This is a generic problem for System Management Products, whether it be for monitoring, software distribution identity management and/or backup & recovery.
The best method to mitigate this risk is to implement segregation of duties and strict access control to the FMS.
- Segregate security, developer and operator roles from the FMS users
- Implement Development and Production FMS, with strict release management, i.e. controlled changes from the development FMS into the Production FMS
- Optionally get a security risk qualification (Low, Medium, High) for FMS and have the production FMS audited by the customers security department.
In order to disable the Remote Command Action and prevent possible security breach concerns, the
The ability to run commands remotely was by design, therefore tightly controlling access of the FMS users on the remote system would be the way to go, the Foglight user does not need to be an Administrator.
Disabling the RemoteCommandAction Cartridge would be a possibility however this should not be done unless instructed by Development. This is the only way to ensure that there are no unintended side effects. The ability to run commands remotely was by design, therefore tightly controlling access of the FMS users on the remote system would be the way to go, the Foglight user does not need to be an Administrator.