< ciso
brief />
Tag Banner

All news with #iam tag

228 articles · page 2 of 12

IAM Identity Center adds multi‑Region directory replication

🔁 IAM Identity Center now replicates identities and entitlements from the primary AWS Region to additional Regions when using the Identity Center directory as the identity source. This extends prior multi‑Region support for organization instances that used external identity providers to those using the Identity Center directory, improving resilience and enabling deployment closer to users and for data residency. The feature requires a multi‑Region customer managed KMS key and is available in the 17 enabled‑by‑default commercial Regions; standard KMS charges apply.
read more →

Amazon Neptune adds tag-based access control

🔒 Amazon Neptune now supports tag-based access control (TBAC) for IAM, enabling the use of AWS resource tags and IAM principal tags as conditions in IAM policies and Service Control Policies to govern data-plane access. TBAC lets administrators restrict neptune-db:* actions to clusters whose tags match principal tags, reducing lateral access risks in shared VPCs and supporting federated identities via SAML or OIDC session tags. The feature is available in all Regions running Neptune and requires engine version 1.2.0.0+ with IAM authentication enabled.
read more →

Hardening Google Cloud access with IAM conditions

🔐 In Google Cloud, IAM enforces the Principle of Least Privilege by combining predefined and custom roles with Allow and Deny policies across resource hierarchies. When resource-level bindings are not possible, IAM conditions let you scope broad roles to specific APIs, services, MCP servers, tools, or time windows. Use conditions alongside Deny policies to surgically remove excessive permissions and strengthen defense-in-depth.
read more →

AWS Marketplace adds India seller signature management

📝 AWS Marketplace now lets India-based sellers upload and manage their seller signatures directly through AWS Partner Central, replacing the prior manual email submission process. This centralized flow consolidates GSTIN registration and signature management for sellers transacting in India. Uploaded signatures are securely stored and used for buyer tax invoices, with automated real-time validation and an at-a-glance tax summary showing verification status. Sellers receive email notifications on verification outcomes and can resubmit if rejected using provided rejection reasons.
read more →

Security Priorities and Risks in the AI Era

🔐 At a recent Information Security Day seminar, white-hat hacker and Steelion CEO Park Chan-am outlined how AI is accelerating attacks and reshaping security priorities. He emphasized that access control, supply chain security, and human verification remain central even as AI shortens vulnerability discovery from weeks to hours. Park warned that AI agents and local testing environments widen attack surfaces and urged new approaches to vulnerability prioritization and behavioral defenses.
read more →

AWS CloudTrail adds UserIdentity network filters

🔍 Today AWS announced enhanced CloudTrail filtering for VPC endpoint network activity events, allowing selectors that filter logs by the IAM user identity making API calls. This update lets customers log only relevant events — for example, access denied actions from identities outside a trusted list — reducing logging noise and cost. The feature supports console, CLI, and SDK access and is available in all Regions that support CloudTrail network activity events.
read more →

Global IAM Data Governance Tags for BigQuery

🔒 This post introduces the preview of IAM data governance tags for BigQuery column-level security. Built on Google Cloud Resource Manager tags with purpose=DATA_GOVERNANCE, these tags are global, support hierarchical classification up to five levels, and are replicated for disaster recovery. The article explains creating tag keys/values, attaching tags to columns via JSON or SQL, and defining regional BigQuery data policies for masking or raw access. It highlights decoupled governance, regional policy enforcement, and layered security requirements.
read more →

Least privilege guidance for AI agents and access

🔒 AI agents require managed identities and tightly scoped permissions to avoid uncontrolled access and privilege escalation. Treat each agent as a first-class principal with lifecycle-managed identities, explicit owners, and task-based RBAC. Implement controlled tool binding, just-in-time elevation for high-risk actions, and end-to-end audit logging to ensure accountability and rapid incident response. Regular reviews and revocation testing are essential.
read more →

Amazon Cognito adds password hash import support

🔐 Amazon Cognito now supports importing users with password hashes in CSV imports, allowing migrated users to sign in immediately with existing credentials. Administrators specify the source system's hashing algorithm during import, and Cognito verifies passwords against the imported hash on first sign-in. Supported algorithms include bcrypt, scrypt, Argon2id, and PBKDF2 with SHA-256; all imported hashes receive additional cryptographic protection before storage. The feature is available in all AWS Regions where Cognito is offered and can be used via the Console, CLI, or SDKs.
read more →

AWS IAM Identity Center Gains FedRAMP Class C

🔒 AWS IAM Identity Center has achieved FedRAMP Class C authorization and is now in scope for the US East (Ohio), US East (N. Virginia), US West (N. California), and US West (Oregon) Regions. This allows organizations to use the service to enable workforce access to AWS accounts and applications that require FedRAMP Class C compliance. The announcement reiterates that the Federal Risk and Authorization Management Program (FedRAMP) standardizes security assessment and continuous monitoring for cloud services and that IAM Identity Center is the recommended AWS service for managing workforce access. Additional compliance and product guidance is available in the AWS documentation and user guides.
read more →

