Alex Smolen·Apr 27AWS Credential Isolation for Local AI AgentsIf you run local agents, you need to make tough choices between autonomy and safety. Setting dangerously-skip-permissions while sword…
Alex Smolen·Mar 23TrailTool: CloudTrail for AI AgentsRunning security for AWS-centric companies means getting down and dirty with CloudTrail. Not only will you crawl the logs with SIEMs to…
Alex Smolen·Oct 1, 2025Refocusing Vendor Security on Risk ReductionVendor security reviews focus on what vendors do. But the real risk (and opportunity) lies in what you do with their software.
Alex Smolen·Nov 11, 2024Access approvals considered harmfulAccess approvals are a feature in categories of software bearing fancy names like Entitlement Management, Identity Governance, Privileged…A response icon2A response icon2
Alex Smolen·Jul 31, 2024Better security policiesSecurity policies are the backbone of information security programs. They define commitments to leadership and communicate objectives to…
Alex Smolen·May 26, 2024Risks are not risks, vulnerabilities are not vulnerabilitiesIn information security we emphasize the importance of risk, but we struggle to operationalize it. How do we make risk useful for auditors…
Alex Smolen·Feb 14, 2024Designing Least Privilege AWS IAM Policies for PeopleThis was originally published on the now defunct IAM Pulse blog in 2021. If you want 2026 advice, check out…
Alex Smolen·Oct 2, 2023Meeting the FedRAMP FIPS 140–2 requirement on AWSFedRAMP is a compliance program for cloud services to process US Federal government data. If you haven’t heard of it, consider yourself…A response icon2A response icon2
Alex Smolen·Dec 5, 2022Vulnerability Inbox ZeroThis is a summary of my LocoMocoSec 2022 and QCon SF 2022 conference talks — thanks to co-author Jake Mertz and the LaunchDarkly Security…A response icon1A response icon1