The principle of least privilege

Concetti di sicurezza e gestione dei costi su AWS

Dev Bhosale

Principal Data & Cloud Architect

What is the principle of least privilege?

  • Separate access to employees by department and capabilities
  • Grant the narrowest set of privileges
  • Do not grant more privileges than necessary to perform job responsibilities

The principle of least privilege

Concetti di sicurezza e gestione dei costi su AWS

Balancing the goal

Balancing the goal

Concetti di sicurezza e gestione dei costi su AWS

Strategies for least privilege

Five step implementation plan

Concetti di sicurezza e gestione dei costi su AWS

Account security framework

  • Root user security is critical
  • grant least necessary privileges to users, groups, and computing resources
  • Develop a process for credential sharing

Account security framework

Concetti di sicurezza e gestione dei costi su AWS

Root user security

Root user security

  • Use a strong root user password
  • Use multi-factor authentication
  • Don't create access keys
  • Use multi-person approval and group email
Concetti di sicurezza e gestione dei costi su AWS

User and group security

  • Enable MFA for all IAM users
  • Use groups to assign permissions, not individuals
  • Apply the principle of least privilege to all accounts
  • Regularly rotate passwords and access keys
Concetti di sicurezza e gestione dei costi su AWS

Resource security

  • Improve visibility and control
  • Maintain instance compliance against your patch, configuration, and custom policies
  • Automate configuration and ongoing management of your applications

Systems manager

Concetti di sicurezza e gestione dei costi su AWS

Credential security

Secrets manager

  • Manage database credentials securely
  • Rotate secrets automatically
  • Encrypt API keys
  • Integrate with AWS services
Concetti di sicurezza e gestione dei costi su AWS

Let's practice!

Concetti di sicurezza e gestione dei costi su AWS

Preparing Video For Download...