• Latest
  • Trending
  • All
  • News
  • Business
  • Politics
  • Science
  • World
  • Lifestyle
  • Tech
How CISOs get multicloud security right with CIEM

How CISOs get multicloud security right with CIEM

November 30, 2022
Putin cleared way for Ukraine to join Nato: Johnson

Putin cleared way for Ukraine to join Nato: Johnson

January 30, 2023
Tyre Nichols’s Parents to Attend State of the Union Address

Tyre Nichols’s Parents to Attend State of the Union Address

January 30, 2023
MSNBC Host Confronts Matt Gaetz Over ‘Pardon’ Testimonies

MSNBC Host Confronts Matt Gaetz Over ‘Pardon’ Testimonies

January 30, 2023
Cindy Williams, Shirley of ‘Laverne & Shirley’ Fame, Dies at 75

Cindy Williams, Shirley of ‘Laverne & Shirley’ Fame, Dies at 75

January 30, 2023
The 10 Best New Movies and Shows Coming to Netflix in February

The 10 Best New Movies and Shows Coming to Netflix in February

January 30, 2023
Two More Memphis Police Officers Are Suspended in Tyre Nichols’s Death

Two More Memphis Police Officers Are Suspended in Tyre Nichols’s Death

January 30, 2023
2 monkeys missing from Dallas Zoo believed to have been taken, police say

2 monkeys missing from Dallas Zoo believed to have been taken, police say

January 30, 2023
Memphis Fire Department fires three following Tyre Nichols death

Memphis Fire Department fires three following Tyre Nichols death

January 30, 2023
Biden plans to end the Covid public health emergency this spring in a major shift to federal response

Biden plans to end the Covid public health emergency this spring in a major shift to federal response

January 30, 2023
Nina Ali Exits ‘The Real Housewives Of Dubai’ After 1 Season

Nina Ali Exits ‘The Real Housewives Of Dubai’ After 1 Season

January 30, 2023
2 Monkeys Are Apparently Taken in Latest Bizarre Incident at Dallas Zoo

2 Monkeys Are Apparently Taken in Latest Bizarre Incident at Dallas Zoo

January 30, 2023
Academic Freedom Group Decries Black Professor’s ‘Racist’ Firing

Academic Freedom Group Decries Black Professor’s ‘Racist’ Firing

January 30, 2023
DNYUZ
  • Home
  • News
    • U.S.
    • World
    • Politics
    • Opinion
    • Business
    • Crime
    • Education
    • Environment
    • Science
  • Entertainment
    • Culture
    • Music
    • Movie
    • Television
    • Theater
    • Gaming
    • Sports
  • Tech
    • Apps
    • Autos
    • Gear
    • Mobile
    • Startup
  • Lifestyle
    • Arts
    • Fashion
    • Food
    • Health
    • Travel
No Result
View All Result
DNYUZ
No Result
View All Result
Home News

How CISOs get multicloud security right with CIEM

November 30, 2022
in News
How CISOs get multicloud security right with CIEM
510
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

More CISOs will have to deliver revenue growth to protect their budgets and grow their careers in 2023 and beyond, and a core part of that will be getting multicloud security right. It’s the most common infrastructure strategy for rejuvenating legacy IT systems and clouds while driving new revenue models. As a result, multicloud is the most popular cloud infrastructure, with 89% of enterprises relying on it, according to Flexera’s 2022 State of the Cloud Report. 

Organizations and the CISOs running them often decide to pursue a multicloud strategy based on the improved availability of resources and best-of-market innovations available, as it helps them meet compliance requirements more efficiently and gain greater bargaining parity during cloud provider negotiations. CISOs have told VentureBeat in previous interviews that multicloud is also an excellent way to avoid vendor lock-in. Large-scale enterprises also look to gain more excellent geographical coverage of their global operations. 

The more multicloud proliferates, the greater the need to enforce least-privileged access across every cloud instance and platform. That’s one of the main reasons why CISOs need to pay attention to what’s happening with cloud infrastructure entitlement management (CIEM). 

Defining CIEM 

Gartner defines CIEM as a software-as-a-service (SaaS) solution for managing cloud access by monitoring and controlling entitlements. It said CIEM uses “analytics, machine learning (ML), and other methods to detect anomalies in account entitlements, like accumulating privileges and dormant and unnecessary entitlements. CIEM ideally provides remediation and enforcement of least privilege approaches.” 

Multicloud is a major zero-trust challenge 

Every cloud hyperscaler has a unique approach to solving their platforms’ IAM, PAM, microsegmentation, multifactor authentication (MFA), single sign-on (SSO), and other main challenges their customers face in attempting to implement a zero-trust network access (ZTNA) framework on and across platforms. 

Gartner predicts that inadequate management of identities, access and privileges will cause 75% of cloud security failures by 2023. The more complex a multicloud configuration, the more it becomes a minefield for zero-trust implementation. CISOs and their teams often rely on the Shared Responsibility Model in briefings and as a planning framework for defining who is responsible for which area of the multicloud tech stacks. 

