This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Identity Perimeter in Cloud Native: A CIEM Focused Approach to CNAPP

Download resources

About this session

Frank Passman, a cloud security strategist at Tenable, argues that identity, not any single vulnerability or misconfiguration, is the common thread behind most cloud breaches, citing that 80% of organizations suffered an identity-related breach in the past year and describing a $270 million loss traced to an exposed, overprivileged S3 bucket. He frames most breaches as needing a 'three-legged stool' of a vulnerability, a misconfiguration and excess privilege, and walks through why point tools for CSPM, workload protection, Kubernetes posture and cloud detection fail to give context on their own, arguing for aggregating exposures instead of chasing every acronym (CNAPP, CIEM, DSPM, AI security posture management). The bulk of the talk covers cloud infrastructure and entitlement management (CIEM): mapping IAM roles and entitlements across AWS, Azure, GCP and Entra ID, auto-remediating overprivileged access through pull requests against Terraform or CloudFormation, and moving toward just-in-time access that grants and automatically revokes time-boxed privileges. An extended audience Q&A covers how just-in-time access integrates with PAM tools like CyberArk, how Tenable's CNAPP differs from Check Point's, on-premises container and Active Directory scanning, and integrations with ServiceNow and CI/CD pipelines.

Deciphering the wordsoup of Cloud Security Acronyms and focusing on what is important.

Key takeaways

  • Treat identity as the foundational layer of cloud security, since most breaches combine a vulnerability, a misconfiguration and excess privilege, and identity touches every asset.
  • Audit which admin-level identities actually have MFA enforced; unused or rogue accounts without MFA are a recurring root cause in real breaches.
  • Move toward just-in-time access: grant time-boxed privileges on request through an approval workflow (Slack, Teams) and auto-revoke them after a set window.
  • Aggregate CSPM, workload protection, IAM, KSPM and cloud detection data into one context instead of running disconnected point tools that each report in isolation.
  • Auto-remediate overprivileged IAM configurations through pull requests against Terraform or CloudFormation so fixes apply to both current and future infrastructure builds.

Speakers

Frank Passman
Frank Passman
Cloud Security Strategist · Tenable
Frank has spent the last 9 years with Tenable serving as a trusted advisor to organizations deploying exposure management solutions utilizing risk-based prioritization to increase operational efficiency and reduce exposures across the modern attack… Read moreRead less

Frank has spent the last 9 years with Tenable serving as a trusted advisor to organizations deploying exposure management solutions utilizing risk-based prioritization to increase operational efficiency and reduce exposures across the modern attack surface. In his current role he provides insights and recommendations to organizations on how to proactively harden their cloud environments by focusing on infrastructure and entitlements and how they are foundational in securing multi-cloud hybrid environments.

Resources

Tags

More from GoSec 2024

Also from Frank Passman

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.