Mastering Cloud Security Policy Code

Опубликовано: 11 Октябрь 2024
на канале: SANS Cloud Security
426
16

The Cloud is enabling businesses to quickly adopt and use technology in ways that we've never imagined before. Security teams need to find ways to keep up; automation is the solution. By using Policy as Code tools we can define and enforce security guardrails. This allows developers and cloud engineers to continue shipping features while bringing the confidence to everybody that security requirements are being met.

Learning Objectives:
Examine how unsafe systems can accidentally be deployed into production
Automatically identify cloud environments that don't meet security requirements
Prevent further misconfigurations via automated Policy as Code enforcement points using tools such as easy_infra and Checkov
Remediate misconfigured systems
Automate reassessing cloud systems, and generate evidence for compliance and audit teams

Prerequisite Knowledge:
Comfortable with Linux command line tools
Comfortable with git-based version control systems
Comfortable reading configuration files

System Requirements:
A modern web browser, preferably Chrome
AWS account with root access or an IAM user with Administrator Access permissions
If you need an AWS account, you can create a free tier account with root access at https://aws.amazon.com/free/
The cost to complete the workshop will be minimal (pennies).

This content supports materials and concepts from SEC540: Cloud Security and DevSecOps Automation, https://www.sans.org/cyber-security-c...

About the Speaker
Jon Zeolla is co-founder and CTO at Seiso, where he works with companies to secure their use of cloud native applications and environments, including contributing directly to open-source projects and industry standards on their behalf. In 2021 he was awarded Start-up Innovator of the Year by the Pittsburgh Technology Council. He is heavily involved in the Pittsburgh cybersecurity community in various ways, is an IANS faculty member, and a SANS Associate Instructor for SEC540: Cloud Security and DevSecOps Automation. Learn more about Jon at https://www.sans.org/profiles/jon-zeo...

SANS Cloud Security focuses the deep resources of SANS on the growing threats to The Cloud by providing training, GIAC certification, research, and community initiatives to help security professionals build, deploy and manage secure cloud infrastructure, platforms, and applications.

SANS Cloud Security Curriculum: www.sans.org/cloud-security
GIAC Cloud Security Certifications: https://www.giac.org/focus-areas/clou...
LinkedIn:   / sanscloudsec  
Discord: www.sansurl.com/cloud-discord
Twitter: @SANSCloudSec