Security Operations with Elliott Abraham and Jason Bisson

Security Operations with Elliott Abraham and Jason Bisson

We're discussing security operations on the podcast this week with your hosts Priyanka Vergadia and Mark Mirchandani. They're joined by Elliott Abraham and Jason Bisson who start the interview explaining that they created the CLAM framework to help customers use Google Cloud security features to their fullest potential to create safe projects and relaxed clients.

The CLAM (Cloud Logging Alerting and Monitoring) framework came about specifically to help customers transition products to, and run products securely in, the cloud. Using the Mitre GCP Matrix, the security team addressed each element with GCP product solutions, from initial access to persistence and beyond. CLAM is GCP specific, taking into account the default security measures GCP already provides and supplementing these measures with appropriate procedures for each client. Once the framework is in place and things are secure, clients can build on that with operational controls, such as SRE best practices.

Elliott explains the shared security model and how clients can shift more of the security responsibility to the cloud service provider by employing more managed services. Jason tells us about VPC Service Controls and how they allow clients to set specific security rules such as from where data can be accessed. They go on to describe the GCP Security Command Center and the tools available there.

We wrap up the interview with some tips from our guests, including what to do if you are compromised.

Elliott Abraham

Elliott Abraham is a Security and Compliance Specialist based in Atlanta. Elliott works with Financial Services, Healthcare and Life Sciences and other Select Accounts migrating to or expanding their footprint on the Google Cloud Platform. Elliott has helped many customers to operationalize GCP Security solutions in alignment with their security, compliance, and regulatory requirements.

Jason Bisson

Jason Bisson is a Security and Compliance Specialist based in NYC. He works with Financial Services, Healthcare, Government, and Retail customers to explain the security, compliance, and regulatory abilities of Google Cloud Platform.

Cool things of the week
  • Announcing Google Cloud Next '20: OnAir blog
  • Celebrating a decade of data: BigQuery turns 10 blog
    • A very special BigQuery Day (The Data Show, w/ Felipe Hoffa & Yufeng Guo) video
Interview
  • CLAM Framework pdf
  • Mitre site
  • Mitre ATT&CK site
  • Mitre GCP Matrix site
  • SRE Handbook site
  • VPC Service Controls site
  • Cloud Audit Logs site
  • Cloud Data Loss Prevention site
  • GCP Podcast Episode 218: Chronicle Security with Dr. Anton Chuvakin and Ansh Patniakpodcast
  • GCP Podcast Episode 221: BeyondCorp with Robert Sadowski podcast
Tip of the week

Yuri Grinshteyn talks about the new logging feature.

What's something cool you're working on?

Priyanka is working on Building an Unbreakable DevOps Pipeline with Google Cloud.

Mark is working on more videos and will be speaking at Next.

Avsnitt(335)

How UniSuper is helping Australians get the best of their superannuation fund investments with cloud

How UniSuper is helping Australians get the best of their superannuation fund investments with cloud

In this special episode, we are featuring That Digital Show. In Australia, every employee is required to select their superannuation fund of choice to help them invest a portion of their income. Havin...

16 Nov 202325min

Creating a sustainable EV ecosystem in Taiwan with ChargeSmith

Creating a sustainable EV ecosystem in Taiwan with ChargeSmith

In this special episode, we are featuring That Digital Show. As the electric vehicles (EV) sector accelerates, drivers are finding it a challenge to conveniently access charging points. This has becom...

16 Aug 202326min

Tapping onto AI to build a more sustainable future with Recursive AI

Tapping onto AI to build a more sustainable future with Recursive AI

In this special episode, we are featuring That Digital Show. AI is seen as a powerful tool and enabler for businesses around the world. At the same time, more organizations are looking for ways to ope...

26 Juli 202325min

Streamlining the Philippine education network with an all-in-one school management app with Wela

Streamlining the Philippine education network with an all-in-one school management app with Wela

In this special episode, we are featuring That Digital Show. In the Philippines, class sizes in schools are often quite large with an average of 30 students per class. This makes keeping track of indi...

3 Maj 202323min

GoJek's digital journey to becoming one of Indonesia's biggest multi-platform apps

GoJek's digital journey to becoming one of Indonesia's biggest multi-platform apps

In this special episode, we are featuring That Digital Show. Theo Davies and Stephanie Wong speak to Sartaj Singh, Head of Technology at GoJek, who shares inside knowledge on GoJek's explosive growth,...

29 Mars 202344min

2022 Year End Wrap Up

2022 Year End Wrap Up

Happy Holidays from all of us at Google! This week, hosts Carter Morgan, Stephanie Wong, and Max Saltonstall are sharing their favorite moments from the year! From great partnerships with national com...

21 Dec 202239min

Cloud Workstations with Marcos Grappeggia and Antoine Castex

Cloud Workstations with Marcos Grappeggia and Antoine Castex

Max Saltonstall and Stephanie Wong welcome fellow Googler Marcos Grappeggia and Antoine Castex of L'Oreal to talk about Cloud Workstations, Google's software that provides managed development environm...

14 Dec 202241min

Active Assist and Resource Lifecycle Management with Sharon Fang and Michael Sudakovitch

Active Assist and Resource Lifecycle Management with Sharon Fang and Michael Sudakovitch

Guests Sharon Fang and Michael Sudakovitch are here this week to talk with Max Saltonstall and Daryl Ducharme about Google's Active Assist optimization portfolio and managing cloud projects efficientl...

7 Dec 202228min

Populärt inom Politik & nyheter

svenska-fall
aftonbladet-krim
p3-krim
fordomspodden
rss-krimstad
motiv
flashback-forever
aftonbladet-daily
blenda-2
rss-sanning-konsekvens
rss-krimreportrarna
rss-vad-fan-hande
olyckan-inifran
svd-ledarredaktionen
rss-frandfors-horna
spar
rss-flodet
dagens-eko
krimmagasinet
politiken