Many enterprises rely on the Amazon Web Services version because of its straightforward approach to defining IAM. With each hyperscaler providing security just for their platform and tech stacks, CISOs and their teams need to identify and validate the best possible IAM, PAM, microsegmentation, and multifactor authentication (MFA) apps and platforms that can traverse across each hyperscalers cloud platform.

“Existing cloud security tools don’t necessarily address specific aspects of cloud infrastructure,” Scott Fanning, senior director of product management and cloud security at CrowdStrike, told VentureBeat. “Identity isn’t necessarily buried into that DNA as well, and the cloud providers themselves have added so much granularity and sophistication in their controls,” he continued. 

One of CIEM’s design goals is to help close the gaps between multiclouds by enforcing least-privileged access, removing any implicit trust of endpoints and human and machine identities. The goal is to eradicate implicit trust from multicloud infrastructure. That isn’t easy to do without an overarching governance platform, which is one of the reasons CIEM is gaining market momentum today. 

The more complex a multicloud configuration, the more challenging it becomes for experienced staff to manage, with errors becoming more commonplace. As a result, CIEM advocates point to the need to automate scale governance and configuration monitoring to alleviate human errors. 

Gartner predicts this year that 50% of enterprises will unknowingly and mistakenly expose some applications, network segments, storage, and APIs directly to the public, up from 25% in 2018. In addition, the research firm predicts that by 2023, 99% of cloud security failures will result from manual controls not being correctly configured. 

Why CIEM’s importance is growing 

Getting in control of cloud access risk is what drives the CIEM market today. CISOs rely on risk-optimization scenarios to balance their budgets, and the value CIEM delivers makes it part of the budgeting mix. In addition, by providing time controls for the governance of entitlements in hybrid and multicloud IaaS environments, CIEM platforms can enforce least privilege at scale. 

Leading CIEM vendors include Authomize, Britive, CrowdStrike, CyberArk, Ermetic, Microsoft (CloudKnox), SailPoint, Saviynt, SentinelOne (Attivo Networks), Sonrai Security, Zscaler and others. 

Advanced CIEM platforms rely on machine learning (ML), predictive analytics, and pattern-matching technologies to identify anomalies in account entitlements, such as accounts accumulating privileges that have been dormant and have unnecessary permissions. From a zero-trust perspective, CIEM can enforce and remediate least-privileged access for any endpoint, human or machine identity.  

Fanning said CrowdStrike’s approach to CIEM enables enterprises to prevent identity-based threats from turning into breaches because of improperly configured cloud entitlements across public cloud service providers. He told VentureBeat that one of the key design goals is to enforce least-privileged access to clouds and provide continuous detection and remediation of identity threats. 

“We’re having more discussions about identity governance and identity deployment in boardrooms,” he told VentureBeat during a recent interview. 

Five reasons why CIEM will continue to gain adoption

CISOs pursuing a ZTNA strategy are out for quick wins, especially with budgets on the line today. CIEM is showing that it has the potential to deliver measurable results in five key areas. 

  • Predicting and preventing identity-based threats across hybrid and multicloud environments delivers measurable results that are being used to quantify risk reduction. 
  • CIEM is also proving effective at visualizing, investigating and securing all cloud identities and entitlements. 
  • CISOs tell VentureBeat that CIEM is simplifying privileged-access management and policy enforcement at scale. 
  • CIEM makes it possible to perform one-click remediation testing before deployment on the most advanced platforms. 
  • CIEM can integrate and remediate fast enough to not slow devops down.

The post How CISOs get multicloud security right with CIEM appeared first on Venture Beat.

Share204Tweet128Share

Trending Posts

Biden to end Covid health emergency declarations in May

Biden to end Covid health emergency declarations in May

January 30, 2023
I.M.F. Upgrades Global Outlook as Inflation Eases

I.M.F. Upgrades Global Outlook as Inflation Eases

January 30, 2023
Man who drove Tesla off cliff with family inside charged with attempted murder

Man who drove Tesla off cliff with family inside charged with attempted murder

January 30, 2023
Texas names border czar who wants to make state ‘least desirable place for illegal immigration’

Texas names border czar who wants to make state ‘least desirable place for illegal immigration’

January 30, 2023
Trump Argues the Value of Hearing His Own Voice in $49M Bob Woodward Suit

Trump Argues the Value of Hearing His Own Voice in $49M Bob Woodward Suit

January 30, 2023

Copyright © 2023.

Site Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

No Result
View All Result
  • Home
  • News
    • U.S.
    • World
    • Politics
    • Opinion
    • Business
    • Crime
    • Education
    • Environment
    • Science
  • Entertainment
    • Culture
    • Gaming
    • Music
    • Movie
    • Sports
    • Television
    • Theater
  • Tech
    • Apps
    • Autos
    • Gear
    • Mobile
    • Startup
  • Lifestyle
    • Arts
    • Fashion
    • Food
    • Health
    • Travel

Copyright © 2023.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT