Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Cloud Infrastructure Entitlement Management (CIEM)Medium
A global organization is leveraging Prisma Cloud CIEM to manage identity permissions across a complex multi-cloud environment. They currently have thousands of custom IAM policies defined across AWS, Azure, and GCP, leading to significant management overhead and potential for misconfigurations. To simplify management and enhance security, they want to standardize their permissions using a common framework. Which CIEM approach would best facilitate this standardization?
- AImplementing a strict 'deny-all' policy for all new identities.
- BUtilizing policy templates and a policy-as-code approach within CIEM.
- CMigration to a centralized identity provider (IdP) for all authentication.
- DManual review and consolidation of all existing policies.
Show answer & explanationAnswer & explanation
Correct answer: B. Utilizing policy templates and a policy-as-code approach within CIEM.
Utilizing policy templates and a policy-as-code approach within CIEM allows organizations to define standardized, reusable permission sets that can be consistently applied across different cloud providers. This simplifies management, reduces errors, and ensures uniformity, directly addressing the challenge of thousands of custom policies.
Why the other options are wrong
- A. A 'deny-all' policy is a starting point for least privilege but doesn't provide a framework for defining standardized, functional permissions.
- C. Centralizing IdP unifies authentication but doesn't standardize authorization policies across cloud providers.
- D. Manual review is time-consuming and error-prone for thousands of policies, not a scalable solution.
Policy-as-Code (CIEM)
The practice of defining and managing identity and access policies in a machine-readable format, allowing for version control, automation, and consistent deployment across cloud environments.
- Enables policy standardization
- Facilitates automation and version control
- Reduces human error in policy management
Memory trick: Code makes policies consistent, not chaotic.