home.social

#i-am — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #i-am, aggregated by home.social.

fetched live
  1. 📰 Critical Keycloak Flaw (CVE-2026-18963) Allows Account Takeover

    🚨 CRITICAL FLAW: Keycloak is vulnerable to CVE-2026-18963 (CVSS 9.1), allowing unauthenticated remote attackers to take over any account. Patches are available—update immediately! #Keycloak #Cybersecurity #Vulnerability #CVE #IAM

    🔗 cyber.netsecops.io/articles/cr

  2. 📰 Critical Keycloak Flaw (CVE-2026-18963) Allows Account Takeover

    🚨 CRITICAL FLAW: Keycloak is vulnerable to CVE-2026-18963 (CVSS 9.1), allowing unauthenticated remote attackers to take over any account. Patches are available—update immediately! #Keycloak #Cybersecurity #Vulnerability #CVE #IAM

    🔗 cyber.netsecops.io/articles/cr

  3. Models to assess scenarios of futures often reflect Western concerns and values. They assume persistent inequalities, obscure ethical or normative choices, and systematically fail to include stakeholders and scientists from other cultures.
    "
    • We explore limitations of modelling science in assessing different justice dimensions
    • We emphasise various procedural, recognitional, and epistemic justice considerations
    • We take aim at the disconnect with non-modellers and Global South underrepresentation."

    Alexandros Nikas et al. (2026). doi.org/10.1016/j.futures.2026 🧩 🧵

    #futures #anticipation #bias #modelling #modeling #models #IAM #IAMs #climatePolicy #science #climateScience

  4. Models to assess scenarios of futures often reflect Western concerns and values. They assume persistent inequalities, obscure ethical or normative choices, and systematically fail to include stakeholders and scientists from other cultures.
    "
    • We explore limitations of modelling science in assessing different justice dimensions
    • We emphasise various procedural, recognitional, and epistemic justice considerations
    • We take aim at the disconnect with non-modellers and Global South underrepresentation."

    Alexandros Nikas et al. (2026). doi.org/10.1016/j.futures.2026 🧩 🧵

    #futures #anticipation #bias #modelling #modeling #models #IAM #IAMs #climatePolicy #science #climateScience

  5. Models to assess scenarios of futures often reflect Western concerns and values. They assume persistent inequalities, obscure ethical or normative choices, and systematically fail to include stakeholders and scientists from other cultures.
    "
    • We explore limitations of modelling science in assessing different justice dimensions
    • We emphasise various procedural, recognitional, and epistemic justice considerations
    • We take aim at the disconnect with non-modellers and Global South underrepresentation."

    Alexandros Nikas et al. (2026). doi.org/10.1016/j.futures.2026 🧩 🧵

    #futures #anticipation #bias #modelling #modeling #models #IAM #IAMs #climatePolicy #science #climateScience

  6. Models to assess scenarios of futures often reflect Western concerns and values. They assume persistent inequalities, obscure ethical or normative choices, and systematically fail to include stakeholders and scientists from other cultures.
    "
    • We explore limitations of modelling science in assessing different justice dimensions
    • We emphasise various procedural, recognitional, and epistemic justice considerations
    • We take aim at the disconnect with non-modellers and Global South underrepresentation."

    Alexandros Nikas et al. (2026). doi.org/10.1016/j.futures.2026 🧩 🧵

    #futures #anticipation #bias #modelling #modeling #models #IAM #IAMs #climatePolicy #science #climateScience

  7. Models to assess scenarios of futures often reflect Western concerns and values. They assume persistent inequalities, obscure ethical or normative choices, and systematically fail to include stakeholders and scientists from other cultures.
    "
    • We explore limitations of modelling science in assessing different justice dimensions
    • We emphasise various procedural, recognitional, and epistemic justice considerations
    • We take aim at the disconnect with non-modellers and Global South underrepresentation."

    Alexandros Nikas et al. (2026). doi.org/10.1016/j.futures.2026 🧩 🧵

    #futures #anticipation #bias #modelling #modeling #models #IAM #IAMs #climatePolicy #science #climateScience

  8. Zero Trust для ИИ-агентов: почему отдельной идентичности недостаточно

    Привет, Хабр! Меня зовут Денис Корбаков, я технический директор «Смарт-Софт». Мы разрабатываем NGFW и регулярно разбираем, какие сетевые события можно использовать для независимого контроля автоматизированных систем. Последний год эта задача резко усложнилась. В инфраструктуре массово появился новый операционный тип машинного субъекта: автономный агент, который сам выбирает инструменты, меняет контекст и делегирует полномочия. Zero Trust никогда не ограничивался только людьми. NIST SP 800-207 прямо включает в модель non-person entities: сервисы, приложения, автоматизированное ПО, и обсуждает их ещё с версии 2020 года. Субъект как класс не новый, новыми являются масштаб, автономность и модель поведения. Большинство корпоративных реализаций IAM на практике заточены либо под человека с интерактивной сессией, либо под стабильный сервисный аккаунт, который работает годами с предсказуемым поведением. ИИ-агент находится между этими моделями: не человек, способный самостоятельно оценить допустимый объём своих полномочий, и не полностью статичный сервис с неизменным поведением. Как отмечает исследование Cloud Security Alliance, проведённое при поддержке Aembit , существующие подходы к IAM испытывают нагрузку, на которую изначально не проектировались.

    habr.com/ru/articles/1071750/

    #Zero_Trust #ИИагенты #IAM #машинная_идентичность #workload_identity #prompt_injection #MCP #NIST_SP
    800207 #SPIFFE #NGFW

  9. Zero Trust для ИИ-агентов: почему отдельной идентичности недостаточно

    Привет, Хабр! Меня зовут Денис Корбаков, я технический директор «Смарт-Софт». Мы разрабатываем NGFW и регулярно разбираем, какие сетевые события можно использовать для независимого контроля автоматизированных систем. Последний год эта задача резко усложнилась. В инфраструктуре массово появился новый операционный тип машинного субъекта: автономный агент, который сам выбирает инструменты, меняет контекст и делегирует полномочия. Zero Trust никогда не ограничивался только людьми. NIST SP 800-207 прямо включает в модель non-person entities: сервисы, приложения, автоматизированное ПО, и обсуждает их ещё с версии 2020 года. Субъект как класс не новый, новыми являются масштаб, автономность и модель поведения. Большинство корпоративных реализаций IAM на практике заточены либо под человека с интерактивной сессией, либо под стабильный сервисный аккаунт, который работает годами с предсказуемым поведением. ИИ-агент находится между этими моделями: не человек, способный самостоятельно оценить допустимый объём своих полномочий, и не полностью статичный сервис с неизменным поведением. Как отмечает исследование Cloud Security Alliance, проведённое при поддержке Aembit , существующие подходы к IAM испытывают нагрузку, на которую изначально не проектировались.

    habr.com/ru/articles/1071750/

    #Zero_Trust #ИИагенты #IAM #машинная_идентичность #workload_identity #prompt_injection #MCP #NIST_SP
    800207 #SPIFFE #NGFW

  10. Zero Trust для ИИ-агентов: почему отдельной идентичности недостаточно

    Привет, Хабр! Меня зовут Денис Корбаков, я технический директор «Смарт-Софт». Мы разрабатываем NGFW и регулярно разбираем, какие сетевые события можно использовать для независимого контроля автоматизированных систем. Последний год эта задача резко усложнилась. В инфраструктуре массово появился новый операционный тип машинного субъекта: автономный агент, который сам выбирает инструменты, меняет контекст и делегирует полномочия. Zero Trust никогда не ограничивался только людьми. NIST SP 800-207 прямо включает в модель non-person entities: сервисы, приложения, автоматизированное ПО, и обсуждает их ещё с версии 2020 года. Субъект как класс не новый, новыми являются масштаб, автономность и модель поведения. Большинство корпоративных реализаций IAM на практике заточены либо под человека с интерактивной сессией, либо под стабильный сервисный аккаунт, который работает годами с предсказуемым поведением. ИИ-агент находится между этими моделями: не человек, способный самостоятельно оценить допустимый объём своих полномочий, и не полностью статичный сервис с неизменным поведением. Как отмечает исследование Cloud Security Alliance, проведённое при поддержке Aembit , существующие подходы к IAM испытывают нагрузку, на которую изначально не проектировались.

    habr.com/ru/articles/1071750/

    #Zero_Trust #ИИагенты #IAM #машинная_идентичность #workload_identity #prompt_injection #MCP #NIST_SP
    800207 #SPIFFE #NGFW

  11. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  12. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  13. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  14. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  15. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  16. Senate Republicans launch McCarthy like attacks on Machinists union over Cuba meeting in union hall #senate #unions #IAM #cuba #cartoon #McCarthy #gregkearney #kearney

  17. Senate Republicans launch McCarthy like attacks on Machinists union over Cuba meeting in union hall #senate #unions #IAM #cuba #cartoon #McCarthy #gregkearney #kearney

  18. Senate Republicans launch McCarthy like attacks on Machinists union over Cuba meeting in union hall #senate #unions #IAM #cuba #cartoon #McCarthy #gregkearney #kearney

