DayBlink Consulting Partner and Cyber Security Practice Lead Michael Morgenstern contributed to Cloud Security Alliance’s “Defining Non-Human Identity.”
From the Cloud Security Alliance: Traditional identity and access management has always been built around human users — employees, contractors, and partners whose activity is relatively easy to monitor and govern. Non-human identities (NHIs), such as service accounts, API keys, and workloads, don’t fit that model. They operate at a scale, speed, and complexity that legacy IAM frameworks were never designed to handle, often spanning cloud, on-premises, and legacy environments without clear ownership or lifecycle management. As organizations increasingly automate the provisioning and decommissioning of these identities to keep pace with modern infrastructure, they introduce new risks that only strong, deliberate governance can address.
This publication, produced through CSA’s Identity and Access Management Working Group, is currently open for peer review and lays the groundwork for how organizations should define and think about non-human identity as a distinct governance challenge.
Read the full paper here: https://cloudsecurityalliance.org/artifacts/defining-non-human-identity
