Zero-trust and least-privilege IAM design in federal/ regulated cloud deployments
Main Article Content
Abstract
Zero Trust and least-privilege Identity and Access Management (IAM) have become critical security strategies for
safeguarding regulated and federally managed cloud environments against a growing number of malicious attacks. The
era of perimeter-based security is over, as cloud computing and remote access, hybrid infrastructures, and interconnected
digital services are becoming commonplace. This research paper explores the design and implementation of a zero-trust
IAM approach that continuously verifies identity, applies least-privilege access throughout the access lifecycle, and enforces
adaptive authorization policies. The research examines various security elements, including multi-factor authentication,
privileged access management, role- and attribute-based access control, continuous monitoring, and automated identity
governance. It also delves into their role in ensuring compliance, mitigating unauthorized access, managing insider threats,
and enhancing organizational resilience. The suggested model connects security controls with governance and compliance
needs and encourages efficient operations in multi-cloud and hybrid cloud environments. Implementation issues such as
legacy system integration, policy management complexity, scalability, and evolving threat landscapes are also addressed.
The results show that the implementation of the zero-trust principles with least-privilege IAM has a significant impact on
improving cloud security, visibility into identity activities, continuous compliance, and securing digital transformation for
government agencies and other highly regulated organizations navigating dynamic cloud environments.