  19. Senate Republicans launch McCarthy like attacks on Machinists union over Cuba meeting in union hall #senate #unions #IAM #cuba #cartoon #McCarthy #gregkearney #kearney

  20. Stop guessing if IAM policies work. Test them programmatically with the AWS CLI policy simulator. This snippet builds a JSON payload with principal, actions, and resources, then calls `iam simulate-principal-policy` to get allow/deny decisions with evaluation reasons. Works on Ubuntu 22.04, RHEL 9, macOS 14. #aws #iam #policy-simulator #ValtersIT

    valtersit.com/vault/verify-iam

  21. Stop guessing if IAM policies work. Test them programmatically with the AWS CLI policy simulator. This snippet builds a JSON payload with principal, actions, and resources, then calls `iam simulate-principal-policy` to get allow/deny decisions with evaluation reasons. Works on Ubuntu 22.04, RHEL 9, macOS 14. #aws #iam #policy-simulator #ValtersIT

    valtersit.com/vault/verify-iam

  22. Как мы тестировали отказоустойчивость MWS Cloud Platform и при чём тут швейцарский сыр

    Всем привет! Я Андрей Халиуллин — руководитель направления IAM & Security Services

    habr.com/ru/companies/mws/arti

    #cloud #mwscloudplatform #MWS_Cloud #отказоустойчивость #iam #AZ #object_storage

  23. Как мы тестировали отказоустойчивость MWS Cloud Platform и при чём тут швейцарский сыр

    Всем привет! Я Андрей Халиуллин — руководитель направления IAM & Security Services

    habr.com/ru/companies/mws/arti

    #cloud #mwscloudplatform #MWS_Cloud #отказоустойчивость #iam #AZ #object_storage

  24. Как мы тестировали отказоустойчивость MWS Cloud Platform и при чём тут швейцарский сыр

    Всем привет! Я Андрей Халиуллин — руководитель направления IAM & Security Services

    habr.com/ru/companies/mws/arti

    #cloud #mwscloudplatform #MWS_Cloud #отказоустойчивость #iam #AZ #object_storage

  25. Celine Dion Gets Candid About Stiff-Person Syndrome & Paris Comeback: “I’m Alive”

    Celine Dion is pressing forward after a health battle that threatened to permanently silence one of music’s most…
    #France #FR #Europe #EU #Paris #CelineDion #CelineDionHealth #CelineDionParis #Harper’sBazaar #iam:celinedion #stiff-personsyndrome
    europesays.com/france/66952/

  26. 🎊 LSC 2.3 released!

    This version brings new features like javascript in LDAP filters, bypass getOne step, fetch all attributes and EL10 package.

    🔗 More information on projects.ow2.org/view/lsc/lsc-

    @ow2 @worteks_com

    #LSC #IAM #IDM #OpenSource #FreeSoftware

  27. 🎊 LSC 2.3 released!

    This version brings new features like javascript in LDAP filters, bypass getOne step, fetch all attributes and EL10 package.

    🔗 More information on projects.ow2.org/view/lsc/lsc-

    @ow2 @worteks_com

    #LSC #IAM #IDM #OpenSource #FreeSoftware

  28. 🎊 LSC 2.3 released!

    This version brings new features like javascript in LDAP filters, bypass getOne step, fetch all attributes and EL10 package.

    🔗 More information on projects.ow2.org/view/lsc/lsc-

    @ow2 @worteks_com

    #LSC #IAM #IDM #OpenSource #FreeSoftware

  29. 🎊 LSC 2.3 released!

    This version brings new features like javascript in LDAP filters, bypass getOne step, fetch all attributes and EL10 package.

    🔗 More information on projects.ow2.org/view/lsc/lsc-

    @ow2 @worteks_com

    #LSC #IAM #IDM #OpenSource #FreeSoftware

  30. “I AM” leads.
    Identity follows.
    Life adjusts.

  31. NextAuth.js CRITICAL vuln (CVE-2026-73420): Unicode email normalization flaw lets attackers intercept magic links & access accounts. Affects pre-@auth/core 0.41.3, next-auth 4.24.15, 5.0.0-beta.32. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #NextAuth #IAM #CVE202673420

  32. NextAuth.js CRITICAL vuln (CVE-2026-73420): Unicode email normalization flaw lets attackers intercept magic links & access accounts. Affects pre-@auth/core 0.41.3, next-auth 4.24.15, 5.0.0-beta.32. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #NextAuth #IAM #CVE202673420

  33. NextAuth.js CRITICAL vuln (CVE-2026-73420): Unicode email normalization flaw lets attackers intercept magic links & access accounts. Affects pre-@auth/core 0.41.3, next-auth 4.24.15, 5.0.0-beta.32. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #NextAuth #IAM #CVE202673420

