Security Operations with Elliott Abraham and Jason Bisson

Security Operations with Elliott Abraham and Jason Bisson

We're discussing security operations on the podcast this week with your hosts Priyanka Vergadia and Mark Mirchandani. They're joined by Elliott Abraham and Jason Bisson who start the interview explaining that they created the CLAM framework to help customers use Google Cloud security features to their fullest potential to create safe projects and relaxed clients.

The CLAM (Cloud Logging Alerting and Monitoring) framework came about specifically to help customers transition products to, and run products securely in, the cloud. Using the Mitre GCP Matrix, the security team addressed each element with GCP product solutions, from initial access to persistence and beyond. CLAM is GCP specific, taking into account the default security measures GCP already provides and supplementing these measures with appropriate procedures for each client. Once the framework is in place and things are secure, clients can build on that with operational controls, such as SRE best practices.

Elliott explains the shared security model and how clients can shift more of the security responsibility to the cloud service provider by employing more managed services. Jason tells us about VPC Service Controls and how they allow clients to set specific security rules such as from where data can be accessed. They go on to describe the GCP Security Command Center and the tools available there.

We wrap up the interview with some tips from our guests, including what to do if you are compromised.

Elliott Abraham

Elliott Abraham is a Security and Compliance Specialist based in Atlanta. Elliott works with Financial Services, Healthcare and Life Sciences and other Select Accounts migrating to or expanding their footprint on the Google Cloud Platform. Elliott has helped many customers to operationalize GCP Security solutions in alignment with their security, compliance, and regulatory requirements.

Jason Bisson

Jason Bisson is a Security and Compliance Specialist based in NYC. He works with Financial Services, Healthcare, Government, and Retail customers to explain the security, compliance, and regulatory abilities of Google Cloud Platform.

Cool things of the week
  • Announcing Google Cloud Next '20: OnAir blog
  • Celebrating a decade of data: BigQuery turns 10 blog
    • A very special BigQuery Day (The Data Show, w/ Felipe Hoffa & Yufeng Guo) video
Interview
  • CLAM Framework pdf
  • Mitre site
  • Mitre ATT&CK site
  • Mitre GCP Matrix site
  • SRE Handbook site
  • VPC Service Controls site
  • Cloud Audit Logs site
  • Cloud Data Loss Prevention site
  • GCP Podcast Episode 218: Chronicle Security with Dr. Anton Chuvakin and Ansh Patniakpodcast
  • GCP Podcast Episode 221: BeyondCorp with Robert Sadowski podcast
Tip of the week

Yuri Grinshteyn talks about the new logging feature.

What's something cool you're working on?

Priyanka is working on Building an Unbreakable DevOps Pipeline with Google Cloud.

Mark is working on more videos and will be speaking at Next.

Jaksot(335)

Cloud Security Megatrends with Phil Venables

Cloud Security Megatrends with Phil Venables

We're back for a new, exciting year of the Google Cloud Platform Podcast! Mark Mirchandani and Carter Morgan start 2022 with a jointly hosted interview with Anton Chuvakin and Timothy Peacock of the C...

19 Tammi 202232min

2021 Year End Wrap Up

2021 Year End Wrap Up

We're finishing out 2021 with a celebration of our favorite episodes and topics from the year! From new tools for Cost Optimization in GKE and advances in AI to tips for improving feelings of imposter...

15 Joulu 202143min

Imposter Syndrome in Tech with Carter Morgan

Imposter Syndrome in Tech with Carter Morgan

Carter Morgan takes the guest seat today to chat with host Stephanie Wong about imposter syndrome in tech. The technology ecosystem is constantly changing, with new advances every day. To keep up, tec...

8 Joulu 202125min

Serverless, Redefined with Jason Polites

Serverless, Redefined with Jason Polites

Guest Jason Polites joins Stephanie Wong and Bukola Ayodele this week to talk about advances in serverless computing with Cloud Run and how developers and wallets are benefiting. Cloud Run, a managed ...

1 Joulu 202123min

Managing ML Lifecycles with Vertex AI with Erwin Huizenga

Managing ML Lifecycles with Vertex AI with Erwin Huizenga

We're learning all about Vertex AI this week as Carter Morgan and Jay Jenkins host guest Erwin Huizenga. He helps us understand what is meant by Asia Pacific and how Machine Learning is growing there....

17 Marras 202138min

State of DevOps Report 2021 with Nathen Harvey and Dustin Smith

State of DevOps Report 2021 with Nathen Harvey and Dustin Smith

This week, Stephanie Wong and Carter Morgan are talking about the recently released State of DevOps Report. Guests Dustin Smith and Nathen Harvey tell us all about DORA, the research group working to ...

10 Marras 202145min

Assured Workloads with Bryce Buffaloe and Mikaela Misaka

Assured Workloads with Bryce Buffaloe and Mikaela Misaka

Mark Mirchandani and Max Saltonstall are back this week to learn everything there is to know about Assured Workloads with Bryce Buffaloe and Mikaela Misaka. Google's Assured Workloads helps companies ...

3 Marras 202133min

Geospatial Cloud and Earth Engine with Chad Jennings and Joel Conkling

Geospatial Cloud and Earth Engine with Chad Jennings and Joel Conkling

On the podcast this week, Mark Mirchandani and Carter Morgan host guests Chad Jennings and Joel Conkling in a fascinating discussion about Earth Engine and performing geospatial processing to help com...

27 Loka 202142min

Suosittua kategoriassa Politiikka ja uutiset

uutiscast
aikalisa
rss-ootsa-kuullut-tasta
politiikan-puskaradio
ootsa-kuullut-tasta-2
tervo-halme
viisupodi
rss-vaalirankkurit-podcast
rss-podme-livebox
rss-asiastudio
rikosmyytit
the-ulkopolitist
et-sa-noin-voi-sanoo-esittaa
otetaan-yhdet
io-techin-tekniikkapodcast
linda-maria
radio-antro
rss-sanna-ukkola-show-verkkouutiset
aihe
rss-tasta-on-kyse-ivan-puopolo-verkkouutiset