Episode 223 - GluuFederation/identerati-office-hours GitHub Wiki

Title: GovOps Version 0.0.1

Channels

Description

With it's first release, OWASP GovOps officially starts iterating three deliverables: (1) a new standard for inventorying enterprise authorization capabilities; (2) an architecture describing GovOps; (3) metrics to give enterprise governors the observability they need to prioritize risks. In this episode, we'll have a brief discussions with the editors to discuss initial thoughts on how GovOps will evolve in the next few months.

Homework

Takeaways

  • ⚡ Why now: enterprise IT was already having trouble governing complex interconnected microservice clouds. Agents just make it worse. GovOps takes the position that extending the "identity-centric" approach to agents and software just won't work. Agents are too ephemeral and the policies we need to control access won't fit nicely into the old RBAC model which is foundational to modern IGA. GovOps aligns with Google Beyond Zero: "Resource and Action-based security".

  • ⚡ Compliance needs to become realtime and operational and not backwards looking.

  • ⚡ Is governance "how to set rules for what the rules can be"? Is governance "how you know you have the right policies"? Is governance "risk management, accountability, and observability"? GovOps will need to be precise to define the line between authorization and governance.

  • ⚡ AuthZen is useful to show the direction of travel for authorization: moving toward the standard PARC request shape. Any application that supports AuthZen is GovOps ready.

  • ⚡ Will GovOps stop AI from killing humanity? We need observability to correlate authorized purpose with runtime behavior, and to compare actual capability use against enterprise policy. Capability_id helps to correlate these things.

Livestream Audio Archive