Checkout our FREE & Paid Cloud Security Training at www.cloudsecuritybootcamp.com
@francisfrancis11532 жыл бұрын
Thanks man. I am routing for cloud security.
@anshulrastogi27512 жыл бұрын
Would like to hear your views on how to monitor alerts on cloud better !!!
@CloudSecurityPodcast2 жыл бұрын
noted! Thank you Anshul
@kirangavara2 жыл бұрын
yes it's bit hard to manage overwhelming alerts, we need to do heavy tuning to make it suitable for operations. also severity associated with these alerts not always correct.
@devsecop42842 жыл бұрын
@@kirangavara 100%, most tools are designed for broad-based detection that is dependent on binary controls (limited), signatures (limited), and profiling (can be erroneous). What will help is the old sliding scale of adversary vs defender - we have to be aware of their TTP (that is always evolving) and tools that are empowered with this rich database (think threat research) to the specific asset (workload) you are protecting is needed. For eg, there is no value in a tool that is a linux supported EPP when your target is Windows.
@GTOneShots8 ай бұрын
very good non-technical examples that made the concepts easy to understand
@CloudSecurityPodcast8 ай бұрын
Glad it was easy to understand. Any cloud security topic that is top of mind for you at the moment?
@bobyluvs Жыл бұрын
Thnq Ashish for sharing Another precise video for these buzz words. And products from various vendors are using marketing strategies to cash out. But in reality there is lot of noise and false positives. Mostly capability and resources issues to manage these tools, is an overhead to Org. Plz do a video on how to do atleast 80% of Observability setup for all type of Workloads on cloud like CNAPP...
@ChiragNayyar912 жыл бұрын
Really informative and easy to understand, keep it up bro
@CloudSecurityPodcast2 жыл бұрын
Glad you got value from this Chirag!
@CloudSecurityPodcast2 жыл бұрын
Thank you @Chirag Nayyar ! Is there a Cloud Security Topic that is top of mind for you that we can cover on the Channel?
@vbarval2 жыл бұрын
Would love to see video on CIEM for seeing in real world use cases.
@CloudSecurityPodcast2 жыл бұрын
noted for a future video - thank you Vineet!
@devsecop42842 жыл бұрын
@@CloudSecurityPodcast Keen as well. I have found most implementations by current vendors of CIEM to be basic and limited.
@pratisthasrivastav53082 жыл бұрын
Loved this! Would love to see more jargons being broke down into more consumable nuggets 🎉
@devsecop42842 жыл бұрын
If only we had such good and easy-to-understand content when I started! Took a while to wrap my head around this when I started years ago :)
@CloudSecurityPodcast2 жыл бұрын
@@devsecop4284 Is there a Cloud Security Topic that is top of mind for you that we can cover on the Channel?
@CloudSecurityPodcast2 жыл бұрын
Thank you Pratistha! Is there a Cloud Security Topic that is top of mind for you that we can cover on the Channel?
@Youdude22 жыл бұрын
Can you give examples of CWPP and CSPM vendors?
@CloudSecurityPodcast2 жыл бұрын
Palo Alto Prisma Cloud, Wiz, Lightspin, Orca Security & many more - most of them are covering both and CNAPP too.
@CloudSecurityPodcast2 жыл бұрын
Hope this answered your question?
@devsecop42842 жыл бұрын
@@CloudSecurityPodcast few CNAPP players through - IMO only Aqua Security & Prisma Cloud (They've been around since the early days and cover most of what Gartner defines them Supply Chain, CSPM, CWPP, CIEM etc).
@andyjaneen12 жыл бұрын
a whole new rash of "data-centric" cloud security tools... Gartner just defined, Data Security Posture Managment (DSPM). We add Data Discovery, Data Access Control (DAC), and Data Detection and Response (DDR)
@devsecop42842 жыл бұрын
Gartner do love their acronyms, to be fair it does help defenders understand the challenge and appropriate response.
@anuragsom09 Жыл бұрын
very nice
@Youdude22 жыл бұрын
Can you discuss how some CNAPP vendors can be 100% agentless?
@devsecop42842 жыл бұрын
In limited context, they could be - if inline prevention can be taken out of the equation or if the rapid detection can lead to network isolation using the control plane. For, e.g., in the K8s context using behavioural detection/signatures etc., determine a pod is compromised, then use API to block its network connectivity or kill the pod to mitigate the propagation of potential privilege escalation, lateral movement etc. Other use cases in Cloud Native Workloads are possible eg serverless I would imagine.
@francisfrancis11532 жыл бұрын
Should we call these tools frameworks as well?
@CloudSecurityPodcast2 жыл бұрын
i personally wouldn't call them framework as they features expected from the 4 Cs.
@kirangavara2 жыл бұрын
I would rather say, you could use these tools to comply with your compliance framework control requirements
@francisfrancis11532 жыл бұрын
@@kirangavara Thanks for clarifying. That means the tools are solutions to achieve compliance.
@devsecop42842 жыл бұрын
I would be careful when presenting these tools, a lot of times the assumption is that CSPM will "make me compliant", and unscrupulous sales reps will try to capitalize on that. The CSPM tool is only as effective as its ability to ingest, process and map the findings in clouds. An unsupported cloud resource or an unchecked framework/standard means gaps. The CSPM tools for Compliance Control should be taken with a grain of salt, and are fine for "check in the box" and a litmus to overall health - but should not be confused with Security!
@kirangavara2 жыл бұрын
Palo Alto Prisma Cloud leader in this category followed by few other
@CloudSecurityPodcast2 жыл бұрын
Would you say in your personal opinion Palo Alto is good in all of these categories?
@kirangavara2 жыл бұрын
@@CloudSecurityPodcast yes, its my personal opinion, paloalto keeps on innovating 💡 and they will be bringing SCA capability to prisma cloud to make more devsecops friendly
@devsecop42842 жыл бұрын
IMO Technical Leader - no. Prisma Cloud is a stiched-up solution that had decent product acquisitions that gave it a breadth of coverage but NOT depth in all cases. The self-developed capabilities lack widespread adoption and are a failed start, their version of WAF, and CIEM for example have limited use cases in the Cloud world (from a capability and cost perspective. Their Shift left Capability is extremely limited (IaC scanning, no integrated code scanning) and the recent foray into Supply Chain through acquisition is an attempted bolt-on. Do not even get me started on the CWP/twist lock that is "noisy" and does not look like it stops attacks. Good at marketing though. Gotta peel the layers of the Onion :)
@devsecop42842 жыл бұрын
@@kirangavara acquisition != innovation :)
@kirangavara2 жыл бұрын
@@devsecop4284 It is not but they do not want to reinvent the wheel when they have cash to buy innovation built by others :)
@bhuvaneshwarannaldasula8558 Жыл бұрын
hi want to guide for career in cloud security certification. I have completed az-500 certificate. after that what should I do my I know,please help me now I am working as cloud operation engineering