Talk

Virtual

Action-level continuous authorization for privacy-regulated cloud systems

This talk presents a risk-driven continuous authorization approach for privacy-regulated cloud data that evaluates authorization decisions at the level of individual sensitive actions.

CEST

Cloud platforms handling privacy-regulated data increasingly adopt continuous security models, yet authorization decisions remain largely static and session-based. During audits or incident reviews, teams often struggle to explain why a specific sensitive action was allowed under particular runtime conditions, relying instead on post-hoc log reconstruction.

This talk presents a risk-driven continuous authorization approach that evaluates authorization at the level of individual sensitive actions. At the time an action is requested, contextual signals are evaluated through a minimal policy model to produce allow, challenge, or deny decisions. Each decision generates privacy-minimized, audit-verifiable evidence explaining the rationale without recording regulated data payloads.

The presentation focuses on architectural principles rather than implementations and is intended for cloud architects and security practitioners.

Virtual

Register for PlatformCon 2026