February 2025 Summaries
5 posts from Veza
Filter
Month:
Year:
Post Summaries
Back to Blog
In a recent podcast episode, Josh de Fido, Workday's Chief Information Security Officer, shared insights on evolving identity security challenges and the importance of implementing least privilege access at scale. With 15 years of experience in leading security at Workday, Josh emphasized that identity has become the front line of security due to sophisticated cyber threats. He noted that managing identity security at scale is crucial for organizations handling sensitive data, particularly financial and HR information, and that ensuring robust identity governance is essential for preventing breaches. Josh also highlighted the need for continuous adaptation in security strategies to address rapidly evolving regulations and the intersection of security and privacy. Looking ahead, he sees exciting opportunities and increasing complexity in identity security, with AI and machine learning playing a growing role in enhancing security but introducing new complexities.
Feb 27, 2025
585 words in the original blog post.
Veza has released several enhancements across its product suite in the November product update, including significant improvements to Access Intelligence, which now includes risk mitigation burndown charts and enhanced dashboards for tracking resolution trends. The company has also made major usability improvements to Access Reviews, Separation of Duties (SoD), and added new integrations with Ivanti Neurons, Device42, Cisco Duo, Zoom, and Exchange Online. Additionally, Veza has introduced enhancements to its Lifecycle Management feature, including support for Oracle HCM, Exchange Online, and Ivanti Neurons, as well as improved Access Profile Intelligence. The update also includes several search enhancements, such as the ability to view natural language explanations of selected paths in Graph Search, and improved performance when visualizing relationships between authorization entities. Overall, these updates aim to improve Veza's capabilities for managing access, security, and identity management.
Feb 24, 2025
1,710 words in the original blog post.
NIST compliance is a crucial aspect of a resilient cybersecurity strategy, providing numerous benefits including improved security, increased trust, regulatory alignment, and competitive advantage. To achieve NIST compliance, organizations must identify and analyze risks, implement access control strategies, prioritize identification and authentication, create and document incident response plans, include physical protection, offer security training, assess security effectiveness, and implement continuous monitoring and maintenance. However, achieving NIST compliance can be complex and requires significant resources, including time, money, and personnel. Organizations must also consider the challenges of complexity, resource allocation, continuous monitoring and maintenance, integration with existing systems, managing subcontractors and third parties, and adopting best practices such as comprehensive identity management, access visibility and monitoring, Zero Trust Architecture, strong authentication mechanisms, regular access reviews and audits, automated compliance reporting, and least privilege access. When comparing NIST compliance to other security frameworks like ISO, SOC 2, CIS, and COBIT, it is essential to understand the unique focus and strengths of each framework.
Feb 13, 2025
2,703 words in the original blog post.
The Veza product update includes several new features and enhancements across various products, including Access Visibility, Access Intelligence, Lifecycle Management, and Access Requests. Non-Human Identities (NHI) security has been improved with the addition of new dashboards, owner accountability features, and extended monitoring capabilities. Access Reviews now support instantiating on-demand reviews triggered by Lifecycle Management workflows, and administrators can configure auto-expiration settings for past due reviews. The catalog in the Access Hub has been redesigned for a more intuitive search experience, and integrations have been added or updated with new features such as Salesforce integration discovery of Connected Applications and Docusign support for multiple accounts. Additionally, improvements have been made to APIs for Snowflake Least Privilege Implementation, Okta Activity Dashboard, and Traceability for API-based Query Changes.
Feb 13, 2025
2,243 words in the original blog post.
Managing access requests has become increasingly challenging due to the exponential growth of apps and systems. Without a strategic approach, businesses risk data leaks, privilege creep, orphaned accounts, and compliance issues. A well-designed access request process is essential to streamline workflows, improve security, and maintain compliance. Key components include creating comprehensive access control policies, conducting regular access reviews and audits, automating user lifecycle management, implementing separation of duties (SoD), establishing audit trails, and utilizing automated access request tools. By leveraging AI-powered automation, businesses can modernize their access request processes, reduce security risks, and make access requests faster, smarter, and more secure.
Feb 03, 2025
3,737 words in the original blog post.