< ciso
brief />
Tag Banner

All news with #iam tag

261 articles · page 7 of 14

Microsoft Fast-Tracks Reinstatement for Hardware Developers

🔐 Microsoft has introduced a temporary fast-track to reinstate accounts suspended from the Windows Hardware Program after developers reported being locked out without prior notice. The process asks affected partners to open a support case, provide a clear business justification, and resolve outstanding compliance requirements before full access is restored. Microsoft also provided guidance on correct sign-in and alternative support contacts to address workflow issues.
read more →

Aurora DSQL PDO_PGSQL Connector for PHP Released by AWS

🔒 The new Aurora DSQL Connector for PHP (PDO_PGSQL) simplifies building PHP applications on Aurora DSQL by automating IAM token generation, SSL configuration, and connection pooling. It removes the need for static user-managed passwords while maintaining full compatibility with existing PDO_PGSQL features. The connector also offers opt-in optimistic concurrency control (OCC) retries with exponential backoff and supports custom IAM credential providers and AWS profiles to streamline credential management and client retry logic.
read more →

AWS Private CA Adds Customer Managed RAM Permissions

🔒 AWS Private Certificate Authority now supports customer managed permissions in AWS Resource Access Manager (AWS RAM), enabling administrators to grant only the specific API operations each consuming account needs. You can choose from granular read operations (for example, DescribeCertificateAuthority, GetCertificate, GetCertificateAuthorityCertificate) and write operations (for example, IssueCertificate, RevokeCertificate). Cross-account issuers are no longer limited to a single certificate template. The feature is available in all Regions where Private CA and RAM are offered.
read more →

Shrinking the IAM Attack Surface with IVIP Platforms

🔍 Orchid Security warns that modern IAM estates harbor extensive "identity dark matter," with roughly 46% of identity activity operating outside centralized visibility. The article positions Gartner's Identity Visibility and Intelligence Platform (IVIP) as a necessary observability layer that unifies telemetry from managed and unmanaged systems, applies AI to infer intent and risky behavior, and enables automated remediation to reduce exposure.
read more →

Hidden Cost of Recurring Credential Incidents and Costs

🛡️ The Hacker News highlights that while headline breaches attract investment, recurring credential incidents—account lockouts, reused or exposed passwords, and frequent resets—impose persistent operational costs. Forrester estimates resets can account for up to 30% of helpdesk tickets, at roughly $70 each, and IBM’s 2025 report cites a $4.4M average breach cost. Poorly designed password policies and mandatory periodic resets often make the problem worse by prompting insecure user behavior. Practical measures include user-friendly, robust policies, breached-password screening, and shifting away from arbitrary expiration windows; vendors such as Specops Password Policy are presented as tools that detect exposed credentials and reduce incident volume.
read more →

Cloudflare Launches Organizations Beta for Enterprises

🔒 Cloudflare has introduced Organizations in public beta to help enterprise customers manage multiple Cloudflare Accounts centrally. The feature creates an organization layer for account grouping, introduces an Org Super Administrator role, and provides aggregated analytics and shared policy sets. Initial rollout targets enterprise plans with staged expansion to other customers and partners. There is no additional fee for Organizations during beta.
read more →

Amazon Verified Permissions: policy aliases and names

🔑 AWS has added support for policy store aliases along with named policies and policy templates in Amazon Verified Permissions. Developers can now assign human-readable aliases to tenant policy stores and reference policies by meaningful names instead of system-generated IDs. This removes the need for separate mapping tables and simplifies multi-tenant deployments and everyday policy management. These capabilities are available in all Regions where the service operates.
read more →

AWS Releases Aurora DSQL Connectors for .NET and Rust

🔐 The new Aurora DSQL connectors for .NET (Npgsql) and Rust (SQLx) simplify secure application access by automating IAM token generation, SSL setup, and connection pooling. They remove reliance on static user passwords while remaining fully compatible with existing driver features. The connectors also provide opt-in optimistic concurrency control retries with exponential backoff, custom IAM credential providers, and AWS profile support to ease credential management.
read more →

Amazon Connect extends tag-based access to quick responses

🔒 Amazon Connect now applies tag-based access control (TBAC) to quick response assignments for routing profiles. Administrators can restrict which routing profiles receive specific quick responses based on their TBAC permissions, so agents only see templates relevant to their assigned profiles. This change aligns quick responses with existing Amazon Connect resource access controls and supports compliance and localized disclosure workflows. The update is available in multiple AWS Regions.
read more →

Aurora DSQL Connector for Ruby (pg gem) Released on AWS

🔒 The new Aurora DSQL Connector for Ruby (pg gem) simplifies building Ruby applications on Aurora DSQL by automating IAM token generation, SSL configuration, and connection pooling. It removes the need for persistent user-generated passwords while preserving full compatibility with existing pg gem features. The connector also provides optional optimistic concurrency control (OCC) retry with exponential backoff and supports custom IAM credential providers and AWS profiles.
read more →

