SID316: Using Access Advisor to Strike the Balance Between Security and Usability

Published: Dec. 1, 2017, midnight

b'AWS provides a killer feature for security operations teams: \\xa0Access Advisor. In this session, we discuss how Access Advisor shows the services to which an IAM policy grants access and provides a timestamp for the last time that the role authenticated against that service. At Netflix, we use this valuable data to automatically remove permissions that are no longer used. By continually removing excess permissions, we can achieve a balance of empowering developers and maintaining a best-practice, secure environment.'