  34. NextAuth.js CRITICAL vuln (CVE-2026-73420): Unicode email normalization flaw lets attackers intercept magic links & access accounts. Affects pre-@auth/core 0.41.3, next-auth 4.24.15, 5.0.0-beta.32. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #NextAuth #IAM #CVE202673420

  35. Ein deutscher Bankkonzern entwickelt ein Open-Source-basiertes IAM-System für die EUDI-Wallet, um eIDAS 2.0-Anforderungen und höchste Datensicherheit zu erfüllen. Dieses Projekt transformiert Identity, KYC und Fraud Prevention in der Finanzbranche – ein spannender Use Case für moderne IT-Architekturen.
    #Aktuell #Strategie #EUDI #EUDIWallet #IAM #x26IKP #Audio
    ht...
    it-finanzmagazin.de/deutscher-

  36. Ein deutscher Bankkonzern entwickelt ein Open-Source-basiertes IAM-System für die EUDI-Wallet, um eIDAS 2.0-Anforderungen und höchste Datensicherheit zu erfüllen. Dieses Projekt transformiert Identity, KYC und Fraud Prevention in der Finanzbranche – ein spannender Use Case für moderne IT-Architekturen.
    #Aktuell #Strategie #EUDI #EUDIWallet #IAM #x26IKP #Audio
    ht...
    it-finanzmagazin.de/deutscher-

  37. Security Tip: Enforce the Principle of Least Privilege (PoLP) for Service Accounts. 🛡️

    Many breaches are worsened by service accounts having broad permissions. Audit your IAM roles: if a microservice only needs to read data, ensure it cannot write or delete. By restricting permissions to the absolute minimum required, you contain potential damage before it happens.

    Stay ahead of emerging threats: cvedatabase.com

  38. I AM is complete.

    Anything after is superfluous.

  39. Путь джедаев: создание компонента IAM в Astra Cloud Platform 2.1

    Хабр, и снова здравствуй) На связи Алексей Боровиков, архитектор Astra Cloud. Тут такое дело, мы выкатили мажорный релиз нашей облачной платформы. Работа была проделана колоссальная, я не буду писать все изменения, иначе это будет не статья, а книга. Поэтому решил сфокусироваться на одном компоненте и рассказать, как мы его сделали и почему. Речь идет про IAM — Identity and Access Management. Он отвечает на главные вопросы облачной безопасности: кто, что сделал и имел ли на это право. Итаааак…

    habr.com/ru/companies/astralin

    #облачная_платформа #облачная_инфраструктура #iam #релиз

  40. Путь джедаев: создание компонента IAM в Astra Cloud Platform 2.1

    Хабр, и снова здравствуй) На связи Алексей Боровиков, архитектор Astra Cloud. Тут такое дело, мы выкатили мажорный релиз нашей облачной платформы. Работа была проделана колоссальная, я не буду писать все изменения, иначе это будет не статья, а книга. Поэтому решил сфокусироваться на одном компоненте и рассказать, как мы его сделали и почему. Речь идет про IAM — Identity and Access Management. Он отвечает на главные вопросы облачной безопасности: кто, что сделал и имел ли на это право. Итаааак…

    habr.com/ru/companies/astralin

    #облачная_платформа #облачная_инфраструктура #iam #релиз

  41. Путь джедаев: создание компонента IAM в Astra Cloud Platform 2.1

    Хабр, и снова здравствуй) На связи Алексей Боровиков, архитектор Astra Cloud. Тут такое дело, мы выкатили мажорный релиз нашей облачной платформы. Работа была проделана колоссальная, я не буду писать все изменения, иначе это будет не статья, а книга. Поэтому решил сфокусироваться на одном компоненте и рассказать, как мы его сделали и почему. Речь идет про IAM — Identity and Access Management. Он отвечает на главные вопросы облачной безопасности: кто, что сделал и имел ли на это право. Итаааак…

    habr.com/ru/companies/astralin

    #облачная_платформа #облачная_инфраструктура #iam #релиз

  42. Tired of unused AWS IAM roles piling up? This Python + boto3 script auto-detects roles idle for 90+ days, skips instance-profile and service-linked roles, detaches managed policies, deletes inline ones, then removes the role. Works with Python 3.9+ and AWS CLI 2.x. #security #aws #iam #ValtersIT #snippet

    valtersit.com/vault/automated-

  43. Tired of unused AWS IAM roles piling up? This Python + boto3 script auto-detects roles idle for 90+ days, skips instance-profile and service-linked roles, detaches managed policies, deletes inline ones, then removes the role. Works with Python 3.9+ and AWS CLI 2.x. #security #aws #iam #ValtersIT #snippet

