3 ms·
IMO, there is no simple answer, since many access control elements are involved and implementations vary between organizations. From my experience I would say
by MiguelHzBz 4y ago
IMO, there is no simple answer, since many access control elements are involved and implementations vary between organizations.
From my experience I would say that there may be different factors:
- Every developer is an exception
- IAM is challenging to scale
- Lazy IT Teams?
- Visibility of access controls are poor
Some useful references:
- https://sysdig.com/blog/identity-access-management-difficult-cloud/ https://sysdig.com/blog/identity-access-management-difficult...
- https://www.effectiveiam.com/why-aws-iam-is-so-hard-to-use https://www.effectiveiam.com/why-aws-iam-is-so-hard-to-use
- https://aws.amazon.com/blogs/security/iam-access-analyzer-makes-it-easier-to-implement-least-privilege-permissions-by-generating-iam-policies-based-on-access-activity/ https://aws.amazon.com/blogs/security/iam-access-analyzer-ma...