Security Operations with Elliott Abraham and Jason Bisson

Security Operations with Elliott Abraham and Jason Bisson

We're discussing security operations on the podcast this week with your hosts Priyanka Vergadia and Mark Mirchandani. They're joined by Elliott Abraham and Jason Bisson who start the interview explaining that they created the CLAM framework to help customers use Google Cloud security features to their fullest potential to create safe projects and relaxed clients.

The CLAM (Cloud Logging Alerting and Monitoring) framework came about specifically to help customers transition products to, and run products securely in, the cloud. Using the Mitre GCP Matrix, the security team addressed each element with GCP product solutions, from initial access to persistence and beyond. CLAM is GCP specific, taking into account the default security measures GCP already provides and supplementing these measures with appropriate procedures for each client. Once the framework is in place and things are secure, clients can build on that with operational controls, such as SRE best practices.

Elliott explains the shared security model and how clients can shift more of the security responsibility to the cloud service provider by employing more managed services. Jason tells us about VPC Service Controls and how they allow clients to set specific security rules such as from where data can be accessed. They go on to describe the GCP Security Command Center and the tools available there.

We wrap up the interview with some tips from our guests, including what to do if you are compromised.

Elliott Abraham

Elliott Abraham is a Security and Compliance Specialist based in Atlanta. Elliott works with Financial Services, Healthcare and Life Sciences and other Select Accounts migrating to or expanding their footprint on the Google Cloud Platform. Elliott has helped many customers to operationalize GCP Security solutions in alignment with their security, compliance, and regulatory requirements.

Jason Bisson

Jason Bisson is a Security and Compliance Specialist based in NYC. He works with Financial Services, Healthcare, Government, and Retail customers to explain the security, compliance, and regulatory abilities of Google Cloud Platform.

Cool things of the week
  • Announcing Google Cloud Next '20: OnAir blog
  • Celebrating a decade of data: BigQuery turns 10 blog
    • A very special BigQuery Day (The Data Show, w/ Felipe Hoffa & Yufeng Guo) video
Interview
  • CLAM Framework pdf
  • Mitre site
  • Mitre ATT&CK site
  • Mitre GCP Matrix site
  • SRE Handbook site
  • VPC Service Controls site
  • Cloud Audit Logs site
  • Cloud Data Loss Prevention site
  • GCP Podcast Episode 218: Chronicle Security with Dr. Anton Chuvakin and Ansh Patniakpodcast
  • GCP Podcast Episode 221: BeyondCorp with Robert Sadowski podcast
Tip of the week

Yuri Grinshteyn talks about the new logging feature.

What's something cool you're working on?

Priyanka is working on Building an Unbreakable DevOps Pipeline with Google Cloud.

Mark is working on more videos and will be speaking at Next.

Jaksot(335)

Managed Service for Prometheus with Lee Yanco and Ashish Kumar

Managed Service for Prometheus with Lee Yanco and Ashish Kumar

Hosts Carter Morgan and Anthony Bushong are in the studio this week! We're talking about Prometheus with guests Lee Yanco and Ashish Kumar and learning about the build process for Google Cloud's Manag...

20 Heinä 202237min

Distributed Cloud Edge for Telcos with DP Ayyadevara and Krishna Garimella

Distributed Cloud Edge for Telcos with DP Ayyadevara and Krishna Garimella

Stephanie Wong and Carter Morgan are back this week learning about Google's Distributed Cloud Edge for telcos with guests Krishna Garimella and DP Ayyadevara. Launched last year, Google Distributed Cl...

13 Heinä 202236min

Disaster Recovery with Cody Ault and Jo-Anne Bourne

Disaster Recovery with Cody Ault and Jo-Anne Bourne

Your hosts Max Saltonstall and Carter Morgan talk with guests Cody Ault and Jo-Anne Bourne of Veeam. Veeam is revolutionizing the data space by minimizing data loss impacts and project downtime with e...

29 Kesä 202236min

Contact Center AI with Amit Kumar and Vasili Triant

Contact Center AI with Amit Kumar and Vasili Triant

This week on the GCP Podcast, Carter Morgan and Max Saltonstall are joined by Amit Kumar and Vasili Triant. Our guests are here to talk about new features in Contact Center AI. Amit starts the show he...

22 Kesä 202236min

New Pi World Record with Emma Haruka Iwao and Sara Ford

New Pi World Record with Emma Haruka Iwao and Sara Ford

Carter Morgan and Brian Dorsey are working on their math skills today with guests Emma Haruka Iwao and Sara Ford. What kind of computing power does it take to break the world record for pi computation...

15 Kesä 202239min

FinOps with Joe Daly

FinOps with Joe Daly

On the podcast this week, guest Joe Daly tells Stephanie Wong, Mark "Money" Mirchandani, and our listeners all about FinOps principles and how they're helping companies take advantage of the cloud whi...

8 Kesä 202239min

Network Analyzer with Zach Seils and Manasa Chalasani

Network Analyzer with Zach Seils and Manasa Chalasani

Stephanie Wong and Lorin Price welcome guests Zach Seils and Manasa Chalasani to talk about networking and the newly released Network Analyzer. Google Cloud's Network Intelligence Center is described ...

1 Kesä 202238min

GKE Release Channels with Kobi Magnezi and Abdelfettah Sghiouar

GKE Release Channels with Kobi Magnezi and Abdelfettah Sghiouar

Kaslin Fields and Mark Mirchandani learn how GKE manages their releases and how customers can take advantage of the GKE release channels for smooth transitions. Guests Abdelfettah Sghiouar and Kobi Ma...

25 Touko 202247min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
rss-ootsa-kuullut-tasta
politiikan-puskaradio
ootsa-kuullut-tasta-2
tervo-halme
viisupodi
rss-podme-livebox
rss-asiastudio
rikosmyytit
the-ulkopolitist
et-sa-noin-voi-sanoo-esittaa
otetaan-yhdet
radio-antro
rss-sanna-ukkola-show-verkkouutiset
io-techin-tekniikkapodcast
aihe
rss-tasta-on-kyse-ivan-puopolo-verkkouutiset
rss-kyselytunti
rss-tekkipodi