THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Wednesday, January 26, 2022
The cloud transition will continue to develop, with more enterprises built on AWS, Azure, GCP, and other cloud providers.
FREMONT, CA: Because of the broad usage of cloud infrastructure, identification has become the new perimeter. Indeed, many IAM solutions have evolved to provide cloud-based identity management for human identities and entitlements. However, first-generation cloud IAM lacks the granularity, visibility, and security capabilities necessary to handle the complex entitlements associated with service identities, which comprise most identities in cloud infrastructure systems. By delivering enhanced identity mapping, risk assessment, and anomaly detection for cloud infrastructure services, CIEM closes this gap.
The pace of digital transformation has accelerated in recent years. COVID-19's requirement for remote access, combined with other technological advancements like worldwide connection and digitalization, has raised the demand for cloud computing and microservices architectures. Most businesses have cloud adoption and migration built into their business goals. Numerous businesses formed in the recent decade were born in the cloud.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
As a result, the nature of security has shifted. Historically, organizational networks were perimeter-based and physically guarded by firewalls. However, identification is the new boundary in the cloud, making identity and access rights the riskiest security characteristic.
There are two forms of cloud identities:
• Human identities: Human identities include those of end-users, administrators, and developers; in other words, actual human individuals.
• Service identities: A unique identifier assigned to each service, with rights and entitlements dictating which services the identity may access and what types of actions it may do. Each resource type—virtual machines, containers, data stores, and secret stores, for example - has an identity and associated permissions and entitlements.
Cloud Identity Entitlements
Each of the two identities can be granted access privileges or permissions to the organization's cloud infrastructure. These entitlements are extremely powerful since they define what an identity is permitted to do and is not permitted to do across the infrastructure and which resources it is permitted to access.
With the appropriate entitlements, a user or service can activate or deactivate virtual machines, buckets, and storage services, configure the network, grant access to other identities, and even access—and potentially leak—important company data.
Additionally, access entitlements can be inherited: If a user or service (let's call them A and B) has access to another identity (let's call them C and D), A can inherit all of C's entitlements. This means that even if A has not been explicitly granted authorization to undertake an activity, such as moving virtual machines, it has access to B. If B has those authorizations, A does as well.
As one can see, entitlements and how they work empower identities—and potentially expose a company to significant risk. Cloud security requires managing and monitoring cloud identities to prevent excessive entitlements.
Although critical, managing identities in the cloud is not a simple task. While standard IAM technologies are great for managing human IDs, managing service identities efficiently in AWS, Azure, and GCP settings is another matter. Among the difficulties are the following:
A high degree of complexity: Each identity has different entitlements and intricate links and interconnections with other identities. As a result, numerous interdependent dependencies are extremely difficult to audit, check, and monitor. A multi-cloud environment multiplies the complexity by a factor of ten.
Insufficient Visibility: Human-centric identity and access management technologies are incapable of managing service entitlements. Without the appropriate technology, enterprises are unable to see all identities and their associated entitlements and the relationships between services and network exposure. Not only are organizations unaware of their identity entitlements, but they are also unaware of the security dangers associated with their attack surface. This renders people incapable of managing their identities—or assessing their dangers and weaknesses.
Monitoring access continuously, ensuring that no identity has excessive permissions, and restructuring entitlements take significant, devoted resources and time. Due to the enormous expense involved, organizations frequently neglect to perform such duties consistently. This lack of governance can result in significant security issues, such as the CapitalOne breach, which resulted in a massive data leak.
More in News