OAM. If OAM is not available, check network line of sight to end point using ping of IP address and DNS name
MFA Issue - single userUser is unable to log in to Privilege SecureReset MFA for user
MFA Issue - multiple usersUsers is unable to log in to Privilege SecureEnsure NTP is used across the organization to avoid issues with time token.
MFA not availableMFA failure stopping access to Privilege SecureTurn off SAML and revert to time based token.
LDAP server failureLDAP server referenced by Privilege Secure fails. Users wouldn't be able to access Privilege Secure.Move to different LDAP server and reflatten groups. Contact Privilege Secure support for assistance
LDAP Credential FailureLDAP updates would not be captured by Privilege Secure.Update the credential in Active Directory and update within Privilege Secure. Ensure the account is non-interactive.
Protect Credential FailureJITA would not be able to be obtained for endpointsUpdate the credential in Active Directory and update within Privilege Secure. Ensure the account is non-interactive.
Scan Credential FailureEndpoints would not be able to be scanned and the inventory policy would not be appliedUpdate the credential in Active Directory and update within Privilege Secure. Ensure the account is non-interactive.
Docker failure (single node)Failure of a single node docker instance would affect Privilege Secure accessFailover to a DR instance. Starting services on a DR instace would take only a few minutes along with a DNS change
Docker failure (single node on cluster)Failure of a single node docker instance would causes Privilege Secure to fail on that node.The other nodes would continue to run uninterupted
Service failure APIUsers unable to access Privilege SecureRestart service via command line
Service failure LDAPLDAP updates would not be captured by Privilege Secure.Restart service
Service failure WorkerRescan and JITA would not functionRestart service
Service failure ScanUpdate of policy to end points would not functionRestart service