Discussion about this post

User's avatar
Adrian's avatar

CSPM and DSPM are designed and built in response to unique challenges with public cloud. IAM -- at large -- is the most complex, challenging and important security component for cloud. Many of the CSPM and DSPM vendors already offer a basic User to Endpoint mapping capability to illustrate what services can be reached, so I would argue that Identity piece is already in play. But when coupled with entitlements complexity, and the use of managed identities representing the machine/service, it's hard for mortals to understand the complexity of blast radius. We can reduce scope / complexity with micro-segmentation _on the data network_ but services APIs may have universal availability. I offer that IAM as a whole is the missing link for security posture.

No posts

Ready for more?