AWS IAM is hard, but what can we do about it? IAM is hard. And we need to understand why IAM is hard and what to do about it. To uncover why IAM is hard, k9 Security interviewed +50 Cloud practitioners privately about their challenges and solutions configuring IAM...
First Look: Compare changes in AWS IAM access with k9
Today we’ll share a first look at how you can compare changes in AWS IAM access with k9 Security. Cloud teams tell us they need an easy way to understand how IAM access changes over time so they can review access periodically. Additionally, IAM access change analysis...
AWS Access Analyzer Policy Generator, building block for continuous policy improvement
AWS Access Analyzer Policy Generator analyzes an IAM user or role’s CloudTrail history and creates a least privilege IAM policy with only the actions that are in use (announcement). This policy generator looks like a great building block for minimizing AWS privileges...
AWS Access Analyzer Policy Checks Explained
AWS launched Access Analyzer Policy Checks to help you develop valid, secure policies and review existing policies. This post explains what the four types of policy checks do and how to start using them. The checks are available via console, CLI, and API...
Why are good AWS security policies so difficult?
Creating good AWS security policies is difficult for two reasons. First, the powerful AWS security model is complex and difficult to understand. Second, application deployments are changing and growing rapidly. Why is AWS IAM so @!#^$ hard? One of our favorite...
