03/17/2022
- Is speed critical to you? Is security as important as your business logic?
Here are some simple steps you can take in the early stages to ensure you are following cloud security posture and avoid service disruption.
๐จ ๐๐๐๐๐ ๐๐๐๐๐๐๐ ๐๐ ๐จ๐พ๐บ ๐๐
๐๐๐๐๐๐ ๐๐๐๐๐๐๐๐๐๐:
๐ IAM users are individuals who needs access to your AWS account
๐ IAM systems users are third party apps that needs access to perform functions such as CI/CD
๐ IAM roles are similar to IAM users except that a role is intended to be assumable by anyone who needs it ( For eg: a user can assume a role to get ๐ access to a staging account to test changes ). It is important to leverage IAM roles because a compromised users credentials can have greater impact.
๐ฏ๐๐๐ ๐๐๐ ๐๐๐๐ ๐๐๐๐ ๐๐๐๐๐๐๐๐๐ ๐๐๐๐ ๐๐ ๐๐๐๐๐๐๐๐๐
:
โ
Usage of strong password policies
โ
Regular credential rotation
โ
Follow least privilege principles
โ
Never share any access keys
โ
Use a secret store such as secrets manager or vault for system users
โ
Adopt Single Sign On for central identity management
โ
Run periodic scans on your codebase to make there are no hard-coded access credentials.
Lastly it is important that you audit user logins and use central logging to track all malicious attacks. Security is a shared responsibility and implementing these best practices early on can reduce the risk cyber attacks and enable you scale faster.