flâneur — a map of the web's best reading

State of Cloud Security | Datadog

datadoghq.com · 3,260 words · saved by 1 readers

Securely configuring the potentially thousands of cloud identities, workloads, and other resources needed to support the high pace of modern software development is difficult—but also critical to prevent attackers from breaching these systems, where security gaps too often go unnoticed. For this report, we analyzed security posture data from a sample of thousands of organizations that use AWS, Azure, or Google Cloud. In particular, we focused on understanding how organizations approach and mitigate common risks that frequently lead to documented public cloud security incidents. (A detailed methodology is available in the annex.) Our findings suggest that, while some elements of strong cloud security posture show signs of improvement, organizations still face significant challenges. These include managing static, long-lived credentials; securely configuring user roles, access, and privileges within cloud resources; and enforcing best-practice safeguards such as multi-factor authenticati

Fact 1 Multi-account environments allow organizational guardrails in AWS Enforcing minimal privileges in a single AWS account is challenging. Similarly, running workloads from the different stages (dev, prod) in the same AWS account can be difficult due to quota, IAM, network, and performance issues. This is why a common best practice, both from a security and operational perspective, is to have multiple AWS accounts centrally managed through AWS Organizations , a governance service offered by AWS. Note that an “AWS organization” refers to one grouping of AWS accounts within this service and i

Explore this link on the map →

related reading