Knowledge Article
Cloud infrastructure entitlement management milestone
Author
ryan_cutter
SailPoint
Cloud Infrastructure Entitlement Management (CIEM) strengthens identity governance by providing thorough oversight of users' cloud access rights to resources and their entitlement activities within the cloud infrastructure. It offers visibility into who can access what resources across both single-cloud and multi-cloud environments.
1
Foundational Visibility
Resources:
Advice:
Focus on identifying all possible cloud providers managed within your organization. This will bring visibility into accounts and service privileges within the cloud infrastructure and their cloud service usage. It helps identifying over-privileged access, excessive permissions, and unused entitlements, reducing the risk of security breaches.
After configuring your Cloud Service Providers connectors and enable cloud entitlements, CIEM gives visibility on accounts associated with human identities have to your cloud infrastructure through OOTB reports such as:
- Cloud Resource Access
- Cloud Scope Status Reports
- Cloud Management Activity
Pitfalls:
- By not identifying all cloud providers and the resources and access rights granted, can create a false sense of security causing to overlook critical security gaps as well as leaving those cloud environments exposed and vulnerable.
- Increases security risks due to unaddressed excessive permissions and unused entitlements. It also results in compliance issues by failing to enforce the principle of least privilege and a lack of visibility across cloud platforms, hindering effective user access tracking.
2
CIEM Access Intelligence Center
Resources:
Advice:
CIEM Access Intelligence Center (AIC) empowers organizations to strengthen and uphold a least-privilege security model for accessing cloud infrastructure. Using the Business Intelligence tool, organizations can analyze and visualize data through user-friendly charts and dashboards of their cloud access and various identity-related actions taken against cloud resources.
Pitfalls:
- The size and quantity of the reports can make it difficult for customers to download and, in some cases, even open them in client spreadsheet tools. Additionally, the zipped files contain numerous individual comma-separated files that necessitate either combining them or generating custom pivot reports.
3
CIEM Machine Identity Security
Resources:
Advice:
CIEM MIS provides effective access visibility into Azure Service Principals and Google Cloud Service Accounts.
Pitfalls:
- IAM administrators and machine identity owners currently lack visibility into the cloud services accessible by Azure and GCP machine identities, which impairs decision-making and efforts to optimize resource allocation.