< ciso
brief />
Tag Banner

All news with #iam tag

261 articles · page 8 of 14

Deploy AWS Applications and Access Accounts Across Regions

🔁 AWS now supports IAM Identity Center multi-Region replication, enabling workforce access and supported AWS managed applications to operate from additional Regions for improved resiliency and lower latency. Administrators create a multi-Region customer-managed KMS key, replicate it to target Regions, and add those Regions in the Identity Center console. External IdP configurations (for example, Okta or Microsoft Entra ID) must be updated with new ACS and access portal URLs so both service-provider and IdP-initiated flows work. Instance-level management remains centralized in the primary Region while additional Regions provide read-only replicated configuration and local application access.
read more →

Access Decisions: The Weakest Link in Identity Security

🔐 Longstanding identity programs have largely solved authentication with MFA and SSO, but authorization — the decisions about what authenticated identities can do — remains fragile and undergoverned. The article highlights a persistent denominator problem: many assets, cloud tenants, service accounts and shadow IT tools fall outside centralized visibility, so coverage metrics can be misleading. Effective risk reduction requires context-rich, accountable access decisions and stronger governance of non-human and third-party identities to avoid rubber-stamp approvals and excessive blast radius.
read more →

AWS IAM Roles Anywhere Adds Post-Quantum ML-DSA Support

🔐 AWS Identity and Access Management (IAM) Roles Anywhere now supports the FIPS 204 Module-Lattice Digital Signature Standard (ML-DSA), a NIST-standardized, quantum-resistant digital signature algorithm. Customers can register ML-DSA-signed CA certificates as IAM Roles Anywhere trust anchors or reference AWS Private Certificate Authority instances, and issue end-entity X.509 certificates bound to ML-DSA keys. The capability is available in all Regions where IAM Roles Anywhere operates, including AWS GovCloud (US), the AWS European Sovereign Cloud (Germany), and China Regions.
read more →

Why Password Audits Miss Accounts Attackers Actually Want

🔐 Password audits commonly validate complexity, length and rotation but frequently miss the accounts attackers prefer. Many organizations overlook reused or breached credentials, orphaned and dormant accounts, and high‑value service accounts with non‑expiring passwords. Point-in-time checks also fail to catch continuous threats like credential stuffing. Modern audits should add breached-password screening, risk-based prioritization, and continuous monitoring using tools such as Specops Password Policy.
read more →

AWS simplifies IAM role creation in service workflows

🔐 AWS Identity and Access Management (IAM) now lets you create and configure IAM roles directly within many service console workflows, so you no longer need to switch to the IAM console. A new in-context permissions panel appears during relevant tasks and supports default policies or a simplified statement builder for custom permissions, while retaining full IAM role-management capabilities. Initially available in the US East (N. Virginia) Region, the feature will roll out to additional services and regions. This streamlines role setup for services such as EC2, Lambda, EKS and more.
read more →

How to Tell if a CSO Is the Real Deal or Inflated Today

🔍 Recruiters and current CSOs warn that true CSO capability combines technical fluency, business judgment, and clear communication. Inflated titles and hasty hires create false confidence, wasted budgets, and a culture of compliance rather than security. Top CSOs prioritize risk choreography, translate risk into business outcomes, and balance risk and revenue. Candidates and employers should verify mandate, budget, and cross‑functional influence before assigning the title.
read more →

AI Agents as Identity Dark Matter: Governance Risks

🔐 The article explains how Model Context Protocol (MCP)-driven AI agents are rapidly moving from chat assistants into enterprise workflows, creating an emergent class of non-human identities that often evade traditional IAM controls. It warns these agents gravitate to low-friction credentials—local accounts, long-lived tokens, and API keys—creating pervasive “identity dark matter.” The piece recommends pairing agents with human sponsors, enforcing dynamic, context-aware access, centralizing visibility and auditability, and applying consistent governance across hybrids to prevent privilege drift and regulatory blind spots.
read more →

Standardized IAM Context Keys for AWS-Managed MCP Servers

🔐 AWS introduced standardized IAM context keys for its managed remote Model Context Protocol (MCP) servers so AI agents can operate with existing IAM credentials while enabling distinct governance controls. The two keys — aws:ViaAWSMCPService (boolean) and aws:CalledViaAWSMCP (string) — let you allow or deny MCP-initiated actions and restrict access to specific MCP servers. AWS will also simplify public endpoint authorization so AI calls use standard IAM permissions (no separate MCP actions) and plans to add VPC endpoint support for private-network enforcement and two-stage authorization.
read more →

Amazon Cognito Enhances Client Secret Lifecycle Management

🔐 Amazon Cognito now supports on-demand client secret rotation and lets you bring your own custom client secrets for app clients in user pools. You can maintain up to two active secrets per app client to enable staged rollovers and avoid application downtime during transitions. These lifecycle controls address periodic rotation and migration needs and are available in all Regions where Amazon Cognito user pools are offered; management is supported via the Console, CLI, SDKs, or CloudFormation.
read more →

Identity Posture Becomes Key Metric in Cyber Underwriting

🔒 Insurers and regulators are increasingly using identity posture as a primary underwriting metric, shifting focus from isolated technical controls to evidence of ongoing identity governance. Evaluations emphasize password hygiene, visibility into credential exposure, privileged access management, and comprehensive MFA coverage across remote, email, and privileged access paths. Organizations that can demonstrate continuous monitoring, regular access certification, and the removal of shared or never‑expiring credentials are more likely to secure favorable premiums and avoid claim disputes.
read more →

