5 ms·
what about hacked employees' aws accounts?
by compootr 2y ago
what about hacked employees' aws accounts?
- mlyle 2y agoUnless they're highly privileged enough to turn on read access to the bucket, you're fine. Thus, you can contain most breaches of credentials.
- viraptor 2y agoEmployees shouldn't have default access to those credentials. This applies to audit/backup/account management/billing privileges. You can have very dedicated roles with lots of restrictions for those specific things.
- atkailash 2y ago[dead]
- inkyoto 2y agoIf the organisation doesn't use SSO coupled with MFA and the enforcement of the least amount of privileges principle on a cloud platform, then they have no right to complain about security breaches.