Security News > 2022 > March > The challenge of planning an IAM strategy for multi-cloud environments to avoid risk
28% of companies are using four or more public/private clouds today, but that is expected to more than double in two years to 65%. "As cloud service providers improve their security and data protection offerings, decision-makers increasingly realize they can't protect their firms' data on-premises as well as they can in the cloud. But migrating existing IAM tools and processes to multicloud IaaS, PaaS, and private clouds creates problems that firms must solve" according to the Forrester study.
"According to the Forrester study, firms can't just lift-and-shift existing IAM tools from on-premises to the cloud," said Eric Olden, CEO of Strata Identity.
"Multi-cloud ecosystems are complex and create a broader attack vector, so companies must plan their IAM strategy carefully or risk leaving themselves vulnerable."
The most significant and commonly reported cloud IAM challenges are not having enough time and money and a lack of skills to support complex cloud-based IAM. In addition, organizations struggle to manage and enforce consistent user policies and comply with changing regulations, while lack of interoperability between IAM solutions and different clouds, siloed identity user groups, and rewriting apps to modernize or migrate to the cloud were other key concerns.
The two top IAM cloud security practices employed by IT departments are IAM governance and IAM in the cloud.
Finally, 85% of respondents agree that having a low-code/no-code solution for IAM would allow an easier adoption of a zero trust posture, and three of the top requirements for cloud IAM cited by respondents were low-code tools that don't require them to rewrite apps, automate IAM across multiple clouds, and integrate cloud and on-premises identity platforms.
News URL
https://www.helpnetsecurity.com/2022/03/25/managing-user-identities-clouds/
Related news
- Multi-cloud Strategies Making DDI and DNS Cumbersome to Manage (source)
- Strategies for CISOs navigating hybrid and multi-cloud security (source)
- 5 Steps to Boost Detection and Response in a Multi-Layered Cloud (source)
- Google Cloud to Enforce Multi-Factor Authentication by 2025 for All Users (source)