AWS IAM Identity Center Available in Asia Pacific (NZ)

🔔 AWS IAM Identity Center is now available in the Asia Pacific (New Zealand) AWS Region, expanding the service to 38 AWS Regions globally. The service is the recommended approach for managing workforce access, offering centralized single sign-on and account management by connecting your existing identity source once. IAM Identity Center powers personalized experiences in services such as Amazon Q and enables user-aware access controls and auditing in services like Amazon Redshift. It is offered at no additional cost in supported regions.
read more →

Aurora DSQL: Go, Python, and Node.js Connectors Released

🔐 Amazon Web Services announced new Aurora DSQL Connectors for Go (pgx), Python (asyncpg), and Node.js (WebSocket for Postgres.js). The connectors serve as transparent authentication layers that automatically generate IAM tokens per connection, removing the need for manual token handling while preserving full compatibility with standard PostgreSQL driver features. The Node.js connector adds WebSocket support for environments where TCP is unavailable. All connectors accept custom IAM credential providers to match customer credential workflows.
read more →

Over-Privileged AI Drives 4.5x Higher Incident Rates

🔐 Teleport's 2026 report finds 69% of US infrastructure security leaders say identity management must evolve to address mounting AI risks. Respondents reported tangible AI-related incidents — 35% confirmed and a further 24% suspected — even as AI improved investigation times, documentation quality and engineering output. The report identifies over-privileged AI and reliance on static credentials as primary risk drivers and recommends least-privilege access, reduced use of long-lived secrets, and reorganizing identity teams to include platform and engineering stakeholders.
read more →

Amazon S3 Access Grants Available in Taipei Region

🔐 Amazon announced that Amazon S3 Access Grants are now available in the AWS Asia Pacific (Taipei) Region. Access Grants map corporate identities in directories such as Microsoft Entra ID or AWS Identity and Access Management (IAM) to S3 datasets, enabling scalable, identity-based data access. The feature automates S3 permission assignment for end users and simplifies data governance for enterprises operating in Taipei. Refer to the AWS Region Table and product documentation for regional availability and deployment guidance.
read more →

AWS Expands Resource Control Policies to DynamoDB Service

🔐 AWS has added Amazon DynamoDB to the set of services supported by Resource Control Policies (RCPs), enabling organizations to centrally constrain the maximum permissions available to resources. Administrators can now use RCPs to block identities outside their AWS Organization from accessing DynamoDB, helping enforce a data perimeter and baseline security standards. RCPs are available in all AWS commercial Regions and AWS GovCloud (US) Regions.
read more →

Gartner: Six Cybersecurity Trends Shaping 2026 Priorities

🔒 Gartner identifies six priority cybersecurity trends for 2026 that demand immediate attention from security and risk leaders. Key risks include uncontrolled agentic AI proliferation, global regulatory volatility, and the urgent need to plan for post-quantum cryptography. Gartner advises stronger governance to detect and control both approved and shadow AI agents, evolve identity and access management for machine actors, modernize SOCs with human-in-the-loop processes, and shift awareness programs toward task-focused, AI-specific behavioral training.
read more →

Top Customer Identity and Access Management (CIAM) Tools

🔐 CIAM platforms manage authentication, authorization, consent, and customer identity for public-facing applications. Analysts highlight six leading solutions — IBM Security Verify, LoginRadius, Microsoft Entra, Okta/Auth0, OneLogin, and Ping Identity — each balancing usability, extensibility, and security differently. Offerings range from turnkey, no-code deployments to developer-led, API-first systems and vary in native fraud analytics, FIDO2 support, consent-management capabilities, and integrations with BI/CRM ecosystems. Organizations should weigh marketing data needs, privacy compliance, and fraud protection when choosing a CIAM.
read more →

How CISOs Lose Their Jobs: Ten Mistakes and Fixes Now

🔒 The CISO role is increasingly precarious: average tenure is 39 months and 2025 turnover climbed to 15%. The article identifies ten common career-ending mistakes — from failing to prevent or manage major breaches and poor communication with the board to inadequate compliance, weak credential controls, burnout, and resistance to change — and offers concrete mitigations. Recommended actions include a documented incident response program, business-focused risk reporting, robust governance that maps controls to regulations, and a risk-based budgeting approach. It also highlights foundational fixes such as enterprise password management (for example, Passwork) to close credential gaps, build audit trails, and demonstrate due diligence to executives and regulators.
read more →

EKS Pod Identity Integration for Add-ons Now in GovCloud

🔐 Amazon EKS now directly integrates EKS add-ons with EKS Pod Identity in AWS GovCloud (US-East and US-West), simplifying lifecycle and IAM permission management for add-ons that need access to AWS services. You can manage Pod Identities via the EKS console, CLI, API, eksctl, and IaC tools like AWS CloudFormation. This GA expansion increases the set of Pod Identity–compatible add-ons available during cluster creation.
read more →

Orchid Security Adds Continuous Identity Observability

🔎 Orchid Security has introduced an continuous identity observability platform that discovers, analyzes, and governs identity usage inside enterprise applications. The solution instruments applications to reveal embedded credentials, non‑human identities, custom authentication flows, and access paths that bypass IAM controls. It then prioritizes risks, routes findings to control owners, and integrates with IAM, PAM, and GRC workflows to drive remediation and provide continuous audit-ready evidence.
read more →