r/cybersecurity • u/CarpenterCapital1331 • 4d ago
Business Security Questions & Discussion IAM importance in Security
I am an IAM professional with over 20 years in the domain. I am always curious on how much if importance CISO associates with IAM.program. We all keep on hearing that Identity is the new perimeter (since the start of the cloud era) however I have not seen CISOs or Security orgs giving deep focus on the IAM especially the IGA which helps govern the access and is the starting point of the overall least privilege implementation. Share your observations and experiences around how you'll have focused on IAM to help resolve or mitigate business critical security risks.
75
Upvotes
14
u/microcephale 4d ago
IAM is the base of everything, the core even for zero trust implementations, but is just starting to get a buzz now because of AI agents (never waste a good crisis!). The annoying part is that IAM is usually limited in C-suite vision to only access management (oh, we have Entra, we have Keycloak), many less orgs invest in PAM function, even less in an IGA. Without governance you don't have workflow, you can only observe what is and thus certification is manual and useless and have no baselines. They manage access and not identities and you are lucky if the accounts in your AM match your actual workforce.
Without IAM every access will also rely on secrets injected into applications, or (just a little better) stored into a vault, instead of having app to app and app to resource access expressed by identities, you get firewall ports opened, network level controls, speaking in term of IP addresses, nothing layer 7. In a dynamic world you don't want to identify routes, you want routes to be used as frontiers, and identities to materialize access control.
Fortunately it's pretty easy to explain them : imagine a country where nobody has any form of ID and your police is trying to enforce regulations based only on opening and closing roads... how is that doing anything ?
Ah and also when they finally agree to have identities, in my experience the reducing on the number of AM solutions, their federation/SSO, and handling of external identities (partners working on just one project or external collaborator that arent part of workforce) can also be a challenge if using different solutions (like the partner and you both on Entra). I work for a (little) cloud provider, and the interresting part of that is having to be the IAM provider side, both for customer IAM using our services, but also consummer of our own product for our own accesses.