Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

2.2.1. Identity as the Primary Security Perimeter

💡 First Principle: Because cloud resources are reachable from anywhere, the strongest and most consistent control point is no longer a network location — it's confirming exactly who is making the request, every time, which is why identity is described as the primary security perimeter rather than just a security perimeter.

This builds directly on Phase 1.3: a firewall protects a network location, but a stolen credential works from any network location, so identity verification has to be the layer that travels with the user. This doesn't erase the need for network protections (Phase 4) — it means identity is the first and most reliable checkpoint, with network and other layers reinforcing it rather than replacing it.

⚠️ Exam Trap: "Primary" perimeter does not mean "only" perimeter. Defense-in-depth (2.1.2) still applies — identity is the first line, not the last.

Reflection Question: Why does a stolen password remain dangerous regardless of which network the attacker connects from, in a way that a stolen firewall rule does not?

See how it connects
Alvin Varughese
Written byAlvin Varughese
Founder18 professional certifications