{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Cybersecurity Awesomeness Podcast","title":"Cybersecurity Awesomeness Podcast - Episode 172","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/145e5485\"></iframe>","width":"100%","height":180,"duration":758,"description":"In this \"Cybersecurity 101\" episode of the Cybersecurity Awesomeness Podcast, host Chris Steffen breaks down the history, fundamentals, and modern challenges of access control.\nSteffen reviews the foundational \"AAA\" framework—Authentication, Authorization, and Accounting—and traces how access control has evolved from 1970s mainframe military models (like Bell-LaPadula and the Orange Book) to 1990s Role-Based Access Control (RBAC), 2010s Zero Trust, and today's modern cloud and Privileged Access Management (PAM) ecosystems.\nThe core challenge, Steffen argues, is that traditional access control models were built for a world where every identity had a human face. Today, the explosion of non-human identities (NHIs) and AI agents has left organizations struggling with unmonitored privileges, standing access, and severe visibility gaps. Steffen concludes with three actionable takeaways: treating access control as a living inventory problem, moving beyond human-centric RBAC models, and ensuring that regular enterprise access reviews explicitly include service accounts and AI agents.","thumbnail_url":"https://img.transistorcdn.com/4gGeNyK3O0BuHdtjNLQjIlIFvrfsTCQ8uimtpAMCMc0/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS9hMGEz/NTgzZDkwNTQ5Yjdh/NWQyMWRjZTU2MjVm/OGJiOS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}