Oct 25, 2021

Defending Public Cloud for Enterprise Tricks and Tips!

 

The public cloud expansion is a reality and maintaining fences up is not easy. Come learn about AWS/Azure/GCP organization rules, policies and best practices to avoid potential threats that help to enforce good practices and avoid potential issues and misconfigurations. 

In this webcast, Moises will cover how to: 

  • - Allow new accounts, subscriptions, or project to start with security practices in place 
  • - Reduce the risk that shadow IT could grow without security policies and good practices 
  • - Enforce security good practices even if users try to resist it 
  • - Maintain cloud environments aligned with legal and privacy requirement

 Final Thoughts - Toolbox !

  1. Prowler - github.com/toniblyx/prowler
  2. Cloud Custodian -  cloudcustodian.io
  3. CheckOV - checkov.io
  4. CloudSploit - cloudsploit.com
  5. rcentry - arcentry.com
  6. Falco - falco.org
  7. ScoutSuite - github.com/nccgroup/ScoutSuite

Final Thoughts - References!

  1. CIS Benchmarks - cisecurity.org
  2. Cloud Security Alliance - cloudsecurityalliance.org
  3. OWASP - owasp.org
  4. NIST - nist.gov
  5. ENISA - www.enisa.europe.eu
  6. Each cloud provider has well-architecture guide