Security Operations with Elliott Abraham and Jason Bisson

Security Operations with Elliott Abraham and Jason Bisson

We're discussing security operations on the podcast this week with your hosts Priyanka Vergadia and Mark Mirchandani. They're joined by Elliott Abraham and Jason Bisson who start the interview explaining that they created the CLAM framework to help customers use Google Cloud security features to their fullest potential to create safe projects and relaxed clients.

The CLAM (Cloud Logging Alerting and Monitoring) framework came about specifically to help customers transition products to, and run products securely in, the cloud. Using the Mitre GCP Matrix, the security team addressed each element with GCP product solutions, from initial access to persistence and beyond. CLAM is GCP specific, taking into account the default security measures GCP already provides and supplementing these measures with appropriate procedures for each client. Once the framework is in place and things are secure, clients can build on that with operational controls, such as SRE best practices.

Elliott explains the shared security model and how clients can shift more of the security responsibility to the cloud service provider by employing more managed services. Jason tells us about VPC Service Controls and how they allow clients to set specific security rules such as from where data can be accessed. They go on to describe the GCP Security Command Center and the tools available there.

We wrap up the interview with some tips from our guests, including what to do if you are compromised.

Elliott Abraham

Elliott Abraham is a Security and Compliance Specialist based in Atlanta. Elliott works with Financial Services, Healthcare and Life Sciences and other Select Accounts migrating to or expanding their footprint on the Google Cloud Platform. Elliott has helped many customers to operationalize GCP Security solutions in alignment with their security, compliance, and regulatory requirements.

Jason Bisson

Jason Bisson is a Security and Compliance Specialist based in NYC. He works with Financial Services, Healthcare, Government, and Retail customers to explain the security, compliance, and regulatory abilities of Google Cloud Platform.

Cool things of the week
  • Announcing Google Cloud Next '20: OnAir blog
  • Celebrating a decade of data: BigQuery turns 10 blog
    • A very special BigQuery Day (The Data Show, w/ Felipe Hoffa & Yufeng Guo) video
Interview
  • CLAM Framework pdf
  • Mitre site
  • Mitre ATT&CK site
  • Mitre GCP Matrix site
  • SRE Handbook site
  • VPC Service Controls site
  • Cloud Audit Logs site
  • Cloud Data Loss Prevention site
  • GCP Podcast Episode 218: Chronicle Security with Dr. Anton Chuvakin and Ansh Patniakpodcast
  • GCP Podcast Episode 221: BeyondCorp with Robert Sadowski podcast
Tip of the week

Yuri Grinshteyn talks about the new logging feature.

What's something cool you're working on?

Priyanka is working on Building an Unbreakable DevOps Pipeline with Google Cloud.

Mark is working on more videos and will be speaking at Next.

Episoder(335)

Database Migration Service with Shachar Guz, Inna Weiner, and Gabe Weiss

Database Migration Service with Shachar Guz, Inna Weiner, and Gabe Weiss

Stephanie Wong talks with guests Shachar Guz, Inna Weiner, and Gabe Weiss about Google's Database Migration Service and how it helps companies move data to Google Cloud. What typically is a complicate...

16 Nov 202240min

ML/AI Data Science for Data Analytics with Jed Dougherty and Dan Darnell

ML/AI Data Science for Data Analytics with Jed Dougherty and Dan Darnell

On the show this week, Carter Morgan and Anu Srivastava talk about AI and ML data analytics with Dataiku VP of Platform Strategy, Jed Dougherty, and Head of Product Marketing, Dan Darnell. Dataiku is ...

9 Nov 202232min

Assured Workloads with Key Access Justifications with Bryce Buffaloe and Seth Denney

Assured Workloads with Key Access Justifications with Bryce Buffaloe and Seth Denney

Hosts Max Saltonstall and Daryl Ducharme are joined by Bryce Buffaloe and Seth Denney to chat about Assured Workloads and the sovereignty control Key Access Justifications so customers can see how the...

2 Nov 202242min

Digital Sovereignty with Archana Ramamoorthy and Julien Blanchez

Digital Sovereignty with Archana Ramamoorthy and Julien Blanchez

This week, Max Saltonstall and Chloe Condon welcome guests Archana Ramamoorthy and Julien Blanchez to talk about digital sovereignty and what goes into a technical strategy for dealing with this compl...

26 Okt 202236min

Top 5 Data & Analytics Launches from Next 2022 with Bruno Aziza and Maire Newton

Top 5 Data & Analytics Launches from Next 2022 with Bruno Aziza and Maire Newton

Debi Cabrera and Stephanie Wong have more great Next content this week as we focus on launches specifically related to data and analytics with guests Bruno Aziza and Maire Newton. We start the episode...

19 Okt 202230min

Next 2022 with Forrest Brazeal and Stephanie Wong

Next 2022 with Forrest Brazeal and Stephanie Wong

Forrest Brazeal joins Stephanie Wong today on the second day of Google Cloud Next '22. We're talking about all the exciting announcements, how the conference has changed in recent years, and what to e...

12 Okt 202243min

2022 State of DevOps Report with Nathen Harvey and Derek DeBellis

2022 State of DevOps Report with Nathen Harvey and Derek DeBellis

On the show this week, we're talking updated DevOps practices for 2022 with hosts Stephanie Wong and Chloe Condon and our guests Nathen Harvey and Derek DeBellis. Nathen and Derek start the show with ...

5 Okt 202244min

DEI and Belonging in the Cloud with Jason Smith

DEI and Belonging in the Cloud with Jason Smith

Jason Smith, founder of the Mixed Googlers group here at Google, joins Stephanie Wong to talk about DEI and the importance of belonging in tech. Jason helps us better understand what the concepts dive...

28 Sep 202233min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
stopp-verden
forklart
i-retten
lydartikler-fra-aftenposten
popradet
rss-gukild-johaug
det-store-bildet
nokon-ma-ga
dine-penger-pengeradet
rss-ness
aftenbla-bla
hanna-de-heldige
fotballpodden-2
rss-dannet-uten-piano
grasoner-den-nye-kalde-krigen
frokostshowet-pa-p5
e24-podden