NHS warns staff over unlawful access to records

🔒 The NHS has warned staff they may face criminal prosecution and career-ending sanctions for accessing patient records without a legitimate reason. Head of the NHS Jim Mackey called such behaviour a “disgraceful breach of patient trust,” and the organisation has launched an awareness campaign alongside guidance for monitoring and preventing unauthorized access. The guidance urges technical controls such as least-privilege, MFA and role-based access, and notes real-time flags in modern electronic patient record systems. High-profile incidents and ICO action have prompted the drive to strengthen detection and deterrence.
read more →

AWS Organizations applies security defaults for new orgs

🔐 AWS Organizations now applies core security controls by default when you create a new organization via the AWS Organizations console. The service automatically attaches service control policies (SCPs) that prevent member accounts from leaving or closing themselves, giving CloudOps and central security teams immediate protection from day one. These defaults are intentionally lightweight and fully editable or disableable to avoid disrupting legitimate operations while establishing governance for new or migrating enterprises.
read more →

AWS adds OAuth support for MCP Server access

🔐 AWS Sign-In now supports OAuth for connecting agents to the AWS MCP Server, enabling browser-based and headless authentication that leverages existing IAM, IAM Identity Center, and federated sign-in methods. The update includes dynamic client registration, token introspection and revocation, new CloudTrail elements, global condition keys, and a headless OAuth API. Agents discover OAuth endpoints, register via DCR, and use authorization code or client credentials flows to obtain short-lived tokens. Administrators can govern OAuth access using standard IAM policies plus OAuth-specific condition keys and monitor activity via CloudTrail.
read more →

Six-stage maturity model for non-human identities

🔒 This article examines the risks of agentic AI and non-human identities in enterprise environments, illustrating incidents where LLM-based agents caused outages due to weak identity controls. It argues that existing IAM models are insufficient for agents that act autonomously, and cites industry guidance from Gartner, OWASP, CISA and NIST. The author proposes six minimum requirements and a cumulative six-stage NHI maturity model to ensure defensible production deployments.
read more →

AWS Security Hub adds impact analysis for exposures

🔍 Today, AWS Security Hub introduces impact analysis for exposure findings, enabling security teams to see the downstream resources an attacker could reach if an exposure is exploited. The feature maps privilege escalation paths by analyzing effective IAM permissions and displays potential attack paths in a graph. A new Impact Assessment tab prioritizes chains of compromise and shows the permissions at each step, while severity scores are adjusted to reflect downstream reach.
read more →

Governing Identity for Agentic AI Operations

🛡️ Existing security controls weren’t built for autonomous AI agents, and static credentials and standing privileges are insufficient. Organizations must define agentic identity, secure agent-to-agent communication, adopt dynamic secrets management, enforce least privilege for delegated workflows, and unify workforce identity. Governance across the identity lifecycle is essential to ensure auditable, revocable, and context-aware access for agents.
read more →

Improving security across Microsoft partner ecosystem

🔒 This post by Raji Dani, Microsoft Deputy CISO, explains how Microsoft secures its partner ecosystem—especially Microsoft Cloud Solution Providers (CSPs)—to reduce risk to downstream customers. It outlines vetting, mandatory security requirements for authorization, granular delegated administrative privileges (GDAP), telemetry and rapid access revocation capabilities. The article emphasizes shared responsibility between Microsoft and partners and a continual roadmap to raise security standards.
read more →

Identity lifecycle challenges posed by AI agents

🔒 This article explains how traditional identity lifecycle management — built around HR-driven joiner, mover, and leaver events — fails to govern AI agents. It describes how agents are created outside HR and IGA workflows, arrive with embedded credentials, and expand access dynamically at runtime. The piece highlights gaps in provisioning, access reviews, and offboarding when agents proliferate across parallel instances and orchestration layers.
read more →

AWS Workload Credentials Provider: Role Chaining and Prefetch

🔒 This post explains how to use two enhancements to the AWS Workload Credentials Provider: role chaining for cross-account secret retrieval and prefetching to reduce cold-start latency. It covers configuration, required IAM permissions, SSRF token usage, and how to build and deploy the Rust-based provider across EC2, ECS, EKS, and Lambda. Examples show curl and Python calls, TOML configuration for max roles, and prefetch settings for individual secrets or tag-based discovery.
read more →

Amazon RDS for Db2 adds self-managed Active Directory support

🔒 Amazon RDS for Db2 now lets customers join DB instances directly to self-managed Microsoft Active Directory domains, whether on-premises, in AWS, or in another cloud. Using Kerberos for authentication, this enables single sign-on and allows customers to authenticate and authorize database users without deploying AWS Managed Microsoft AD or creating a domain trust. Domain join is available when creating or modifying instances using a delegated AD service account stored in AWS Secrets Manager and encrypted with AWS KMS, and the feature is generally available in all Regions where RDS for Db2 is offered, including GovCloud.
read more →