ADVSEC01-BP01 Implement user authentication and access control to protect bidding process and content
Authenticate the approved SSPs (supply-side platforms) and advertisers. Based on this authentication, DSPs can provide them with least-privileged authorization and access to the relevant resources and data.
Implementation guidance
AWS offers multiple services to provide SSPs and DSPs secured
and scalable user management across all parts of the workload.
Consider using
Amazon Cognito
Additionally, you can use
AWS Identity and Access Management (IAM)
Consider implementing role-based access control to determine which access to resources may align with a role based on business requirements. Use specific roles for different advertising services, including DSPs and SSPs, to verify that services operate with limited least privileged access.