Talk
Virtual
Action-level continuous authorization for privacy-regulated cloud systems
This talk presents a risk-driven continuous authorization approach for privacy-regulated cloud data that evaluates authorization decisions at the level of individual sensitive actions.
CEST
Meet the speakers
Cloud platforms handling privacy-regulated data increasingly adopt continuous security models, yet authorization decisions remain largely static and session-based. During audits or incident reviews, teams often struggle to explain why a specific sensitive action was allowed under particular runtime conditions, relying instead on post-hoc log reconstruction.
This talk presents a risk-driven continuous authorization approach that evaluates authorization at the level of individual sensitive actions. At the time an action is requested, contextual signals are evaluated through a minimal policy model to produce allow, challenge, or deny decisions. Each decision generates privacy-minimized, audit-verifiable evidence explaining the rationale without recording regulated data payloads.
The presentation focuses on architectural principles rather than implementations and is intended for cloud architects and security practitioners.
