Report Reveals AWS S3 Buckets are Poorly Protected

Research from Lightspin indicates that AWS S3 Buckets are not as secure as many users may think. Lightspin, which specializes in cloud security services, inspected more than 40,000 Amazon S3 buckets and found that improperly configured AWS permissions… Continue reading Report Reveals AWS S3 Buckets are Poorly Protected

Shedding light on the threat posed by shadow admins

Few organizations would purposefully hand a huge responsibility to a junior staff member before letting them fly solo on their own personal projects, but that’s effectively what happens inside too many corporate networks: organizations delegate specifi… Continue reading Shedding light on the threat posed by shadow admins

On Authorization and Implementation of Access Control Models

There are dozens of implementations of authorization mechanisms. When there are complex requirements dictated by business processes, authorization mechanisms may often be implemented incorrectly or, at least, not optimally. The reason for that, in my o… Continue reading On Authorization and Implementation of Access Control Models

Taming the Jungle: Hardening your AWS infrastructure

After nine tutorials, sixteen posts on stack overflow, and several hours or workweeks of effort you’ve finally done it. You’ve finally got something in Amazon Web Services (AWS) to work as expected. It could have been something as simple as… Continue reading Taming the Jungle: Hardening your AWS infrastructure

The Analytic Staircase for Auditors

Building a successful audit analytics program is like climbing a staircase. The staircase is a set of steps that consist of several items having increasing levels of maturity. The staircase steps not only help you build your program, but enable …… Continue reading The Analytic Staircase for Auditors

5 Things We Need from ACL in 2018

Here’s the 5 things I’m hoping will change in 2018 regarding ACL. They are all related to each other and feed off each other… Interesting. One) The ACL Analytics user interface (UI) finds a good plastic surgeon. While I have crit… Continue reading 5 Things We Need from ACL in 2018

Quick Introduction to ACL

If you’ve every wondered what Audit Command Language (ACL) is, here’s a quick way to find out. ACL has provided a quick, one-page introduction to ACL. And I mean quick. It doesn’t explain a lot, but it gives you a … Continue rea… Continue reading Quick Introduction to ACL