CyberArk PAM Self-Hosted
CyberArk CorePAS provides Privileged Access Management (PAM) solutions, these are end-to-end solutions that protects, manages and audits both user and application credentials, provides least privilege access and session isolation while recording, monitoring automation and response to all real time privileged activity using intelligent threat analytics.
Features
- Enterprise Password Vault (EPV)
- Secure and tamper proof digital vault with multiple security layers
- Privileged Session Manager (PSM)
- Single-sign-on control point that isolates, records and audits privileged access
- Privileged Threat Analytics (PTA)
- Intelligent real time audit with ability to respond to threats.
Benefits
- Manage Privilege at an Enterprise level through policy driven rules
- Protection all privileged Accounts and SSH Keys
- Control Access to Privileged Accounts
- Initiate and Monitor Privileged Sessions
- Manage application and service credentials
- Comply with audit and regulatory requirements
- Streamlined management of Privileged Accounts
- Seamlessly integrate with enterprise systems
- Detect and respond to known threats such as over-pass-the-hash
- Risk Scoring of privileged use and session behaviour
Pricing
£70.20 a user an hour
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
8 1 2 2 3 1 8 3 3 2 4 0 9 1 5
Contact
CyberIAM Holdings Ltd
Andy Pinnington
Telephone: 08443350012
Email: sales@cyberiam.com
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- N/a
- Cloud deployment model
- Community cloud
- Service constraints
- No
- System requirements
- https://docs.cyberark.com
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- 1-3 hours
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- CyberArk provides direct support - 24x7 support, TAM Services are available at an additional cost.
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Consultancy services and workshops. Entry level introduction training for the Trustee certification is provided for free, further full training both onsite, off site and online is provided at a cost either on site at CyberArk or remotely over the web. See https://training.cyberark.com
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Swagger
- End-of-contract data extraction
- Use the ExportVaultData (EVD) tool
- End-of-contract process
- If your maintenance contract expires while your relevant software licences are still active, the result is a scenario in which your support will be ‘frozen’. While the solution will continue to function as is, you will no longer be eligible for any upgrades or patches to the existing solution. All users within your company will lose Technical Community access and will no longer be able to directly contact Cyberark Support. All active Support cases will be put on hold until outstanding maintenance fees have been settled. Once maintenance is paid, full Support assistance will resume.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Internet Explorer 11
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- The interface development follows the API first principle and all actions available via the GUI can be access and accomplished via the API. Full documentation on the abilities is hosted on https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/WebServices/Implementing%20Privileged%20Account%20Security%20Web%20Services%20.htm?Highlight=REST%20API
- API documentation
- Yes
- API documentation formats
-
- Open API (also known as Swagger)
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Colour and branding changes are possible on the Privilege Vault Web Access (PVWA) interface. Additional customisation around automation and integration is possible, please contact CyberArk for more details
Scaling
- Independence of resources
- CyberArk Architecture and Design services take into account the customer requirements, ensuring that the customer requirements are met for demand. Components are modular and can be scaled out horizontally and with industry standard load balancing technology
Analytics
- Service usage metrics
- Yes
- Metrics types
- N/a
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- CyberArk
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
-
Other - data is encrypted at rest and in transit
CyberArk uses advanced encryption algorithms to protect data at rest. - Data sanitisation process
- Yes
- Data sanitisation type
- Deleted data can’t be directly accessed
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- N/a
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- Other
- Other protection within supplier network
-
Other (CyberArk proprietary VPN protocol)
CyberArk uses advanced encryption algorithms to protect data at rest.
Availability and resilience
- Guaranteed availability
- 99.9
- Approach to resilience
- 0
- Outage reporting
- 0
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Management interface is controlled by RBAC. Support access with CyberArk requires users to be registered and also take have completed training and passed the Defender exam
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- DAS Certification
- ISO/IEC 27001 accreditation date
- 10/05/2021
- What the ISO/IEC 27001 doesn’t cover
- None
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber essentials plus
- No
- Other security certifications
- No
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- CyberArk has the following accreditations: ISO27001 certification, ISO 9001, Common Criteria, NISA Certified, VPAT 508, FIPS 140-2, NIST 800 & uses SOC2 certified Datacentres where relevant.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Available upon request
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- As opposed to other cloud service providers who only provide a service but use 3rd-party technologies, CyberArk developed all the technologies it uses from scratch and only uses standard servers and routers (no 3rd-party technologies). This allows much more flexibility and rapid reaction to new threats and attack vectors as we do not have to wait for updates and patches – we do them ourselves immediately. In order to fight todays sophisticated and constantly changing attack patterns we have CyberArk’s 24x7 SOC - manned with security experts that can handle any attack in real time.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Available on request
- Incident management type
- Supplier-defined controls
- Incident management approach
- We have defined process of incident response and an incident response team whose responsibilities include: Analysis of the security issue risk (based on Severity Matrix and CVSS), remediation and recommendation. SLA of handling the issue according to the risk level. In case the decision is to fix, the fix is like any standard feature\bug development, including validation (QA) and automation. Security bulletin - in case a security issue found risky, and requires patch, we have a mechanism of publishing "security bulleting" to our customers. This bulletin contains explanation of the issue, and mitigation steps (including patch if needed).
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
At CyberIAM, our environmental footprint is significantly smaller than similarly sized organizations due to numerous different factors which are built into our core business processes. We are an entirely paperless business, eliminating our reliance on paper for printing. CyberIAM also utilises a public cloud environment for our IT infrastructure, minimising our environmental impact, as resources are shared across Microsoft’s datacenters. We do not house our own data centres, keeping our carbon footprint small. We are also committed to recycling and re-using IT hardware, which is recycled wherever possible by approved suppliers, to guarantee that the hardware is recycled in the most environmentally friendly way possible. Furthermore, plastics are not used in any CyberIAM offices or for any business processes.Covid-19 recovery
As an organization, CyberIAM responded quickly to the Covid-19 pandemic, enabling our employees to work from home and continue to do so as they wish, allowing for flexibility. This enables CyberIAM to adapt to any COVID-19-related challenges and to provide our services at all times without disruption. CyberIAM regularly holds company meetings and virtual social events which allow everyone to communicate and socialize without risk. Now that staff are permitted to return to offices, there are suggestion boxes for employees to anonymously let us know about anything that would help them carry out their duties safely and comfortably. CyberIAM’s offices also have COVID-19 rapid flow tests, hand sanitisers and temperature monitors available at all timesTackling economic inequality
At CyberIAM we are committed to diversity, inclusion and equality. Our employees hail from all around the globe and are all paid higher than the national average in each territory.Equal opportunity
Our equal opportunities policy is in place to enforce our firm belief in equality for all. Everybody at the company has the same opportunity for training, recruitment and selection. Our jobs are advertised to a diverse audience and our employees come from around the world including the UK, South Africa, Spain, Philippines and Australia. We specify that our initiatives need to include gender representation and typically under supported, disadvantaged groups. Most recently CyberIAM celebrated Eid in April and May 2022. We also offer a women’s support network group for the women in our company of all ages, ethnicities and backgrounds.Wellbeing
Our offices are stocked with fruit, snacks and drinks to support the health and wellbeing of our employees. We also have a social committee who organize and run events for the company, ensuring everybody gets to have fun and socialize if they wish to. We have an open-door policy where people are encouraged to share and resolve any worries they have; we work with our employees to ensure they are happy and comfortable, e.g. flexible working hours to accommodate childcare needs. We work hard for our inclusive and supportive culture where everyone and their views, beliefs and goals are respected.
Pricing
- Price
- £70.20 a user an hour
- Discount for educational organisations
- No
- Free trial available
- No