Identity and Access Management - IAM by Jo Peterson
Transcript
welcome I am here to talk to you about AWS security I'm Joe Peterson I'm the vice president of cloud and security for clarify 360. and I am here on behalf of the CTO advisor on their AWS everyday platform so let's get started there's six key areas in Cloud security identity and access management detection Network and application protection data protection incident response and compliance AWS addresses these six areas across 31 different products and today we're here to talk about their identity and access management platform or product so what is it well see you can securely manage your identities and access to AWS services and resources you can set and manage guard rails and find green access controls for your Workforce and your workloads you can manage identities across single AWS accounts or centrally connect identities to multiple multiple AWS accounts you can grant temporary security credentials for workloads that access your AWS resources and you can continually analyze access to right size permissions on your journey to least privilege so how does it work well with AWS identity and access management you can specify who or what can access services and resources in your AWS environment you can centrally manage and provide fine-grain missions you can analyze access to refine permissions across the footprint so why would you use it well you use IM to manage and scale workloads and Workforce while you securely support their agility and innovation in AWS so what are a couple ways that you could use it on a daily basis first you can apply fine grain permissions and scale with attribute based Access Control what does that do you can create granular permissions based on user user attributes such as Department job role team name by using attribute based Access Control another way to use it is to manage per account access or scale access across your AWS accounts and applications there's a center to provide multiple account access and application management across AWS next you can establish organization-wide and preventative guardrails on AWS by using service control policies you establish guardrails for IM for users and their roles and you implement a data perimeter around your accounts in AWS and then lastly you can set verify and right size permissions towards lease privilege so you can streamline to management you can access account findings you can set verify and refine policies on your journey towards lease privilege thanks for joining