Secure Identity and Access Management Frameworks for Cloud Native DevOps Systems

Authors

  • Suresh Pairu Subramanyam Technical Manager, Full Stack Development, Columbus, OHIO, USA Author

DOI:

https://doi.org/10.15680/IJCTECE.2023.0604014

Keywords:

Secure Identity Management, Access Control, Cloud-Native DevOps, Role-Based Access Governance, Kubernetes RBAC, Azure Active Directory, Infrastructure as Code, Compliance Monitoring

Abstract

The novel shift to cloud-based DevOps systems has helped to make the operations more effective, but also has created a wide attack surface that requires using a strong identity and access management (IAM) system. The proposed paper describes a particular Framework of Secure Identity and Access Management which is particularly targeted at the adoption of cloud-native framework of DevOps systems, which encompasses such aspects as automation, control, monitoring and enterprise integration. It possesses an outline of the framework based on the Infrastructure as Code (IaC) to make possible automated deployments of Kubernetes clusters, role-based access administration of Kubernetes RBAC and Azure Active Directory (AAD) to centralized identities. Secret management, least privilege-based access and security policies are defined by this policy-as-code solution and Azure Key Vault that provides a solid guarantee to operations that the operations are auditable and compliant. Monitoring layer will offer a chance to trace the activities, track the threats in real-time, create compliance reporting, and visualize the data with such tools as Prometheus, Grafana, and Azure security center. The pipelines deployments of CI/CD and team work platforms and tools are integrated into the deployment without interfering with the security and governance needs. Multi-layered structure of the framework enhances scalability, uniformity of the operations and reduce administrative burdens besides countering vulnerabilities associated with identities. Tests it has also shown to be complementary, and effective at improving, the security status quo and compliance readiness of cloud-native DevOps practices, automated cluster provisioning, fine-grained access control and continuous monitoring. Towards the conclusion of the paper the recommendations on the enterprises adoption and the potential paths to expand IAM to hybrid and multi-cloud DevOps systems will be described.

References

[1] Cloud Security Alliance, Cloud Controls Matrix (CCM), Cloud Security Alliance, 2019. [Online]. Available: https://cloudsecurityalliance.org/research/cloud-controls-matrix

[2] National Institute of Standards and Technology, Zero Trust Architecture, NIST Special Publication 800 207, Aug. 2020. [Online]. Available: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf

[3] International Organization for Standardization, ISO/IEC 27001 — Information Security Management, ISO, 2019. [Online]. Available: https://www.iso.org/isoiec-27001-information-security.html

[4] European Union Agency for Cybersecurity (ENISA), Cloud Security Technical Guidance, ENISA, 2020. [Online]. Available: https://www.enisa.europa.eu/publications/cloud-security-technical-guidance

[5] National Cyber Security Centre (NCSC), Identity and Authentication Guidance, NCSC (UK), 2018. [Online]. Available: https://www.ncsc.gov.uk/collection/identity-and-authentication

[6] Center for Internet Security, CIS Controls v8, CIS, 2021. [Online]. Available: https://www.cisecurity.org/controls/cis-controls-list/

[7] Amazon Web Services, AWS Security Best Practices, AWS, 2021. [Online]. Available: https://aws.amazon.com/architecture/security-best-practices/

[8] Microsoft Azure, Azure Identity Management and Security Documentation, Microsoft, 2022. [Online]. Available: https://learn.microsoft.com/azure/security/fundamentals/identity-management-overview

[9] Google Cloud, Identity and Access Management (IAM) Documentation, Google Cloud, 2022. [Online]. Available: https://cloud.google.com/iam/docs

[10] The Open Web Application Security Project (OWASP), OWASP DevSecOps Guideline, OWASP, 2022. [Online]. Available: https://owasp.org/www-project-devsecops-guideline/

Downloads

Published

2023-07-12

How to Cite

Secure Identity and Access Management Frameworks for Cloud Native DevOps Systems. (2023). International Journal of Computer Technology and Electronics Communication, 6(4), 7357-7366. https://doi.org/10.15680/IJCTECE.2023.0604014