Home / Companies / Cloudsmith / Blog / Post Details
Content Deep Dive

OWASP CI/CD Top 10: Inadequate IAM

Blog post from Cloudsmith

Post Details
Company
Date Published
Author
Nigel Douglas
Word Count
1,379
Company Posts That Month
11
Language
English
Hacker News Points
-
Post removed?
No
Summary

In the race to ship software faster, many teams have turned to automation, decentralized tools, and powerful pipelines, but this has introduced a growing Identity and Access Management (IAM) threat vector in modern CI/CD security. This vulnerability arises from managing numerous identities across interconnected systems, including source control, build agents, artifact repositories, and deployment targets, often leading to inconsistent, outdated, or overly permissive IAM policies. Several recurring IAM security issues emerge, including overly permissive identities, stale accounts, local identities, shared credentials, and external users, which can lead to compromise of a single identity holding excessive permissions, lateral movement potential, credential sprawl, orphaned accounts, compliance gaps, and unauthorised activities. To mitigate these risks, organisations must adopt IAM best practices, such as mapping all identities, auditing external users, enforcing least privilege access, eliminating stale access, federating identity management, disabling self-registration, and prioritising IAM as a security priority in CI/CD.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 3 1,776 200 89 +33%
Platform Engineering 1 400 70 42 +16%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.