Rethinking Cybersecurity Hiring: Skills-First Talent

🔍 Many organizations treat the cybersecurity skills gap as a supply problem, but the 2025 Cybersecurity Skills Gap Global Research Report shows restrictive hiring definitions are a major cause. Rigid filters like four-year degrees exclude candidates with military, technical, or vendor-certified experience who already possess relevant, hands-on capabilities. Adopting a skills-first approach and mapping role-aligned certifications to job requirements expands the qualified pool, shortens onboarding, and reduces operational risk. Fortinet emphasizes partnerships and free, scalable training as practical ways to build and certify talent at scale.
read more →

Amazon Route 53 Profiles Adds Granular IAM Controls

🔐 Amazon Route 53 Profiles now supports granular AWS Identity and Access Management (IAM) permissions. Administrators can create IAM policies that restrict users to specific operations—associate, disassociate, or update—on resource types such as private hosted zones, Resolver rules, and DNS Firewall rule groups. Permissions may be scoped by resource ARN, hosted zone name, Resolver rule domain name, DNS Firewall rule group priority range, or specific VPC associations to enable precise delegation.
read more →

6 Key Trends Reshaping the Identity and Access Market

🔐 The IAM market is shifting from traditional login and MFA toward treating identity as a security control plane, driven by demand for phishing-resistant authentication and stronger governance for non-human accounts. Buyers are prioritizing FIDO2/passkeys, biometrics, and controls for service accounts, API keys, and AI agents. Regulatory change, managed services, and vendor consolidation are reshaping architectures and procurement decisions.
read more →

AWS IAM Policy Types for Secure Multi-Account Access

🔒 This post explains AWS IAM policy types and how to apply them in a multi-account environment. It describes identity-based and resource-based policies, permissions boundaries, service control policies (SCPs), and resource control policies (RCPs), with ownership guidance for central security and application teams. Using a practical multi-account example, it shows how to combine these controls to enforce least privilege and protect data while enabling team autonomy. It also recommends policy validation and provides sample code.
read more →

Amazon Bedrock AgentCore Browser: Enterprise Policies & CA

🔒 Amazon Bedrock AgentCore now lets administrators apply Chrome Enterprise policies to AgentCore Browser and upload custom root CA certificates for both AgentCore Browser and Code Interpreter. These capabilities enable enforcement of organizational controls such as URL restrictions, disabling downloads or password managers, and implementing URL blocklists while agents operate. Custom root CA support allows agents to connect to internal systems and work with corporate TLS interception without certificate errors. The features are available in 14 AWS Regions where AgentCore is offered.
read more →

Amazon Redshift: Federated Permissions via IAM IdC

🔐 Amazon Redshift now supports federated permissions with AWS IAM Identity Center (IdC) across multiple AWS Regions, letting you extend IdC from a primary Region to additional Regions for improved proximity-based performance and resilience. In those Regions you can create Redshift and Lake Formation Identity Center applications without replicating identities, so existing workforce identities can query warehouses while row-, column-level and masking controls continue to apply automatically. Users benefit from single sign-on access via Amazon QuickSight, the Redshift Query Editor, or third-party SQL tools, simplifying access and compliance across regions.
read more →

Amazon S3 Access Grants Now Available in New Zealand

🔒 Amazon S3 Access Grants are now generally available in the AWS Asia Pacific (New Zealand) Region. The capability maps identities from directories such as Microsoft Entra ID and AWS IAM principals directly to S3 datasets, enabling identity-driven, automated access provisioning for users. This reduces the need for manual policy changes and simplifies large-scale permission management. Local availability also helps improve latency and supports regional compliance and governance requirements for organizations operating in New Zealand.
read more →

Top 5 Actions CISOs Must Take to Secure AI Agents Now

🔐 Treat AI agents as first-class identities and enforce identity-based access across systems and APIs. The author argues CISOs must move beyond prompt guardrails to explicit authentication, scoped permissions, continuous logging, and monitoring of tokens, service accounts, OAuth grants, and keys. Organizations should discover shadow AI, map agent access, and enforce intent-aware controls. Full lifecycle governance — ownership, rotation, reviews, and decommissioning — is required to prevent privilege creep and data loss while enabling safe autonomy.
read more →

AWS Glue Data Catalog: IAM Permissions for S3 Tables

🔐 AWS announced IAM-based authorization in the AWS Glue Data Catalog for Amazon S3 Tables and Apache Iceberg materialized views. The change allows administrators to consolidate storage, catalog, and query engine permissions into a single IAM policy, simplifying access management for analytics services. Customers can still opt into AWS Lake Formation for fine-grained controls and manage access via Console, CLI, API, or CloudFormation.
read more →

What It Takes to Win the CSO or CISO Role Today: Guide

🔒 CSO and CISO roles have shifted from technical gatekeepers to board-level leaders accountable for resilience, compliance, and business enablement. Recruiters and incumbent executives emphasize a T-shaped background — deep domain expertise plus broad business fluency — including identity and access management, cloud operations, AI risk, and security automation. Candidates must translate security investments into enterprise value and demonstrate continuous assurance; negotiation, delegation, and measurable outcomes now define success.
read more →