Home / Companies / Veza / Blog / November 2023

November 2023 Summaries

6 posts from Veza

Filter
Month: Year:
Post Summaries Back to Blog
The increasing scale and complexity of identity security due to cloud migration has led to the need for new approaches to manage risky permissions. Expired permissions are one such issue that arises when necessary permissions granted to employees or service accounts are not revoked after their purpose is fulfilled. This can happen because IAM teams prioritize urgent work over removing access no longer needed, and it's difficult to recognize expired permissions without full context. To fix this problem, organizations need to create a culture of access removal and continuously monitor for bad permissions using tools like Veza's Authorization Graph.
Nov 30, 2023 1,219 words in the original blog post.
The rapid migration of data and infrastructure to the cloud has significantly increased the scale, scope, and complexity of identity security. However, the tools used for identity security and governance have not fundamentally changed from the on-prem era, leaving security teams struggling to keep up with the rising number of identity-based attacks. This article provides a field guide to the major types of bad permissions that organizations need to be aware of in order to safeguard their critical apps and data. It focuses on ungoverned permissions, which are not captured or tracked in access governance tools like identity providers (IdP) and identity governance & administration (IGA) tools. Ungoverned permissions happen due to the existence of local accounts and local admins in SaaS apps and cloud providers that allow for standalone use. These ungoverned identities can lead to compliance failures, incident response challenges, and increased risk of data breaches. To fix ungoverned permissions, organizations need to compare the full permissions an identity has at the data end with the permissions granted through their IdP. Veza, a platform that connects to both identity providers and all data systems, can help identify and remediate ungoverned local accounts by comparing them with users in Okta or other IdPs.
Nov 21, 2023 1,219 words in the original blog post.
Veza has announced the arrival of Next-Gen IGA, a fresh approach to securing access in the enterprise amidst an expanding identity attack surface and traditional IGA tools' limitations. The new platform aims to govern access at scale by connecting to cloud services, on-prem apps, SaaS apps, and data lakes while monitoring all identities, including human and non-human ones. It also visualizes true permissions, democratizes information, and automates the monitoring, notification, and remediation of policy violations. Veza's Access Control Platform is designed to reduce identity-based risks, lower operational costs, and provide time-to-value in visibility and remediation.
Nov 20, 2023 2,312 words in the original blog post.
The shift of services and data to the cloud has led to a massive adoption of major cloud providers like AWS, with many companies relying on it as their infrastructure cornerstone. However, while the move to the cloud has been rapid, governance and security have been slower to catch up. Companies often still use processes and tools from when most sensitive data was housed on-premise in just one or two critical systems or databases. AWS allows for very granular access controls at an individual identity, role, and resource level using several policy types. Understanding effective permissions is crucial for successful access governance. Challenges to understanding effective permissions include IAM policy complexity, policy interaction, and siloed access data. Veza, a cloud-based solution, helps organizations understand the effective permissions of any local or federated identity in AWS by standardizing permissions, resolving policy conflicts, and unifying IdP and AWS IAM data.
Nov 17, 2023 996 words in the original blog post.
AWS re:Invent is approaching, and attendees can expect to learn about Veza's Access Control Platform at their booth #1371 in the Venetian Expo Center. The platform helps visualize and manage access permissions across all systems, including human and machine identities. Attendees can also schedule a personalized demo or attend a whiskey & spirits tasting event on November 28th.
Nov 06, 2023 195 words in the original blog post.
In this episode of Identity Radicals, Jenner Holden, CISO at Axon Enterprise, discusses the company's innovative security programs and their approach to cybersecurity. He highlights the importance of security reviews and access control processes, as well as the challenges of automating provisioning and deprovisioning processes. The conversation also covers compliance frameworks such as Sarban’s Oxley, SOC2, GDPR, and FedRAMP, and the intricacies of securing service accounts. Jenner shares his experience with unusual security threats and emphasizes the crucial role that resilience plays in cybersecurity. Identity Radicals is a podcast featuring interviews with cybersecurity experts, providing practical advice and actionable solutions for organizations facing security challenges.
Nov 02, 2023 430 words in the original blog post.