    valtersit.com/vault/automated-

  44. Clean up unused IAM roles with AWS CLI: this script uses Access Advisor to generate last-accessed reports, flags roles idle for 30+ days, then disables/deletes them to shrink your attack surface. Requires bash 4+, AWS CLI v2. #aws #iam #roles #snippet #ValtersIT

    valtersit.com/vault/detect-and

  45. Clean up unused IAM roles with AWS CLI: this script uses Access Advisor to generate last-accessed reports, flags roles idle for 30+ days, then disables/deletes them to shrink your attack surface. Requires bash 4+, AWS CLI v2. #aws #iam #roles #snippet #ValtersIT

    valtersit.com/vault/detect-and

  46. Киберустойчивость начинается с данных

    Авторы: Екатерина Гафиятуллина, менеджер по развитию бизнеса Innostage, и Артём Шмарев , руководитель центра компетенций по управлению данными Юникон Бизнес Солюшнс Данные перестали быть вспомогательным ресурсом для отчётности или аналитики. Сегодня они лежат в основе операционной деятельности организаций, клиентских сервисов, производственных процессов и стратегических решений. Но в то же время данные становятся одной из главных мишеней для кибератак. При этом бизнес требует мгновенного доступа к данным — для аналитики, машинного обучения, цифровых продуктов и автоматизации. Но чем активнее они циркулируют между внутренними системами, облачными хранилищами, подрядчиками и ИИ-контурами, тем сложнее обеспечить их защиту и управляемость. На этом фоне ключевой вызов для CISO (Chief Information Security Officer, директор по информационной безопасности) и топ-менеджмента — отсутствие полной картины: какие данные существуют, где они хранятся, кто имеет к ним доступ, как они перемещаются и какие риски создают для бизнеса.

    habr.com/ru/companies/innostag

    #киберустойчивость #управление_данными #защита_данных #киберриски #siem #dlp #iam #Innostage_Cardinal_Platform #arenadata_catalog

  47. Киберустойчивость начинается с данных

    Авторы: Екатерина Гафиятуллина, менеджер по развитию бизнеса Innostage, и Артём Шмарев , руководитель центра компетенций по управлению данными Юникон Бизнес Солюшнс Данные перестали быть вспомогательным ресурсом для отчётности или аналитики. Сегодня они лежат в основе операционной деятельности организаций, клиентских сервисов, производственных процессов и стратегических решений. Но в то же время данные становятся одной из главных мишеней для кибератак. При этом бизнес требует мгновенного доступа к данным — для аналитики, машинного обучения, цифровых продуктов и автоматизации. Но чем активнее они циркулируют между внутренними системами, облачными хранилищами, подрядчиками и ИИ-контурами, тем сложнее обеспечить их защиту и управляемость. На этом фоне ключевой вызов для CISO (Chief Information Security Officer, директор по информационной безопасности) и топ-менеджмента — отсутствие полной картины: какие данные существуют, где они хранятся, кто имеет к ним доступ, как они перемещаются и какие риски создают для бизнеса.

    habr.com/ru/companies/innostag

    #киберустойчивость #управление_данными #защита_данных #киберриски #siem #dlp #iam #Innostage_Cardinal_Platform #arenadata_catalog

  48. Киберустойчивость начинается с данных

    Авторы: Екатерина Гафиятуллина, менеджер по развитию бизнеса Innostage, и Артём Шмарев , руководитель центра компетенций по управлению данными Юникон Бизнес Солюшнс Данные перестали быть вспомогательным ресурсом для отчётности или аналитики. Сегодня они лежат в основе операционной деятельности организаций, клиентских сервисов, производственных процессов и стратегических решений. Но в то же время данные становятся одной из главных мишеней для кибератак. При этом бизнес требует мгновенного доступа к данным — для аналитики, машинного обучения, цифровых продуктов и автоматизации. Но чем активнее они циркулируют между внутренними системами, облачными хранилищами, подрядчиками и ИИ-контурами, тем сложнее обеспечить их защиту и управляемость. На этом фоне ключевой вызов для CISO (Chief Information Security Officer, директор по информационной безопасности) и топ-менеджмента — отсутствие полной картины: какие данные существуют, где они хранятся, кто имеет к ним доступ, как они перемещаются и какие риски создают для бизнеса.

    habr.com/ru/companies/innostag

    #киберустойчивость #управление_данными #защита_данных #киберриски #siem #dlp #iam #Innostage_Cardinal_Platform #arenadata_catalog