The Cyber Security Review | Friday, September 06, 2024
Cloud migration necessitates robust identity and access management (IAM) solutions to address challenges like account inventory, provisioning, and privileges, requiring centralized control and regular audits.
FREMONT, CA: As organizations migrate to the cloud, security and risk management teams view identity as the new security perimeter. While these teams are adept at handling on-premises identity and access management (IAM), deploying and maintaining IAM in the cloud presents unique challenges. Here are some key cloud-specific IAM challenges and their solutions.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Lack of Visibility into Account Inventory
Challenge: Security teams often need help understanding which users can access applications and where they are accessing them, especially when distributed across multiple clouds. Proper visibility over user account provisioning is essential to ensure appropriate access control and accurate compliance reporting.
Solution: Ensure all accounts, regardless of the cloud model (SaaS, PaaS, or IaaS), tie back to a central directory service like Active Directory. Utilize federation and single sign-on (SSO) for access management. For unique service and admin accounts, establish processes to create and track these as exceptions, with regular auditing and monitoring.
Improper Service and User Provisioning and Deprovisioning
Challenge: Shadow and unmanaged accounts can proliferate without central management of provisioning and deprovisioning cloud accounts. Former employees retaining access to business applications and data pose significant security risks.
Solution: Develop a centralized process for creating and removing all cloud accounts for all types of cloud services when an employee leaves or is terminated. Ideally, use a single provisioning tool or service that integrates with all federation and SSO capabilities.
Zombie SaaS Accounts
Challenge: Inactive assigned users, or zombie accounts, are particularly prevalent with SaaS offerings. Some SaaS apps do not integrate well with federation and SSO, requiring local users for administrative capabilities.
Solution: Adopt cloud security posture management, cloud access security broker, or security service edge platforms to track SaaS deployments. Regularly audit all SaaS accounts for terminated and inactive employees and other stakeholders, focusing on partners and contractors who might not be integrated with central identity directories.
Lifecycle Management
Challenge: Cloud identity lifecycle management can worsen due to a lack of visibility and insight into what has been created, by whom, and where.
Solution: Manage all identities centrally and avoid generating identities outside a central directory system with SSO and federation. Adapt current lifecycle management practices to the cloud as needed.
Changing Roles
Challenge: Users changing roles within their company can create IAM issues, especially in large organizations with numerous cloud deployments.
Solution: Enable logging and auditing for role changes within all cloud environments. Build correlation rules to ensure these changes align with approved managerial directions.
Too Many Admin Accounts
Challenge: The proliferation of admin accounts can lead to cloud misconfigurations and accidental data exposure.
Solution: Implement centralized control to allocate privileges and track admin accounts. Use a privileged user management (PUM) tool that integrates with cloud services and DevOps pipelines. Follow the principle of least privilege and use privileged access management to ensure only a select few users have admin access.
More in News