Using Data Perimeters in AWS To Scale Guardrails

Using Data Perimeters in AWS To Scale Guardrails

Cloud Security Podcast - AWS Network Security, IAM Security or even Organization security for what can happen in your AWS Environments can be achieved using Data perimeter. John Burgress (⁠John - Linkedin⁠⁠⁠⁠) from Stripe spoke about this topic at @fwdcloudsec and shared additional insights on the thinking he had when building data perimeters are guardrails. There were lot more gems dropped so def check out the episode.


Episode YouTube Video - https://youtu.be/Hs9ZEaVG7Ww


Host Twitter: Ashish Rajan (⁠⁠⁠⁠@hashishrajan⁠⁠⁠⁠)

Guest Socials: John Burgress (John - Linkedin⁠)

Podcast Twitter - ⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠ ⁠⁠⁠⁠@CloudSecureNews⁠⁠⁠⁠

If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:

- ⁠⁠⁠⁠Cloud Security News ⁠⁠⁠⁠

- ⁠⁠⁠⁠Cloud Security BootCamp⁠⁠⁠⁠


Spotify TimeStamp for Interview Questions

A word from our sponsors - you can visit them on ⁠⁠⁠⁠snyk.io/csp⁠⁠⁠⁠

(00:00) Introduction

(03:13) A word from our sponsors

(03:38) A bit about John Burgess

(04:26) Data perimeter in the Cloud

(05:10) Defining data perimeter in AWS

(06:50) Where to start building AWS data perimeter

(08:21) The defense in depth approach 09:09 Approach to enable developers

(10:40) Starting point for building data perimeter

(11:41) Limitations with Data Perimeter

(13:06) Implementing data perimeter for segregation

(15:52) Working with Terraform Modules

(16:34) Goals behind data perimeter controls

(18:31) Proactive detection for third party

(20:00) Data perimeter for other CSPs

(20:42) Challenges in establishing data perimeter

(23:06) Dealing with multiple organisations

(23:35) Learn more about data perimeter

(24:06) The fun section


These are some of the resources John found helpful for data perimeter:

See you at the next episode!

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(360)

Securing Millions of AI-built Apps: How Lovable Defends Against Insider Threats

Securing Millions of AI-built Apps: How Lovable Defends Against Insider Threats

Empowering non-technical users to build production-grade applications requires a proactive, secure-by-design architecture. In this episode, Ashish sits down with Marcus Hallberg and Samuel Kelemen, se...

11 Sep 1h 10min

Why AI Won't Replace Your SOC: Federated Data & APEX Framework

Why AI Won't Replace Your SOC: Federated Data & APEX Framework

Hash values, IP addresses, and domains are virtually useless as primary detection mechanisms in the era of AI-driven polymorphic malware and short-lived phishing kits. If your detection strategy is st...

1 Sep 37min

The "Hunt First" AI Security Strategy

The "Hunt First" AI Security Strategy

Did you know that 82% of all intrusions don't involve any sort of malware, and AI-augmented attacks are up 89% year over year? If your security operations team is solely focused on reacting to known-b...

25 Aug 46min

Shadow AI & Sandbox Escapes: Why You Need an Agentic Control Plane?

Shadow AI & Sandbox Escapes: Why You Need an Agentic Control Plane?

When Claude Cowork hits a roadblock, it doesn't give up, it writes a custom Python script and downloads an untrusted NPM package just to bypass its restrictions and finish its goal. Are your security ...

18 Aug 32min

How Adobe Uses AI Agents for building a WAF Pipeline?

How Adobe Uses AI Agents for building a WAF Pipeline?

When vulnerability disclosures shrink the wild exploit window down to less than 24 hours (or even minutes), traditional manual patching and WAF rule creation simply cannot keep up.In this episode, Ash...

4 Aug 47min

Why Runtime Agents Are Replacing Static Posture Checks

Why Runtime Agents Are Replacing Static Posture Checks

The attack window from the discovery of a vulnerability to its exploitation has shrunk to less than 24 hours and sometimes down to just 25 minutes. Is your security team prepared for the speed of AI-d...

28 Jul 44min

The Hidden Cost of BlackBox AI: Bridging Cloud and Code Security

The Hidden Cost of BlackBox AI: Bridging Cloud and Code Security

Traditional SCA and SAST tools are notorious for drowning security teams in false positives, historically flagging nine out of ten alerts incorrectly. But while generative AI seems like a magic bullet...

9 Jul 42min

Who Governs Your AI Agents? Identity, Offboarding & Open Standards

Who Governs Your AI Agents? Identity, Offboarding & Open Standards

Are overprivileged AI agents the biggest emerging threat in cybersecurity? In a recent high-profile attack, a vibe-coding company had its entire source code stolen because an attacker exploited a long...

2 Jul 34min

Populært innen Teknologi

tomprat-med-gunnar-tjomlid
teknisk-sett
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
energi-og-klima
lydartikler-fra-aftenposten
nasjonal-sikkerhetsmyndighet-nsm
hans-petter-og-co
elektropodden
rss-ki-praten
shifter
rss-alt-som-gar-pa-strom
rss-ai-forklart
smart-forklart
teknologi-og-mennesker
fornybaren
rss-snakk-om-sikkerhet
rss-alt-vi-kan
pedagogisk-intelligens
rss-heis
rss-ki-til-kaffen