Is CISO MAG even valuable as a resource?

Is CISO MAG even valuable as a resource?

Strap in because CISO MAG dropped the LAMEST article I've ever read and it begs the question, is it even a valuable resource to a CISO in today's market?

Let's start with the title... Okay, IaaS what client today doesn't have that?

Begins overviewing the advantages of cloud computing referencing a recent article from 2 months ago.. okay needed for those who may be unfamiliar... but is a CISO in this day and age really not familiar with IaaS? Let's keep going.

What is IaaS? The article calls it the "ideal solution for SMALL & MEDIUM SIZED ORGANIZATIONS looking for a cost-effective solution after touting load balancing and scaling... What? Then references an article from last month, another CISO MAG article that discussed legacy architectures in Cloud environments. Not the best tie-in from a research perspective and anyone who has expertise in the space of IaaS understand that the complexities of workloads, ingress/egress, containers, etc. is often lost on a SMB but I digress.

No alt text provided for this image

Now we're in the security challenges section and the topics are SLA, Platform Virtualization, and Computer Hardware issues. SLAs are a big concern for organizations but this is so vague you may as well have written nothing at all. How this is tied to security I'd love some, I don't know, evidence? Platform virtualization showcases some actual potential vulnerabilities but the virtualization lay you're likely mentioning is within the service provider. Which In a Datacenter or GCP/Azure/AWS the level of security around their physical datacenters is pretty high for the level of compliance they must meet. They later mention that you should hire an organization to manage the SLAs between their vendors, so another cost centre for a SMB? Not seeing the value but I digress.

Now for the Crown Jewel...

No alt text provided for this image

Johnny, I don't get it hardware issues for cloud computing? It's even sadder than that, the writer references their 70% statistic from an ISP resource from over a DECADE AGO. https://www.ist-lobster.org/publications/presentations/markatos-attacks.pdf This PDF outlines The LOBSTER Project addressing infrastructure monitoring large scale attacks on the Internet. This website hasn't been updated since I graduated HIGH SCHOOL! (2008, feel old yet?) Not only that but this resource overviews attacks traversing Internet Service Providers, not IaaS resources. So whoever wrote this article doesn't understand IaaS and worse yet lacks the fortitude to conduct research in the market and decade we are currently in.

No alt text provided for this image

Okay, really the rest of the article is just as worthless. CISO MAG Please remove this from your website and apologize to your community. There is a ton more that can be said here, but who wants an article on the REAL vulnerabilities for IaaS resources?

要查看或添加评论,请登录

Johnny Endrihs的更多文章

社区洞察

其他会员也浏览了