Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Setting AWS Permissions Boundaries for Large Cloud Environments - A Self-Service IAM Model

fwd:cloudsec via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn how to effectively implement AWS Permissions boundaries in large-scale cloud environments through this technical conference talk from fwd:cloudsec. Explore how central security teams can empower development teams while maintaining robust security controls, focusing on Booking.com's innovative approach to permissions management. Discover the implementation of "flavored" permissions boundaries that accommodate unique security exceptions and account-level requirements while ensuring scalability. Master techniques for creating dynamic boundaries, including Global Denial Lists, Service Allow Lists, and Account Level Exceptions, all while maintaining a balance between security compliance and developer productivity. Gain practical insights into overcoming common challenges in implementing IAM models and establishing a self-service framework that supports both rapid cloud adoption and comprehensive security measures.

Syllabus

Intro
Topic
Agenda
Challenges
Machine boundary
Onesizefitsall boundary
Flavored approach
So far so good
Lets find out
Define Global Denial List
Service Allow List
Account Level Exceptions
Per Account Level Exceptions
Input Boundary List
Dynamic Statements
Enforce
Onesizefitsall
Does it scale
Developer experience
Questions

Taught by

fwd:cloudsec

Reviews

Start your review of Setting AWS Permissions Boundaries for Large Cloud Environments - A Self-Service IAM Model

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.