HOT Password Manager

HOT Password Manager (HPM v1.21) - A tool that randomly generates Cryptographically Strong Passwords, applies to OS Users, DB Users, Tasks, Services, others, Encrypts & Stores it for future use and maintains Audit Trail of all the activities performed using this tool. It can be used as:

  • IT Automation Tool (Automates the SysAdmin/DBA activities)
  • Security Tool (Enhances Data Security)
  • A Compliance Tool (Compliance with Password Policies, ISO/PCI-DSS/NIST Standards
  • An Audit Tool / Change Management Tool (Makes Password Change activity Auditable)

Click here for Flow of HPM Application and Sample at each step


Features of HPM

Automation

  • Automates Password changing activity (in OS, in Task Scheduler and in Service Manager)
  • Single Screen / Interface / Click to change passwords (Easily Addresses all activities related to Password Change at once)
  • Can be customized:
    • To change passwords of all Tasks & Services owned by User
    • To change hard-coded passwords in Filesystems, Applications, DBs, etc.
    • To take feed of New password from existing Password Vault, if one exists,
    • To generate the passwords in line with Password Standard of the organization
  • Reduces manual work and hence reduces errors
  • Improves IT Productivity
  • Need not keep extended expiry period for Service Accounts
  • Apply same Password Policy for all User IDs
  • Reduces downtime
  • Reduces no. of Policy Deviations / Exceptions
  • Tune to Policies of the organization and to the Regulations they follow

Auditing

  • Generates Audit Trail of each and every Password Change action
  • Use the logs as Audit evidence of password change activity
  • Can be integrated with SIEM

Data Security

  • Generates Cryptographically Strong and Complex passwords
  • Generates Random Passwords
  • Passwords are stored in password protected + encrypted Repository (uses 256-bit Advanced Encryption Standard [AES] / Rijndael algorithm)
  • Stored Passwords can be easily retrieved (using Repository password)
  • Possible to have dual custody of passwords
  • Shows generated / stored passwords for very short period
  • Makes Password Breaking most difficult
  • Makes Password Guessing most difficult
  • Passwords are kept safe & secure
  • No need to remember / note down passwords
  • Segrregation of Duties & Accountability
  • Safeguards password from unauthorized disclosure and misuse

Compliance

  • Generates Audit Trail of each and every Password Change action
  • Use the logs as Audit evidence of password change activity
  • Can be integrated with SIEM

Governance

  • Generates Audit Trail of each and every Password Change action
  • Use the logs as Audit evidence of password change activity
  • Can be integrated with SIEM