Speakers: David Hazar, Yuto Takei, Nobuaki Sako
The cloud is not inherently more secure than our on-premises environments, but security is not typically the reason companies are moving to the cloud. The cloud beckons to us with promises of less (shared) responsibility, scalability, automation, and cost savings. However, with these promises, sometimes comes the consequences of less visibility and less control. Join us as we discuss how organizations can gain back some of the visibility and control in their cloud environments by implementing repeatable architectural patterns. Please join us as we discuss micro-segmentation, network visibility and control, identity and more.
Learning Objectives:
Hub and spoke network patterns in the top cloud providers
The ups and downs of cloud-native network security
Identity federation and credential management
クラウドはオンプレミス環境よりも本質的に安全というわけではありませんが、そもそも一般的に組織がクラウドに移行する理由はセキュリティではありません。クラウドは、責任共有モデルやスケーラビリティ、自動化やコスト削減において魅力的です。しかし一方で、可視性が低下してしまい、制御可能な範囲も狭まります。このセッションでは、クラウド環境において可視性や制御性を損なわないアーキテクチャ実装についてお話します。マイクロセグメンテーションやネットワークの可視性と制御、ID管理など、さまざまなトピックについて取り上げますので是非ご参加ください!
ディスカッション内容:
各クラウド事業者におけるハブ&スポークネットワークトポロジ
クラウドネイティブネットワークセキュリティの浮き沈み
IDフェデレーションとクレデンシャル管理
About David Hazar
David is a security consultant based in Salt Lake City, Utah focused on vulnerability management, application security, cloud security, and DevOps. David has 20+ years of broad, deep technical experience gained from a wide variety of IT functions held throughout his career, including: Developer, Server Admin, Network Admin, Domain Admin, Telephony Admin, Database Admin/Developer, Security Engineer, Risk Manager, and AppSec Engineer. David is a co-author and instructor for MGT516: Building and Leading Vulnerability Management Programs, an instructor for and contributor to SEC540: Cloud Security and DevSecOps Automation, and has also developed and led technical security training initiatives at many of the companies for which he has worked. Learn more about David at https://www.sans.org/profiles/david-h...
SANS Cloud Security focuses the deep resources of SANS on the growing threats to The Cloud by providing training, GIAC certification, research, and community initiatives to help security professionals build, deploy and manage secure cloud infrastructure, platforms, and applications.
SANS Cloud Security Curriculum: www.sans.org/cloud-security
GIAC Cloud Security Certifications: https://www.giac.org/focus-areas/clou...
LinkedIn: / sanscloudsec
Discord: www.sansurl.com/cloud-discord
Twitter: @SANSCloudSec