November 2024 Summaries
8 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
Veza's October product update includes enhancements and new features across its products. These updates cover Access Intelligence, Access Reviews, Lifecycle Management, and Veza Integrations. Key improvements include managing risk assignees, improved dashboard actionability, Access Portal enhancements for all users, historic decision visualization, scheduled review exports, templates for pre-set approval and rejection notes, Oracle HCM as a source of identity, new actions for ServiceNow, dry run capabilities for previewing Lifecycle Management policies results, support for Webhooks in Orchestration Actions, options for triggering workflows based on an identity's existing entitlements, and new integrations for Privacera, Cisco Duo, Device42.
Nov 22, 2024
1,547 words in the original blog post.
Veza's podcast, Identity Radicals, offers insights into managing identity security in an ever-changing cybersecurity landscape. The latest episode features a discussion between Veza's Chief Security & Trust Officer, Mike Towers, and Anthony Belfiore, Chief Strategy Officer at Wiz, exploring the enduring and emerging dynamics of identity security. They discuss how technology shifts have impacted access control strategies, the persistent risk posed by the human factor, and the importance of both authentication and authorization in maintaining security.
Nov 21, 2024
687 words in the original blog post.
SailPoint, Saviynt, and Veza are prominent players in the identity security space, offering solutions for managing and securing user access to applications and data. Identity-based incidents accounted for 64% of all investigated in 2023, highlighting the importance of a robust identity security strategy. When considering an identity security solution, it's crucial to consider factors such as ease of implementation, scalability, accuracy, and management of on-premise and cloud environments. Veza stands out as the superior choice with its next-generation approach to identity governance, leveraging authorization metadata for real-time monitoring, automated access reviews, and proactive security measures that eliminate blind spots and reduce risk. Veza's rapid deployment and extensive integration capabilities make it an efficient and scalable solution for modern enterprises.
Nov 15, 2024
2,740 words in the original blog post.
The past two decades of enterprise security have shown that promising technologies often fall short due to gaps in organizational operationalization rather than technical limitations. In the complex identity security landscape, this lesson remains critical. Modern identity security platforms offer powerful capabilities such as visibility across entire technology stacks, but visibility alone doesn't solve problems; it often just makes them more apparent. Operationalizing these platforms requires a methodical approach that builds value incrementally, with key phases including initial visibility and quick wins, intelligence-driven governance, and proactive risk management. Value generation in modern identity security follows two distinct but complementary paths: security/risk reduction and governance/compliance. Successful integration of legacy systems is essential for comprehensive identity security implementation. Modern identity security platforms drive value across multiple dimensions, creating a comprehensive improvement in security posture and operational efficiency. Effective programs balance dual security and governance paths while maintaining focus on progressive value creation.
Nov 11, 2024
1,187 words in the original blog post.
Privileged accounts are common in modern business environments, but they also attract cybercriminals. Organizations have traditionally used privileged access management (PAM) solutions to protect against credential theft and privilege misuse. However, PAM tools have limitations, particularly in managing and monitoring access across various cloud platforms and handling the scale and complexity of contemporary IT infrastructure. As a result, organizations need more than just a PAM solution to address all security risks. They require a comprehensive approach that includes creating a formal PAM policy, implementing the principle of least privilege, conducting regular access reviews, reducing app sprawl, providing security education, and addressing blind spots such as accidental over-provisioning, identifying privileged users, monitoring non-privileged accounts, and managing decentralized access. Organizations need an intelligent access tool that goes beyond traditional PAM solutions to visualize who has access to what, automate access reviews, and investigate identity threats quickly.
Nov 09, 2024
4,192 words in the original blog post.
High-profile data breaches have increased in frequency, leading to a greater focus on data security for businesses. Service Organizations Control (SOC) reports, particularly SOC 2, are becoming essential benchmarks for organizations to demonstrate their commitment to protecting customer data. A SOC 2 report evaluates an organization's information security measures and focuses on protecting customer data, privacy, and networks against vulnerabilities. The SOC 2 audit process involves assessing the design of controls related to security, availability, processing integrity, confidentiality, and privacy. Organizations can choose between two types of reports: Type I (a snapshot of an organization's systems at a specific point in time) and Type II (an analysis of these controls over a longer period). The SOC 2 framework is based on the Trust Services Criteria (TSC), which include security, availability, processing integrity, confidentiality, and privacy. Achieving SOC 2 compliance can help strengthen an organization's security posture, gain a competitive edge, expedite deal closures, and attract new business.
Nov 08, 2024
3,593 words in the original blog post.
Lifecycle management is crucial for protecting company data and ensuring compliance with regulations like SOX, GDPR, and PCI DSS. It involves creating, adjusting, and deleting digital identities based on changing circumstances. Key elements of lifecycle management include provisioning, automated monitoring, role-based access control (RBAC), and deprovisioning. Lifecycle management helps organizations automate access and permission management, improve security posture, streamline audits and compliance, and reduce manual work. Challenges such as app sprawl, access debt, over-permissioned accounts, inappropriate access, and limited visibility can be mitigated through proper implementation of lifecycle management strategies.
Nov 08, 2024
1,925 words in the original blog post.
Identity governance and administration (IGA) solutions are crucial for organizations to manage human and non-human access using policy-driven approaches. These solutions combine identity and access information from various IT systems to improve security and meet compliance obligations. IGA software platforms typically offer features such as identity lifecycle management, access governance and certification, individual role management, access requests and approvals, policy enforcement, audit, and compliance reporting. Common vendors of IGA software include Veza, SailPoint, Okta, One Identity, Oracle Identity Governance, Saviynt Enterprise Identity Cloud, Omada Identity, IBM Security Verify, SAP Cloud Identity Access Governance, Fischer Identity, Ping Identity, and RSA.
Nov 08, 2024
3,712 words in the original blog post.