Compliance Perspectives

Chris Ford on Compliance and Cloud Computing [Podcast]


Listen Later

Post By: Adam Turteltaub

While organizations have increasingly embraced cloud computing as a solution to their data management and other needs, they do so in an environment of heightened risks. Attacks on cloud providers are increasing, which makes it ever more important to ensure that the rewards outweigh the risks, including from a compliance perspective.

Chris Ford, Vice President Product, Threat Stack, advises organizations look to cloud service providers that have taken the step of becoming certified against standards such as ISO 27001 or SOC 2. He also recommends not stopping there and looking to certifications that align with specific risk areas such as IPAA, GDPR, CCPA or PCI.

That’s still not enough, though, he cautions in this podcast. Meet with the security team to discuss the organization’s practices and how it manages third party vendor risk. If their practices aren’t secure or the team is unwilling to meet with you that should be a very large red flag. So, too, is the approach to compliance:  stay away from vendors who take a check-the-box approach.

Other pieces of advice he offers:

* Ask if they scan code in the build pipeline
* Determine if they do runtime monitoring of the infrastructure
* Find out what tools they use to ensure your date is secure
* Make sure they are constantly scanning for vulnerabilities

Finally, security is a “team sport” he notes. It’s important to maintain trust on an ongoing basis and look at this as a journey together. Be sure to learn from the failures of others, and, of course, make sure that you are just as vigilant of your internal IT security as you are of your vendor’s.
...more
View all episodesView all episodes
Download on the App Store

Compliance PerspectivesBy SCCE

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

34 ratings


More shows like Compliance Perspectives

View all
The Joe Rogan Experience by Joe Rogan

The Joe Rogan Experience

229,674 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,687 Listeners

Wait Wait... Don't Tell Me! by NPR

Wait Wait... Don't Tell Me!

38,950 Listeners

Making Sense with Sam Harris by Sam Harris

Making Sense with Sam Harris

26,380 Listeners

Pivot by New York Magazine

Pivot

9,724 Listeners

FCPA Compliance Report by Thomas Fox

FCPA Compliance Report

20 Listeners

Up First from NPR by NPR

Up First from NPR

56,944 Listeners

Stay Tuned with Preet by Preet Bharara

Stay Tuned with Preet

32,354 Listeners

Corruption Crime & Compliance by Michael Volkov

Corruption Crime & Compliance

43 Listeners

GZERO World with Ian Bremmer by GZERO Media

GZERO World with Ian Bremmer

837 Listeners

Compliance into the Weeds by Tom Fox

Compliance into the Weeds

12 Listeners

Daily Compliance News by Tom Fox

Daily Compliance News

7 Listeners

The Ezra Klein Show by New York Times Opinion

The Ezra Klein Show

16,525 Listeners

On with Kara Swisher by Vox Media

On with Kara Swisher

3,538 Listeners

The Mel Robbins Podcast by Mel Robbins

The Mel Robbins Podcast

20,222 Listeners