Solution

Audit and compliance

Answer access questions from one record instead of six admin consoles, and export the evidence.

The problem

Access questions arrive with a deadline attached. An auditor asks who could reach a system in a particular month; a customer questionnaire asks how access is granted and removed; an incident asks who signed in and from where.

Answering from six admin consoles takes days and produces an answer you cannot really stand behind. The evidence either exists centrally or it is reconstructed, and reconstructed evidence is what fails a review.

What Besecure does about it

One record, not six

Sign-ins and administrative changes are written to a single audit log across every application published through Besecure, so an access question has one place to be answered from.

Reports you can hand over

Activity can be exported, so the answer to an auditor or a customer questionnaire is a document rather than a screenshot of an admin screen.

Controls you can point at

Sign-in can be restricted by IP address and by geography, alongside multi-factor authentication and a password policy set for your organisation — each of them a control you can demonstrate rather than describe.

Two of the Essential Eight

The ACSC Essential Eight names multi-factor authentication and restricting administrative privileges among its eight mitigation strategies. Besecure contributes directly to both. It does not address the other six — patching, application control, macro settings, application hardening and backups are someone else's job, and any vendor claiming otherwise is overselling.

Questions this usually raises

Does Besecure make us Essential Eight compliant?

No, and be wary of anything that says it does. The Essential Eight has eight mitigation strategies across three maturity levels. Besecure contributes to two of them — multi-factor authentication, and restricting administrative privileges through role-based access. The remaining six are about patching, application control, Office macros, user application hardening and backups, none of which an identity product touches.

What exactly is recorded?

Sign-ins and administrative changes, centrally, across the applications published through Besecure. Directory synchronisation runs are recorded separately with their status and record counts.

Can we get the data out?

Yes. Reports are exportable, so evidence can be attached to an audit response rather than described in one.

One sign-in for every app your team uses.

Set up your organisation, connect your directory and give your people a single secure launchpad.