HOW TO BUILD A CLOUD SECURITY PROGRAM WITH CONTAINERS

HOW TO BUILD A CLOUD SECURITY PROGRAM WITH CONTAINERS

Cloud Security Podcast - This month we are talking about "Building on the AWS Cloud" and next up on this series, we spoke to Mrunal Shah (Mrunal's Linkedin), Head of Container Security at Warner Bros. Discovery. We talk about how to build a Container or K8s security program while best practices are maintained and team have the right capability and tools. 4 Cs - Cloud, Container & Cluster, Code can be foundational to this

Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv

Host Twitter: Ashish Rajan (@hashishrajan)

Guest Twitter: Mrunal Shah (Mrunal's Linkedin)

Podcast Twitter - @CloudSecPod @CloudSecureNews

If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:

- Cloud Security News

- Cloud Security Academy

Spotify TimeStamp for Interview Questions

(00:00) Intro

(02:01) https://snyk.io/csp

(02:30) Mrunal's Professional Background

(03:04) Why containers are popular (technical reasons)

(04:05) Why containers are popular (leadership reasons)

(05:39) Challenges with running a Container Security Program (Leadership)

(06:34) Team skill challenge in a Container Security Program

(08:57) When to pick AWS ECS vs AWS EKS?

(10:53) ECS or EKS for building Banking Applications?

(13:12) Would Kubernetes/ Containers be preferred for security reasons?

(15:04) What would Amazon's responsibility be for security with ECS/EKS?

(16:13) What is bad about working with Containers in AWS?

(19:40) Is there a need for anti-virus in a container world?

(20:36) Balance of security when working with containers?

(22:08) Threat Detection and Prevention in a Container Security Program

(22:57) Using AWS Services for Threat Detection with Containers?

(25:14) Runtime Threat Discovery vs Agentless Threat Discovery for containers in Cloud?

(29:11) Prevention on the left vs Detection on the right of SDLC

(29:22) Cluster Misconfig vs Service Misconfigurations?

(30:19) Vulnerability Management vs Misconfiguration Management?

(31:50) Inspector in a Container Security Program?

(32:36) Detective in a Container Security Program?

(35:36) Can AWS Services help when Non-AWS services are in use?

See you at the next episode!

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(352)

AI-Powered Forensics: How Attackers Automate Breaches

AI-Powered Forensics: How Attackers Automate Breaches

AI isn't necessarily creating impossible new attacks, but it is drastically lowering the technical barrier to entry for cybercriminals. In this episode, Ashish Rajan speaks with Simon Biggs, Cyber Inc...

23 Juni 39min

The 4 Pillars of AI SOC:From Threat Hunting to Vibe Hunting

The 4 Pillars of AI SOC:From Threat Hunting to Vibe Hunting

Threat hunting has officially evolved into "vibe hunting". However, if your AI security tools lack the right semantic context, they might be doing more harm than good. In this episode, Ashish sits dow...

16 Juni 46min

Native Cloud Firewalls Falling Short in a Multicloud World

Native Cloud Firewalls Falling Short in a Multicloud World

As enterprises expand across multiple cloud environments, on-premise data centers, and dynamic AI workloads, traditional perimeter defenses and siloed cloud-native tools are no longer enough to secure...

11 Juni 36min

How AI Agents Will Negotiate Your Vendor Contracts

How AI Agents Will Negotiate Your Vendor Contracts

Third-Party Risk Management (TPRM) has historically been a tedious, 200-page paper exercise that felt like being catapulted back to 1979. But AI is changing that.In this episode, Ashish sits down with...

27 Maj 37min

How Claude Mythos Changes Vulnerability Management: From CVSS to Exploitability

How Claude Mythos Changes Vulnerability Management: From CVSS to Exploitability

Is your vulnerability management program ready for something like Claude Mythos? The old days of treating vulnerabilities as temporal events (like Heartbleed or Log4J) and patching them on a leisurely...

5 Maj 44min

AISPM Isn't Enough: How to Apply Zero Trust to AI Agents

AISPM Isn't Enough: How to Apply Zero Trust to AI Agents

We are officially entering the "Multi-AI Era." Much like the multi-cloud times, organizations are no longer just using a single AI tool like Microsoft Copilot, they are building custom, agentic workfl...

29 Apr 54min

 The Rise of Agentic Cloud Security: Code-to-Cloud Shrinks to 3 Days

The Rise of Agentic Cloud Security: Code-to-Cloud Shrinks to 3 Days

Is your cloud security strategy ready for the "messy middle" of AI adoption? With developers pushing code from inception to production in under three days using "vibe coding," and adversaries capable ...

21 Apr 26min

Why EDR Fails at AI Security & The Rise of Endpoint Behavior Modeling

Why EDR Fails at AI Security & The Rise of Endpoint Behavior Modeling

Is your EDR blinding you to insider threats? In this episode, Ashish is joined by Brandon Dixon (Co-Founder & CTO of Ent AI, and former Microsoft Security Copilot leader) to discuss why traditional en...

14 Apr 31min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
bilar-med-sladd
natets-morka-sida
market-makers
rss-laddstationen-med-elbilen-i-sverige
rss-uppgang-och-fall
rss-technokratin
rss-elektrikerpodden
bli-saker-podden
skogsforum-podcast
rss-veckans-ai
developers-mer-an-bara-kod
hej-bruksbil
rss-snacka-om-ai
under-femton
rss-fabriken-2
rss-en-ai-till-kaffet
rss-aximapodden
rss-sakerhetspodcasten