A global e-commerce company uses Prisma Cloud CIEM to manage identity permissions across its AWS and GCP environments. Due to a recent data breach in a competitor, the CISO has mandated a proactive measure: all identities (users, roles, service accounts) that have not accessed any resources for the past 90 days must have their permissions automatically suspended or revoked. Which CIEM policy and remediation combination would be most efficient to implement this mandate?
- AA DSPM policy to encrypt data accessed by inactive identities and generate alerts.
- BA CIEM policy identifying inactive identities based on usage data, linked to an automated 'suspend permissions' workflow.
- CA network security policy to block inactive IP addresses from accessing cloud resources.
- DA CSPM policy to detect unused cloud resources and a manual review process.
Show answer & explanationAnswer & explanation
Correct answer: B. A CIEM policy identifying inactive identities based on usage data, linked to an automated 'suspend permissions' workflow.
This scenario directly calls for CIEM's ability to analyze identity usage data to identify inactive identities and then trigger automated remediation. A CIEM policy can be configured to flag identities with no activity for 90 days, and an integrated automated workflow can then suspend or revoke their permissions, fulfilling the CISO's mandate efficiently.
Why the other options are wrong
- A. DSPM manages data security, not the suspension/revocation of identity permissions based on inactivity.
- C. Network policies manage network access, not identity permissions based on usage.
- D. CSPM focuses on resource configurations, not identity usage, and manual review isn't efficient for thousands of identities.
Inactive Identity Remediation
The automated process of identifying identities (users, roles, service accounts) that have not been active for a defined period and subsequently revoking or suspending their permissions to reduce attack surface.
- Reduces dormant accounts risk
- Automates least privilege enforcement
- Improves security posture over time
Memory trick: If it's not used, lose the access.