THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Monday, January 03, 2022
A company's IAM architecture should be a top priority, mainly if it uses cloud computing or cloud services.
Fremont, CA: Cloud services have progressively expanded in popularity across all industries over the years. Then came COVID-19, which pushed firms to use cloud services sooner than expected. Along with cloud architecture, new and developing dangers have emerged, and the best method to deal with risk vectors is to use Identity and Access Management (IAM).
Improving Identity Access Management in cloud computing
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
The same best practices apply to IAM for cloud computing as they do to any other identity access management protocol. Three key concepts, however, are essential for cloud security. These are some of them:
• Control over the security of user credentials and the frequency with which they are changed.
• Beyond vulnerable passwords, the requirements for multi-factor authentication
• All user access sessions, including approved and privileged users, are subject to restrictions.
User Credentials: Optimal Strength and Lifespan
User credential management is a critical component of a successful IAM implementation. Usernames and passwords (or passes) that provide access to sensitive data must meet minimum length and complexity standards to be considered strong. Passwords, for example, should have at least eight characters and include at least one unique character (a number, symbol, or space) in addition to letters. Password security requires more than just password strength. They must also be updated on a regular basis.
Cloud Security Using Multi-Factor Authentication (MFA)
Regardless of how complex a password is, how frequently it is updated, or how resistant to theft it is, it still isn't the most secure authentication technique available. Multi-factor authentication (MFA) is a type of authentication that uses more than one identification vector. Cloud networks require the use of at least two components. Unauthorized users stealing or compromising credentials represent a more significant concern when users automate their log-in from home or remote computers. Secure access cannot be guaranteed by credentials alone.
Integrating Zero Trust Architecture Principles into Cloud IAM
Zero Trust Architecture is a revolutionary new approach to cybersecurity (ZTA). It has long been an element of government security procedures, and the NIST Special Publication 800-207 from August 2020 advises that it be used more widely. Overall, ZTA approaches IAM and cloud security using multi-factor authentication and access session management as guiding principles. In a given usage session, neither proximity nor user status is sufficient to establish trust. All users and sessions should be monitored as though they were a potential threat.
More in News