🔐 Cybersecurity · Cloud Hardening
Right-size IAM to least privilege
Start scoped-down, expand only with evidence from real denied actions.
advanced~45 minSecurity EngineersAppSecDevSecOps
Steps
- 1Inventory every identity: humans, services, CI roles, third parties
- 2Replace wildcards with explicit actions gathered from access logs
- 3Separate duties: deploy role cannot read databases
- 4MFA enforced for console humans; no long-lived access keys
- 5Set permission boundaries so escalation paths are capped
- 6Quarterly access reviews with auto-expiring grants
Common Pitfalls
- ▲Admin roles 'temporarily' granted during setup, forever
- ▲CI pipelines holding prod-write credentials
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill cloud-hardening-iam-least-privilegeInstall globally
$ npx skills add aniruddhaadak80/skills --skill cloud-hardening-iam-least-privilege -gTags
#iam#cloud#zero-trust#cybersecurity#cloud-hardening