Thursday, June 12, 2025

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
  • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Cloud Security Cybersecurity Data Security Featured Governance, Risk & Compliance Identity & Access News Security Boulevard (Original) Social - Facebook Spotlight 

Home » Security Boulevard (Original) » Why Policy-as-Code is the Best Way to Streamline Authorization

Why Policy-as-Code is the Best Way to Streamline Authorization

by George V. Hulme on November 7, 2023

Automating essential but tedious tasks is one of the most significant benefits of cloud computing. There have been many attempts to automate authorization processes over the years, but finally, it appears one burgeoning effort is beginning to gain traction.

According to a survey released by cloud-native authorization provider Styra, Inc., 94% of those respondents who currently manage authorization and compliance within their organization agreed that policy-as-code is vital for their organization’s preventative security and compliance objectives.

Essentially, policy-as-code is a way to codify policies so that they can be programmed and automated. Typically, there is a policy engine that holds created policies and processes them on demand. Policy-as-code can be used for everything from automated software security testing, controlling mesh architectures, managing authorization in a cloud-native stack and more.

Techstrong Gang Youtube
AWS Hub

Authorization Challenges

In Styra’s survey of 285 developers and technical decision-makers, more than two-thirds of respondents reported “major flaws” in their current homegrown authorization methods, including trouble with efficiency, security and application performance. A full 83% said they planned to increase their investments in policy-as-code to improve their situation.

“The biggest challenge, by far, is auditing access,” Chris Hendrix, Styra director of product management, told Security Boulevard. Additional challenges, according to respondents to Styra’s survey, included a lack of alignment between teams (34%), a lack of visibility into authorization (31%), and a lack of consistent or centralized policy development (29%).

While most respondents suffered no single authorization challenge, challenges implementing authorization do abound, especially for developers. At 34%, the “lack of alignment” between development teams was the most common challenge cited. Other significant challenges were a lack of visibility into authorization implementation, enforcement, monitoring and reporting among 31% of respondents. Also, a lack of consistent or centralized policy development and management life cycle (29%), difficulty meeting security, compliance, and auditability requirements (29%) and difficulty managing policies at greater scale or complexity.

Policy-as-Code on the Rise

While the survey strongly supported policy-as-code, its actual adoption is just getting off the ground. Fifty-one percent of respondents currently using policy-as-code said they have only adopted it in the last two years. And only 30% of those who use policy-as-code are doing so significantly. Finally, as with manual authorization challenges, implementing policy remains challenging; 52% of those who have implemented policy-as-code said they had difficulty writing efficient policies as code.

The benefits of policy-as-code were almost universally accepted, with 95% of respondents who said that policy-as-code was a valuable way to streamline authorization, 96% that it speeds up time-to-market and 91% who agreed that policy-as-code makes work easier for developers.

Still, policy-as-code takes time to adopt correctly. “You have to learn completely new best practices, new tools and new patterns,” Hendrix said.

However, over time, there’s a payoff, Hendrix contended. “Policy-as-code allows you to standardize the mechanism by which you ingest data and write policy and authorization rules. And one of the beautiful things with policy as code is that the same code language for infrastructure works with applications and organizations can share their policies across the organization,” Hendrix said.

Recent Articles By Author
  • Versa Networks’ Sovereign SASE Targets Nation-State Threats With On-Prem Architecture 
  • AttackIQ Bolsters Cyber Defenses with DeepSurface’s Risk-Analysis Tech
  • Critical ‘Backdoor’ Discovered in Widely Used Healthcare Patient Monitors 
More from George V. Hulme
November 7, 2023November 6, 2023 George V. Hulme Authentication, authorization, Automation, Compliance, identity, policy as code
  • ← Eclypsium Launches Guide to Supply Chain Security for Enterprise Infrastructure
  • What Developers Need to Succeed for Effective Application Security →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

How to Spot and Stop Security Risks From Unmanaged AI Tools
Software Supply Chain Security: Navigating NIST, CRA, and FDA Regulations

Podcast

Listen to all of our podcasts

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

ThreatLocker

Most Read on the Boulevard

Huge Food Wholesaler Paralyzed by Hack — is it Scattered Spider Again?
BADBOX 2.0 Botnet Infects Million-Plus Devices, FBI Says
No Lollygagging: Cisco IOS XE Flaw With 10.0 Rating Should be Patched Now
Contrast Security Combines Graph and AI Technologies to Secure Applications
Trump EO Takes Aim at Biden, Obama Provisions for Identity, Sanctions, AI
OffensiveCon25 – No Signal, No Security: Dynamic Baseband Vulnerability Research
What is AI Red Teaming?
From StackStorm to DeepTempo
Scalable Solutions for NHI Management
Boost Your Confidence with Strong NHI Management

Industry Spotlight

Huge Food Wholesaler Paralyzed by Hack — is it Scattered Spider Again?
Analytics & Intelligence Cyberlaw Cybersecurity Data Security DevOps Editorial Calendar Endpoint Featured Governance, Risk & Compliance Humor Identity & Access Incident Response Industry Spotlight Malware Most Read This Week Network Security News Popular Post Ransomware Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Social Engineering Spotlight Threat Intelligence Threats & Breaches Vulnerabilities 

Huge Food Wholesaler Paralyzed by Hack — is it Scattered Spider Again?

June 10, 2025 Richi Jennings | 1 day ago 0
Meta’s Secret Spyware: ‘Local Mess’ Hack Tracks You Across the Web
Application Security Cloud Security Cyberlaw Cybersecurity Data Privacy DevOps Endpoint Featured Governance, Risk & Compliance Humor Identity & Access Incident Response Industry Spotlight Malware Mobile Security Most Read This Week Network Security News Popular Post Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Social Engineering Spotlight Threats & Breaches Vulnerabilities 

Meta’s Secret Spyware: ‘Local Mess’ Hack Tracks You Across the Web

June 4, 2025 Richi Jennings | Jun 04 0
USDA Worker, 5 Others Charged in Food Stamp Fraud Operation
Cyberlaw Cybersecurity Data Security Featured Governance, Risk & Compliance Identity & Access Industry Spotlight News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

USDA Worker, 5 Others Charged in Food Stamp Fraud Operation

May 30, 2025 Jeffrey Burt | May 30 0

Top Stories

BADBOX 2.0 Botnet Infects Million-Plus Devices, FBI Says
Application Security Cloud Security Cybersecurity Data Security Featured IoT & ICS Security Malware Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence 

BADBOX 2.0 Botnet Infects Million-Plus Devices, FBI Says

June 9, 2025 Jeffrey Burt | 2 days ago 0
Trump EO Takes Aim at Biden, Obama Provisions for Identity, Sanctions, AI
Cloud Security Cyberlaw Cybersecurity Data Security DevOps Featured Identity & Access Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

Trump EO Takes Aim at Biden, Obama Provisions for Identity, Sanctions, AI

June 9, 2025 Jeffrey Burt | 2 days ago 0
RSA Extends Reach of Passwordless Management Platform
Cybersecurity Featured Identity & Access News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

RSA Extends Reach of Passwordless Management Platform

June 9, 2025 Michael Vizard | 3 days ago 0

Security Humor

Randall Munroe’s XKCD ‘Trojan Horse’

Randall Munroe’s XKCD ‘Trojan Horse’

Download Free eBook

7 Must-Read eBooks for Security Professionals

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2025 Techstrong Group Inc. All rights reserved.
×