Security Operations with Elliott Abraham and Jason Bisson

Security Operations with Elliott Abraham and Jason Bisson

We're discussing security operations on the podcast this week with your hosts Priyanka Vergadia and Mark Mirchandani. They're joined by Elliott Abraham and Jason Bisson who start the interview explaining that they created the CLAM framework to help customers use Google Cloud security features to their fullest potential to create safe projects and relaxed clients.

The CLAM (Cloud Logging Alerting and Monitoring) framework came about specifically to help customers transition products to, and run products securely in, the cloud. Using the Mitre GCP Matrix, the security team addressed each element with GCP product solutions, from initial access to persistence and beyond. CLAM is GCP specific, taking into account the default security measures GCP already provides and supplementing these measures with appropriate procedures for each client. Once the framework is in place and things are secure, clients can build on that with operational controls, such as SRE best practices.

Elliott explains the shared security model and how clients can shift more of the security responsibility to the cloud service provider by employing more managed services. Jason tells us about VPC Service Controls and how they allow clients to set specific security rules such as from where data can be accessed. They go on to describe the GCP Security Command Center and the tools available there.

We wrap up the interview with some tips from our guests, including what to do if you are compromised.

Elliott Abraham

Elliott Abraham is a Security and Compliance Specialist based in Atlanta. Elliott works with Financial Services, Healthcare and Life Sciences and other Select Accounts migrating to or expanding their footprint on the Google Cloud Platform. Elliott has helped many customers to operationalize GCP Security solutions in alignment with their security, compliance, and regulatory requirements.

Jason Bisson

Jason Bisson is a Security and Compliance Specialist based in NYC. He works with Financial Services, Healthcare, Government, and Retail customers to explain the security, compliance, and regulatory abilities of Google Cloud Platform.

Cool things of the week
  • Announcing Google Cloud Next '20: OnAir blog
  • Celebrating a decade of data: BigQuery turns 10 blog
    • A very special BigQuery Day (The Data Show, w/ Felipe Hoffa & Yufeng Guo) video
Interview
  • CLAM Framework pdf
  • Mitre site
  • Mitre ATT&CK site
  • Mitre GCP Matrix site
  • SRE Handbook site
  • VPC Service Controls site
  • Cloud Audit Logs site
  • Cloud Data Loss Prevention site
  • GCP Podcast Episode 218: Chronicle Security with Dr. Anton Chuvakin and Ansh Patniakpodcast
  • GCP Podcast Episode 221: BeyondCorp with Robert Sadowski podcast
Tip of the week

Yuri Grinshteyn talks about the new logging feature.

What's something cool you're working on?

Priyanka is working on Building an Unbreakable DevOps Pipeline with Google Cloud.

Mark is working on more videos and will be speaking at Next.

Episoder(335)

Google Cloud Next Data, Analytics, and AI Launches with Eric Schmidt and Bruno Aziza

Google Cloud Next Data, Analytics, and AI Launches with Eric Schmidt and Bruno Aziza

Mark Mirchandani is back this week with cohost Bukola Ayodele. We're talking with Eric Schmidt and Bruno Aziza about all the awesome new analytics, data, and AI launches from last week's Google Cloud ...

20 Okt 202135min

Google Cloud Next '21 with Brian Hall and Forrest Brazeal

Google Cloud Next '21 with Brian Hall and Forrest Brazeal

On the podcast this week, Mark Mirchandani and Stephanie Wong hear all about the cool stuff happening at Cloud Next 2021. Brian Hall and Forrest Brazeal join the show to outline exciting announcements...

13 Okt 202144min

MLB with Perry Pierce and JoAnn Brereton

MLB with Perry Pierce and JoAnn Brereton

This week, Mark Mirchandani and Brian Dorsey welcome Perry Pierce and JoAnn Brereton of Major League Baseball to the show to talk sports and cloud. Baseball teams are independently owned franchises, P...

6 Okt 202141min

Managing non-REST APIs like GraphQL and gRPC with Nandan Sridhar and David Feuer

Managing non-REST APIs like GraphQL and gRPC with Nandan Sridhar and David Feuer

Alexandrina Garcia-Verdin and Stephanie Wong host this week's episode all about managing non-REST APIs. Guests Nandan Sridhar and Dave Feuer start the show introducing our listeners to Apigee, a full ...

29 Sep 202134min

Storage Launches with Brian Schwarz and Sean Derrington

Storage Launches with Brian Schwarz and Sean Derrington

On the podcast this week, our guests Brian Schwarz and Sean Derrington discuss the ins and outs of the new storage launches with your hosts Stephanie Wong and Jenny Brown. Brian gives light introducti...

22 Sep 202136min

Cloud Migration with Txture and Accenture

Cloud Migration with Txture and Accenture

Mark Mirchandani and Brian Dorsey are together again this week for an episode all about cloud migration using Txture and Accenture. Our guests Matthias Farwick of Txture, Patrick Niesel of Accenture, ...

15 Sep 202141min

Building the I/O Adventure Game with Valentin Deleplace

Building the I/O Adventure Game with Valentin Deleplace

Carter Morgan and Guillaume Laforge co-host this week's episode about what it took to develop the Google I/O Adventure Game. Our guest Valentin Deleplace and Guillaume introduce us to the game designe...

8 Sep 202132min

BigQuery Admin Reference Guides with Leigha Jarett

BigQuery Admin Reference Guides with Leigha Jarett

Your hosts Stephanie Wong and Alicia Williams talk about BigQuery Admin Reference Guides with guest Leigha Jarett. Leigha tells us a bit about the origins of the Admin Reference Guide, which was devel...

1 Sep 202126min

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
aftenpodden-usa
stopp-verden
forklart
popradet
lydartikler-fra-aftenposten
det-store-bildet
rss-gukild-johaug
fotballpodden-2
rss-ness
dine-penger-pengeradet
i-retten
nokon-ma-ga
hanna-de-heldige
aftenbla-bla
frokostshowet-pa-p5
grasoner-den-nye-kalde-krigen
rss-dannet-uten-piano
e24-podden