Forum Moderators: open

Message Too Old, No Replies

Cloud Threat Report: "Lack of Proper Identity Management"

         

engine

3:00 pm on Apr 12, 2022 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



Unit 42 at Paloalto Networks has published a security report detailing the threats made worse by the extended use of the Cloud.

The research consisted of analyzing "680,000+ identities across 18,000 cloud accounts from 200 different organizations to understand their configuration and usage patterns."

The findings don't look good with the inadequate identity and access management (IAM) policy and controls, resulting in security issues. The report said, "Nearly all organizations we analyzed lack the proper IAM management policy controls to remain secure. "

It identified IAM as the opportunity for bad actors to take advantage, with four key points.


  • Password reuse: 44% of organizations allow IAM password reuse.
  • Weak passwords (<14 characters): 53% of cloud accounts allow weak password usage.
  • Cloud identities are too permissive: 99% of cloud users, roles, services, and resources were granted excessive permissions which were ultimately left unused (we consider permissions excessive when they go unused for 60 days or more).
  • Built-in cloud service provider (CSP) policies are not managed properly by users: CSP-managed policies are granted 2.5 times more permissions than customer-managed policies, and most cloud users prefer to use built-in policies. Users are able to reduce the permissions given, but often don’t.


  • It's worth a read, imho.

    [unit42.paloaltonetworks.com...]

    graeme_p

    4:02 pm on Apr 12, 2022 (gmt 0)

    WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



    Weak passwords are less of a problem if you use 2FA.

    The big cloud services IAM (at least the two I have used) are complicated. Unless you are an expert in the particular cloud you are using, its very difficult to configure correctly.

    engine

    11:04 am on Apr 13, 2022 (gmt 0)

    WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



    Weak passwords are less of a problem if you use 2FA.


    However, if they use the same password on something else without 2FA...

    Yes, it's complicated, but it's also good management to devise IAM, no matter how small the system.
    It's just reminded me to take action in one area that has been neglected.

    Sgt_Kickaxe

    10:43 pm on Apr 13, 2022 (gmt 0)



    Now more than ever you want to review EVERY site or service you have ever needed an account, username or password to access.

    If you don't need it, delete it.