<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>IAM on AI VOID</title><link>https://ai-blog.noorshomelab.dev/tags/iam/</link><description>Recent content in IAM on AI VOID</description><generator>Hugo</generator><language>en</language><lastBuildDate>Thu, 28 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://ai-blog.noorshomelab.dev/tags/iam/index.xml" rel="self" type="application/rss+xml"/><item><title>Identity is the New Perimeter: Strengthening Authentication and Authorization</title><link>https://ai-blog.noorshomelab.dev/zero-trust-security-guide/identity-new-perimeter/</link><pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate><guid>https://ai-blog.noorshomelab.dev/zero-trust-security-guide/identity-new-perimeter/</guid><description>&lt;p&gt;In the digital world, the traditional &amp;ldquo;castle-and-moat&amp;rdquo; security model is obsolete. Gone are the days when we could simply build a strong wall around our network and assume everything inside was safe. With cloud computing, mobile devices, and remote work, our resources are everywhere, and the old network perimeter has dissolved.&lt;/p&gt;
&lt;p&gt;So, if the network isn&amp;rsquo;t the perimeter, what is? In a Zero Trust world, the answer is clear: &lt;strong&gt;identity&lt;/strong&gt;. Every user, every device, every application, and every service must explicitly prove who and what it is, and what it&amp;rsquo;s authorized to do, before gaining access to any resource. This chapter dives deep into how we establish and enforce this new identity-centric perimeter, focusing on robust authentication and granular authorization.&lt;/p&gt;</description></item><item><title>Authentication, Authorization, and Identity Management</title><link>https://ai-blog.noorshomelab.dev/netflix-internals-guide-2026-03-19/auth-authz-identity/</link><pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate><guid>https://ai-blog.noorshomelab.dev/netflix-internals-guide-2026-03-19/auth-authz-identity/</guid><description>&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;
&lt;p&gt;In a platform like Netflix, managing who can access what content and perform which actions is paramount. This chapter dives into the critical mechanisms of &lt;strong&gt;Authentication (AuthN)&lt;/strong&gt;, &lt;strong&gt;Authorization (AuthZ)&lt;/strong&gt;, and &lt;strong&gt;Identity Management (IAM)&lt;/strong&gt;. These are the bedrock of security, ensuring that only legitimate users access the service and only have permission to do what they&amp;rsquo;re supposed to, whether it&amp;rsquo;s streaming a movie, updating their profile, or managing payment information.&lt;/p&gt;</description></item><item><title>Chapter 12: Security Best Practices for Kiro Development</title><link>https://ai-blog.noorshomelab.dev/aws-kiro-mastery/kiro-security-best-practices/</link><pubDate>Sat, 24 Jan 2026 00:00:00 +0000</pubDate><guid>https://ai-blog.noorshomelab.dev/aws-kiro-mastery/kiro-security-best-practices/</guid><description>&lt;h2 id="chapter-12-security-best-practices-for-kiro-development"&gt;Chapter 12: Security Best Practices for Kiro Development&lt;/h2&gt;
&lt;p&gt;Welcome back, fellow developer! In our journey with AWS Kiro, we&amp;rsquo;ve explored its powerful capabilities for intelligent code generation, debugging, and deployment. As we embrace the efficiency and innovation Kiro brings, it&amp;rsquo;s absolutely crucial to also embrace a strong security mindset. After all, a powerful tool in the wrong hands, or configured insecurely, can introduce significant risks.&lt;/p&gt;
&lt;p&gt;In this chapter, we&amp;rsquo;ll dive deep into establishing robust security best practices for your Kiro development workflows. We&amp;rsquo;ll learn why security is paramount when working with AI-powered agents, how to apply the principle of least privilege, manage sensitive information effectively, and monitor agent activities. By the end of this chapter, you&amp;rsquo;ll be equipped to leverage Kiro&amp;rsquo;s power while keeping your AWS environment and applications secure.&lt;/p&gt;</description></item></channel></rss>