Cloud Security Baseline For Scale

Cloud Security Baseline For Scale

Cloud Security Podcast - Automating a Security Baseline in Cloud with Olivia Siow (⁠Olivia's Linkedin⁠) and David Levitsky (⁠David's Linkedin⁠). In this episode Olivia and David shared their experience of how they were able to empower developers to always do the right thing through positive reinforcements like making default libraries as part of the AWS Account build to scale security across their organisation. There were lot more gems dropped so def check out the episode.


Episode YouTube Video - ⁠https://www.youtube.com/watch?v=8kpiDcowl2A⁠


Host Twitter: Ashish Rajan (⁠⁠@hashishrajan⁠⁠)

Guest Socials: Olivia Siow (⁠Olivia's Linkedin⁠) and David Levitsky (⁠David's Linkedin⁠)

Podcast Twitter - ⁠⁠@CloudSecPod⁠⁠ ⁠⁠@CloudSecureNews⁠⁠

If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:

- ⁠⁠Cloud Security News ⁠⁠

- ⁠⁠Cloud Security BootCamp⁠⁠


Spotify TimeStamp for Interview Questions

A word from our sponsors - you can visit them on ⁠⁠snyk.io/csp⁠⁠

(00:00) Introduction

(04:16) A bit about Olivia Siow

(04:31) A bit about David Levitsky

(04:54) Cloud Security Baseline

(06:38) Do all organisations need a cloud security baseline?

(07:16) Does cloud security baseline help with scaling?

(07:34) Success Metrics for establishing cloud security baseline

(10:41) The cultural side of building a baseline

(11:40) Anatomy of AWS Cloud Account at Scale

(12:58) Building Blocks of Cloud Security Baseline

(16:54) Non Technical Challenges

(19:24) Organisation Challenges

(21:41) Would larger organisations have multiple baselines?

(23:34) Baseline for Multicloud or hybridcloud

(26:10) Use case with terraform cloud and route 53

(30:26) What telemetry is important

(32:36) Segregating Logs in a cloud context

(33:58) Can be done with any cloud and tool of choice

(34:43) Baseline vs CNAPP + CSPM

(37:56) Team skill requirement

(39:16) The fun section

(45:13) Where can you connect with Olivia and David to continue the conversation

See you at the next episode!

Jaksot(344)

Building a SOC Team in 2024 - Automation & AI

Building a SOC Team in 2024 - Automation & AI

What is the future of SOC? In this episode Ashish sat down with Allie Mellen, Principal Analyst at Forrester, to explore the current state of security operations and the evolving role of AI in cyberse...

15 Loka 202456min

Cloud Identity Lifecycle Management Explained!

Cloud Identity Lifecycle Management Explained!

In this episode Ashish Rajan sits down with Shashwat Sehgal, co-founder and CEO of P0 Security, to talk about the complexities of cloud identity lifecycle management. Shashwat spoke to us about why tr...

8 Loka 202433min

Traditional PAM vs Cloud CPAM for a cloud first world

Traditional PAM vs Cloud CPAM for a cloud first world

In this episode of the Cloud Security Podcast, Ashish sat down with Art Poghosyan, CEO and co-founder of Britive, to explore the changing world of identity and access management (IAM) in the cloud era...

4 Loka 202434min

The Role of Cloud Security Research in 2024

The Role of Cloud Security Research in 2024

Why does Cloud Security Research matter in 2024? At fwd:cloudsec EU in Brussels, we sat down with Scott Piper, a renowned cloud security researcher at Wiz, to discuss the growing importance of cloud s...

2 Loka 202435min

Edge Security is the Key to Cloud Protection

Edge Security is the Key to Cloud Protection

How does Edge Security fit into the future of Cloud Protection ? In this episode, we sat down with Brian McHenry, Global Head of Cloud Security Engineering at Check Point at BlackHat USA, to chat abou...

20 Syys 202426min

Is your CI/CD Pipeline your Biggest Security Risk?

Is your CI/CD Pipeline your Biggest Security Risk?

How CI/CD Tools can expose your Code to Security Risks? In this episode, we’re joined by Mike Ruth, Senior Staff Security Engineer at Rippling and returning guest, live from BlackHat 2024. Mike dives ...

13 Syys 202429min

State of Cloud Security - Practitioner Edition

State of Cloud Security - Practitioner Edition

In this episode of the Cloud Security Podcast, we bring together an incredible panel of experts to explore the evolving landscape of cloud security in 2024. Hosted by Ashish Rajan, the discussion dive...

4 Syys 202456min

BlackHat USA 2024 Highlights and Recap

BlackHat USA 2024 Highlights and Recap

What were the main themes at BlackHat USA 2024? With respect to Cloud Security, maybe with a sprinkle of AI Security. Our team was on the ground at BlackHat and DefCon32 this year, we heard many talks...

28 Elo 202439min