Showing posts with label IAM. Show all posts
Showing posts with label IAM. Show all posts

Wednesday, December 23, 2020

You need a Cyber strategy

 https://devops.com/the-best-iam-practices-for-devops/

Most orgs fail to have an internal IAM policy, a partner IAM strategy (B2B), as well as a customer (B2C) strategy.  Due to that, the orgs is all over the place.

Furthermore, the article discusses unstructured data (cloud storage) that is often an issue for orgs as the lack of a strategy leads to a lack of data governance (classification, access controls, etc).  

Thursday, August 17, 2017

Orchestration is Great, But is it Secure

DevOps / DevSecOps are all the current rage, and that is great, but how secure is your environment?

Chef, Puppet, and others offer automation and orchestration, but have those environments been secured via IAM, TVM, and architectural perspective?  While these solutions offer add-ons, a secure design and incorporating the right controls from the get go, will help dramatically.

Tuesday, February 7, 2017

Vetting Security Policies

There always seems to be a considerable gap between policy development and execution.

This often stems from a delineation between the org that develops versus audits said policies.

Beyond administrative controls, many companies are now deploying security solutions (e.g., DLP, CASB, EMM/MDM, MAM, IAM/IDM, DMARC/SPF, ATP) w/ policy engines.  To implement either admin and/or technical safeguards and not validate their utilization is a noticeable risk.

Monday, November 21, 2016

Identity & Access Management (IAM / IdAM) Programs

IAM / IdAM / Single Sign-On (SSO) / Privileged Access Management (PAM) / Multi-Factor Authentication (MFA) / Identity Providers (IdP) / Identity Federation are all part of a program that enterprises should focus on these days.  And, these programs need to be able to extend to multiple technologies: cloud, mobile, IoT, ERP, etc.

However, these endeavors are treated as one-offs. 

As organizations wrestle with business transactions (merges, acquisitions, divestitures), the need to have a formal, organized IAM / IdAM program grows in need.

Wednesday, August 31, 2016

Consolidate Internal Identity Stores BEFORE Focusing on Cloud-based SSO / IAM

There is a tendency to focus on the shiny objects, and many orgs have a cloud-first mentality, but there is no reason to ignore the multitude of internal identity stores that exist in most large enterprises.

SSO, SAML, etc. are great, but what about LDAP, AD, etc.?  How about de / provisioning, especially with your vendors (e.g., SOC / MSSP, NOC / MSP, ITO, BPO)?

Monday, August 8, 2016

Securing Native Big Data Deployments v3.0: Apache Ranger & Atlas for DevSecOps, IAM, & InfoGov

Apache Ranger (http://ranger.apache.org/) and Atlas (http://atlas.incubator.apache.org/) offer some real thought leadership for securing native big data environments.

The question that remains is, will corporate IT teams embrace these new technologies?

I do see (cloud) providers (MS Azure, AWS) using these tools, as they need to for security compliance purposes.  I also see on-premise (hyper-convergence) solution vendors (e.g., Hortonworks, Cloudera) leveraging this as well.