Keeping the wolves at bay in the cloud
Don't rely on a single line of defense

Keeping the wolves at bay in the cloud

If you are working in the cloud, then appropriately securing your environment must be a top priority. There are a variety of resources readily available to help you think about and deploy a defense in depth strategy. If you are new to the cloud then I would suggest adding the following to your resource list:

Cloud Security Alliance - Good overview information and the Cloud Controls Matrix is great reference when looking at controls for cloud solutions.

Cloud Provider Security Blogs: Both AWS and Microsoft have dedicated blogs focused on cloud security. This is a fast moving area so I recommend putting them on your weekly reading list.

When you build out your environment make sure you look at the reference architectures that both Microsoft (and here) and AWS (includes PCI and NIST examples) have published. Starting from one of these models should help eliminate some internal debates and risk.

The Center for Internet Security (CIS) published the CIS AWS Foundations Benchmark, a set of security configuration best practices for Amazon Web Services (AWS). This is a great reference point to use when looking at your cloud security implementation. Although specific to AWS, you can map the concepts pretty easily to Azure as well. Even better, AWSLabs has a GitHub repository with sample alerts and Lamda functions that you can use to quickly take and apply the best practices in your environment. The security center has a good set of resources as well.

If Azure is your focus, make sure that you are taking a hard look at leveraging Azure Security Center. Trend Micro's blog has some good guidance. If you are deploying PaaS Services, then you should take a look at Azure Platform as a Service (PaaS) Security Best Practices. (Note 3/9 - Msft just launched a new Azure Architecture  Center here)

If servers are cattle, then you have to guard them like sheep. But don't do it the old fashion way. Think about SecDevOps and automation for your security architecture. A little code will go a long way in helping keep the wolves at bay.

 

Note - Msft just launched a new #Azure #Architecture Center as well. https://docs.microsoft.com/en-us/azure/architecture/

回复

要查看或添加评论,请登录

Pat Beahan的更多文章

  • Learning Opportunity: Hotchips free for all

    Learning Opportunity: Hotchips free for all

    The Hotchips conference is one of the key events to understand how computing hardware is evolving. As hardware…

  • Cloud Learning:The Tale of Two Certies

    Cloud Learning:The Tale of Two Certies

    It was the best of times, after the worst of times, it was the season of Light, after a season of darkness, yes I am…

    5 条评论
  • New Years resolution: Keep your cloud secure

    New Years resolution: Keep your cloud secure

    Glad to say that I ended 2018 by passing the Certified Cloud Security Professional exam (CCSP). Overall a good…

  • Cloud Marketplaces: Let the buyer beware

    Cloud Marketplaces: Let the buyer beware

    The cloud marketplaces are useful tools. I believe the major cloud providers set some basic reviews/standards for…

    3 条评论
  • Keeping the safety on: AWS and Azure cloud governance with policies

    Keeping the safety on: AWS and Azure cloud governance with policies

    Cloud providers talk about security and the shared responsibility model. They do a pretty good job on their portion.

    1 条评论
  • Facing adversity at work

    Facing adversity at work

    For many of us, our jobs define who we are. So when we face adversity, whether it is a dis-agreeable co-worker, a tough…

    3 条评论
  • Celebrate your cloud savings

    Celebrate your cloud savings

    Competition is a wonderful thing. AWS has supported the concept of VM reserved instances for several years and have…

    1 条评论
  • Cloud Learnings - be like a shark

    Cloud Learnings - be like a shark

    Many in the oil and gas IT industry have experienced challenges over the past 2 years. As my father used to say…

  • Catapulting the cloud with More than Moore

    Catapulting the cloud with More than Moore

    Microsoft's Catapault project has recently made the news. Congrats to Doug Burger (a friend from the Msft days) and…

  • Amazon - some interesting charts

    Amazon - some interesting charts

    Amazon is a company I admire. They have a great customer focus and continual strong innovation.

    2 条评论

社区洞察

其他会员也浏览了