Identity & Cross Account Access Management in AWS | CLOUD SECURITY - Alexandre Sieira

Identity & Cross Account Access Management in AWS | CLOUD SECURITY - Alexandre Sieira

In this episode of the Virtual Coffee with Ashish edition, we spoke with Alexandre Sieira - Founder @ Tenchi Security

In this episode, Alex & Ashish spoke about

  • What was your path into CyberSecurity?
  • What does Cloud Security mean for you?
  • How is Security different in a cloud world?
  • What are the kind of Identities in AWS?
  • What are the challenges with IT?
  • Identity in AWS vs Identity in Azure?
  • Best practices for Privilege and non-Privilege users in AWS?
  • AWS SSO
  • How important are Domain Accounts in Cloud World/
  • Importance of 2FA?
  • What is Cross Account and why does it matter in Cloud?
  • IAM Role in AWS?
  • AWS STS service in AWS?
  • What about Bio metrics as a 2FA?
  • How does one manage identity across a large cloud landscape?
  • Multi-cloud or Poli-cloud?
  • Security people that know all clouds?
  • How should one manage Root Accounts in AWS?
  • What are the challenges with Identity that people are not talking enough about?
  • Recommendation on good source of AWS security training
  • Thoughts on AWS Cognito?
  • Cognito Research by Andres Riancho- https://andresriancho.com/internet-scale-analysis-of-aws-cognito-security/
  • Auditing IAM using Cloud Spanning - https://github.com/salesforce/cloudsplaining
  • Policy Sentry - https://github.com/salesforce/policy_sentry
  • IAM Policy Generator and AWS Challenges between products

ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv

Twitter - @kaizenteq @hashishrajan

If you want to watch videos of this and previous episodes:

- Twitch Channel: https://lnkd.in/gxhFrqw

- Youtube Channel: https://lnkd.in/gUHqSai

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(360)

Securing Millions of AI-built Apps: How Lovable Defends Against Insider Threats

Securing Millions of AI-built Apps: How Lovable Defends Against Insider Threats

Empowering non-technical users to build production-grade applications requires a proactive, secure-by-design architecture. In this episode, Ashish sits down with Marcus Hallberg and Samuel Kelemen, se...

11 Sep 1h 10min

Why AI Won't Replace Your SOC: Federated Data & APEX Framework

Why AI Won't Replace Your SOC: Federated Data & APEX Framework

Hash values, IP addresses, and domains are virtually useless as primary detection mechanisms in the era of AI-driven polymorphic malware and short-lived phishing kits. If your detection strategy is st...

1 Sep 37min

The "Hunt First" AI Security Strategy

The "Hunt First" AI Security Strategy

Did you know that 82% of all intrusions don't involve any sort of malware, and AI-augmented attacks are up 89% year over year? If your security operations team is solely focused on reacting to known-b...

25 Aug 46min

Shadow AI & Sandbox Escapes: Why You Need an Agentic Control Plane?

Shadow AI & Sandbox Escapes: Why You Need an Agentic Control Plane?

When Claude Cowork hits a roadblock, it doesn't give up, it writes a custom Python script and downloads an untrusted NPM package just to bypass its restrictions and finish its goal. Are your security ...

18 Aug 32min

How Adobe Uses AI Agents for building a WAF Pipeline?

How Adobe Uses AI Agents for building a WAF Pipeline?

When vulnerability disclosures shrink the wild exploit window down to less than 24 hours (or even minutes), traditional manual patching and WAF rule creation simply cannot keep up.In this episode, Ash...

4 Aug 47min

Why Runtime Agents Are Replacing Static Posture Checks

Why Runtime Agents Are Replacing Static Posture Checks

The attack window from the discovery of a vulnerability to its exploitation has shrunk to less than 24 hours and sometimes down to just 25 minutes. Is your security team prepared for the speed of AI-d...

28 Jul 44min

The Hidden Cost of BlackBox AI: Bridging Cloud and Code Security

The Hidden Cost of BlackBox AI: Bridging Cloud and Code Security

Traditional SCA and SAST tools are notorious for drowning security teams in false positives, historically flagging nine out of ten alerts incorrectly. But while generative AI seems like a magic bullet...

9 Jul 42min

Who Governs Your AI Agents? Identity, Offboarding & Open Standards

Who Governs Your AI Agents? Identity, Offboarding & Open Standards

Are overprivileged AI agents the biggest emerging threat in cybersecurity? In a recent high-profile attack, a vibe-coding company had its entire source code stolen because an attacker exploited a long...

2 Jul 34min

Populært innen Teknologi

teknisk-sett
tomprat-med-gunnar-tjomlid
lydartikler-fra-aftenposten
energi-og-klima
elektropodden
rss-ki-praten
hans-petter-og-co
nasjonal-sikkerhetsmyndighet-nsm
shifter
smart-forklart
rss-alt-som-gar-pa-strom
rss-ai-forklart
teknologi-og-mennesker
rss-snakk-om-sikkerhet
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
fornybaren
rss-teknologioptimistene-en-podkast-om-teknologi-og-mennesker
pedagogisk-intelligens
rss-alt-vi-kan
rss-heis