惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
J
Java Code Geeks
V
V2EX
Blog — PlanetScale
Blog — PlanetScale
博客园 - 司徒正美
Hugging Face - Blog
Hugging Face - Blog
F
Fortinet All Blogs
aimingoo的专栏
aimingoo的专栏
B
Blog
A
About on SuperTechFans
有赞技术团队
有赞技术团队
月光博客
月光博客
Microsoft Azure Blog
Microsoft Azure Blog
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
美团技术团队
大猫的无限游戏
大猫的无限游戏
爱范儿
爱范儿
N
Netflix TechBlog - Medium
C
Check Point Blog
Recent Announcements
Recent Announcements
博客园 - Franky
博客园 - 叶小钗
T
Tailwind CSS Blog

Wiz Blog | RSS feed

Meet Wiz for M365: Bringing SaaS into the Security Graph Bringing Security Visibility to Vercel with Wiz Axios NPM Distribution Compromised in Supply Chain Attack Tracking TeamPCP: Investigating Post-Compromise Attacks Seen in the Wild The Wiz Blue Agent, now Generally Available Beyond the Badge: What Achieving Microsoft’s Certified Software Designation Means for Your Cloud Security Introducing the Green Agent: AI-Powered Remediation for the Cloud Three’s a Crowd: TeamPCP trojanizes LiteLLM in Continuation of Campaign KICS GitHub Action Compromised: TeamPCP Strikes Again in Supply Chain Attack Introducing the Wiz Red Agent- AI-Powered Attacker Introducing Wiz AI Application Protection Platform (AI-APP) Introducing Wiz Agents & Workflows: Security at the Speed of AI AI Runtime Threat Detection: From Input to Real-World Impact Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack It’s Official: Wiz Joins Google Understanding and Reducing AI Risk in Modern Applications Introducing Wiz Tenant Manager: Multi-Tenant Management for Federated Organizations The Agile FedRAMP Playbook, Part 4: Reactive Risk Management through Enriched Incident Response Wiz Achieves CPSTIC Certification in Spain Seeing AI Clearly: Building Visibility Across Modern AI Applications The Agile FedRAMP Playbook, Part 3: Preventative Risk Management by building Secure by Design Wiz Leads the 2026 Latio Application Security Report with awards in 4 categories Building an Agentic Cloud Security Ecosystem: A Reference Architecture with Wiz MCP and Infosys Cyber Next The Agile FedRAMP Playbook, Part 2: Proactive Risk Management with Continuous Monitoring Cloud-native Security for your Windows environment: Announcing the Wiz Runtime Sensor for Windows Would You Click ‘Accept’? Automatically detecting malicious Azure OAuth applications using LLMs Wiz Named a Leader in The Forrester Wave™: Cloud Native Application Protection Solutions, Q1 2026 From Detection to Remediation: It’s Time to Rethink AppSec Around Exploitability and Root Cause Fixes The Agile FedRAMP Playbook, Part 1: Why Risk is Your Best Starting Point Introducing AI Cyber Model Arena: A Real-World Benchmark for AI Agents in Cybersecurity
Data access governance: Who's got the keys to your data k...
Shaked Rotlevi, Yariv Ashkenazy, Matika Lidgi · 2024-11-06 · via Wiz Blog | RSS feed

The dynamic and decentralized nature of the cloud makes managing data governance a challenging task, with most organizations running across cloud providers and regions, leading to data sprawl. This fragmentation makes it difficult to maintain consistent data policies, track data lineage, and ensure compliance with various regulatory standards like GDPR or HIPAA. Furthermore, as environments grow, so does the sheer volume of identities involved, from users to non-human identities. Each cloud includes roles, groups, users, access keys, and resource-based policies that interact in complex ways, and permissions are often layered and inherited, meaning that access rights can be granted at different levels, such as organization, project, folder, or individual resource. Based on Microsoft’s 2023 State of Cloud Permissions, there are over 40,000 permissions that can be granted across key cloud infrastructure platforms. In addition, you have the “clouds within the cloud”, such as Kubernetes, OpenAI, Snowflake, and others that have their own set of identities, as well as external Identity Providers like Okta or Google Workspace. This can result in a complex web of permissions layers that make it hard to manage and visualize exactly who can access what. 

To effectively secure cloud data, organizations need to easily answer “who can access what data in my environment?” to detect if data is at risk and ensure compliance. That is why it is important for security and data teams to have a tool in place that enables them to govern data access across their entire cloud environment by allowing them to: 

  1. Discover where their sensitive data is 

  2. Identify effective permissions of cloud identities 

  3. Understand which identities have access to sensitive data 

  4. Detect and remove identity risks associated with critical data 

To help organizations successfully answer these questions, Wiz provides Data Security Posture Management (DSPM) capabilities that are fully integrated with our Cloud Infrastructure Entitlement Management (CIEM) capabilities to allow effective data access governance. This is how Wiz enables data access governance:

1. Discovering and classifying sensitive data with Wiz DSPM

Wiz DSPM provides agentless data discovery with built-in classification rules that detect sensitive data such as PCI, PII, PHI, secrets, and more across your multi-cloud environment. As scanning doesn't rely on agents, you can automatically discover new instances of sensitive data regardless to whether they are stored in storage buckets, PaaS or hosted databases, serverless functions, data warehouses, Snowflake, or OpenAI. If your organization has unique data formats you can also create custom classifiers to identify where that sensitive data is across your environment.

2. Effective permissions analysis with Wiz CIEM 

Wiz calculates the effective permissions of every identity across your cloud footprint and maps the effective access between all human and non-human identities and resources on the Wiz Security Graph. Such analysis takes into account complex IAM policies and controls including boundaries, SCPs, resource policies and more across all platforms. Wiz conducts the same effective permissions analysis to your IdP identities such as Okta, Google Workspace, or EntraID so you can understand which user in your organization has what cloud permission. This enables you to answer: “who can access what?” across various clouds and platforms. 

3. Govern access to crown jewels 

Let’s combine these insights by answering the first and second questions to understand, who can access the critical data in my environment? With Wiz, you can start by looking at CIEM Explorer to quickly query for identity, access, and resource to answer who can access what without having to understand IAM nuances. For example, you can use it to explore which human or non-human identities have access to sensitive data, find admin users with access to sensitive data, or Snowflake users that can access critical data. By simplifying IAM, the CIEM Explorer empowers security teams to quickly understand data access governance across all storage platforms.

4. Remediate risky identities with access to critical data 

Now that we know who can access our sensitive data, we want to ensure those identities are configured securely and detect any IAM risks related to them. In Wiz, the Identities Inventory page provides a centralized view into what platforms a human identity can access (i.e Snowflake, AWS, Okta) and allows you to detect security misconfigurations on that identity across all platforms it accesses, such as a user with no MFA enabled or an inactive user. For each identity in your environment, Wiz also alerts you of any IAM misconfigurations and risky identities such as those with excessive or high privileges and provides you with remediation guidance so you can scope down permissions. This enables you to ensure all identities have least privilege access, and only those who need to access critical data are authorized to do so securely. 

Start governing access to your critical data with Wiz today and gain visibility into every single identity and its access across your cloud footprint. Learn more about Wiz DSPM (login required) and Wiz CIEM (login required). If you prefer a live demo, we would love to connect with you.