Security Operations with Elliott Abraham and Jason Bisson

Security Operations with Elliott Abraham and Jason Bisson

We're discussing security operations on the podcast this week with your hosts Priyanka Vergadia and Mark Mirchandani. They're joined by Elliott Abraham and Jason Bisson who start the interview explaining that they created the CLAM framework to help customers use Google Cloud security features to their fullest potential to create safe projects and relaxed clients.

The CLAM (Cloud Logging Alerting and Monitoring) framework came about specifically to help customers transition products to, and run products securely in, the cloud. Using the Mitre GCP Matrix, the security team addressed each element with GCP product solutions, from initial access to persistence and beyond. CLAM is GCP specific, taking into account the default security measures GCP already provides and supplementing these measures with appropriate procedures for each client. Once the framework is in place and things are secure, clients can build on that with operational controls, such as SRE best practices.

Elliott explains the shared security model and how clients can shift more of the security responsibility to the cloud service provider by employing more managed services. Jason tells us about VPC Service Controls and how they allow clients to set specific security rules such as from where data can be accessed. They go on to describe the GCP Security Command Center and the tools available there.

We wrap up the interview with some tips from our guests, including what to do if you are compromised.

Elliott Abraham

Elliott Abraham is a Security and Compliance Specialist based in Atlanta. Elliott works with Financial Services, Healthcare and Life Sciences and other Select Accounts migrating to or expanding their footprint on the Google Cloud Platform. Elliott has helped many customers to operationalize GCP Security solutions in alignment with their security, compliance, and regulatory requirements.

Jason Bisson

Jason Bisson is a Security and Compliance Specialist based in NYC. He works with Financial Services, Healthcare, Government, and Retail customers to explain the security, compliance, and regulatory abilities of Google Cloud Platform.

Cool things of the week
  • Announcing Google Cloud Next '20: OnAir blog
  • Celebrating a decade of data: BigQuery turns 10 blog
    • A very special BigQuery Day (The Data Show, w/ Felipe Hoffa & Yufeng Guo) video
Interview
  • CLAM Framework pdf
  • Mitre site
  • Mitre ATT&CK site
  • Mitre GCP Matrix site
  • SRE Handbook site
  • VPC Service Controls site
  • Cloud Audit Logs site
  • Cloud Data Loss Prevention site
  • GCP Podcast Episode 218: Chronicle Security with Dr. Anton Chuvakin and Ansh Patniakpodcast
  • GCP Podcast Episode 221: BeyondCorp with Robert Sadowski podcast
Tip of the week

Yuri Grinshteyn talks about the new logging feature.

What's something cool you're working on?

Priyanka is working on Building an Unbreakable DevOps Pipeline with Google Cloud.

Mark is working on more videos and will be speaking at Next.

Jaksot(335)

Fathers of the Internet with Vint Cerf

Fathers of the Internet with Vint Cerf

This week, Stephanie Wong and Anthony Bushong introduce a special podcast of the Gtalk at Airbus speaker series where prestigious Googlers have been invited to talk with Airbus. In this episode, Vint ...

23 Maalis 202241min

SQL Commenter with Nimesh Bhagat and Morgan McLean

SQL Commenter with Nimesh Bhagat and Morgan McLean

First time co-host Jan Kleinert joins Mark Mirchandani this week to talk about database observability and the cool tools that make it possible. Morgan McLean and Nimesh Bhagat describe database observ...

16 Maalis 202242min

Google Cloud Reader with Jenny Brown

Google Cloud Reader with Jenny Brown

On the show this week, we're talking about Google Cloud Reader, a nifty podcast we created to narrate Google Tech blog posts. Host Jenny Brown tells us her inspiration for creating Google Cloud Reader...

7 Maalis 202248min

Looker with Leigha Jarett and Debi Cabrera

Looker with Leigha Jarett and Debi Cabrera

Guests Leigha Jarett and Debi Cabrera from the Looker team join Mark Mirchandani this week to talk about this powerful tool. Looker, Google's data analytics platform, was built to provide enterprise c...

23 Helmi 202245min

Data Journeys with Bruno Aziza

Data Journeys with Bruno Aziza

On the show this week, Mark Mirchandani and Stephanie Wong share two popular episodes of Bruno Aziza's YouTube series Data Journeys. First up, Bruno talks with Aaron Biller of Postmates about their tr...

16 Helmi 202243min

Pulumi and Kubernetes Releases with Kat Cosgrove

Pulumi and Kubernetes Releases with Kat Cosgrove

Brian Dorsey and Kaslin Fields welcome Kat Cosgrove of Pulumi this week to talk about what's new with Kubernetes 1.24. Pulumi is infrastructure as code, allowing developers to use whatever language th...

9 Helmi 202234min

Redesigning the Cloud SDK and CLI with Wael Manasra and Cody Oss

Redesigning the Cloud SDK and CLI with Wael Manasra and Cody Oss

This week on the podcast, Wael Manasra and Cody Oss join hosts Carter Morgan and Mark Mirchandani to chat about new branding in Cloud SDK and gcloud CLI. Google Cloud SDK was built and designed to tak...

2 Helmi 202244min

Resiliency at Shopify with Camilo Lopez and Tai Dickerson

Resiliency at Shopify with Camilo Lopez and Tai Dickerson

Carter Morgan and Stephanie Wong host Shopify guests Camilo Lopez and Tai Dickerson this week. Shopify streamlines the online purchasing process so merchants and customers can transact with confidence...

26 Tammi 202239min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
rss-ootsa-kuullut-tasta
politiikan-puskaradio
ootsa-kuullut-tasta-2
tervo-halme
viisupodi
rss-vaalirankkurit-podcast
rss-podme-livebox
rss-asiastudio
rikosmyytit
the-ulkopolitist
et-sa-noin-voi-sanoo-esittaa
otetaan-yhdet
io-techin-tekniikkapodcast
linda-maria
radio-antro
rss-sanna-ukkola-show-verkkouutiset
aihe
rss-tasta-on-kyse-ivan-puopolo-verkkouutiset