
Sign up to save your podcasts
Or


Guest:
Andrew Hoying, Senior Security Engineering Manager @ Google
Topics:
What is different about system hardening today vs 20 years ago?
Also, what is special about hardening systems at Google massive scale?
Can I just apply CIS templates and be done with it?
Part of hardening has to be following up with developers after they have un-hardened things – how do we operationalize that at scale without getting too much in the way of productivity?
A part of hardening has got to be responding to new regulation and compliance regimes, how do you incorporate new controls and stay responsive to the changing world around us?
Are there cases where we have taken lessons from hardening at scale and converted those into product improvements?
What metrics do you track to keep your teams moving, and what metrics do your leads look at to understand how you're doing? [Spoiler: the answer here is VERY fun!]
Resources:
"Why Shared Fate is a Better Way to Manage Cloud Risk" article (and this too)
CIS for GCP
GCP IAM Deny
CloudSecList by Marco Lancini
By Anton Chuvakin4.8
3939 ratings
Guest:
Andrew Hoying, Senior Security Engineering Manager @ Google
Topics:
What is different about system hardening today vs 20 years ago?
Also, what is special about hardening systems at Google massive scale?
Can I just apply CIS templates and be done with it?
Part of hardening has to be following up with developers after they have un-hardened things – how do we operationalize that at scale without getting too much in the way of productivity?
A part of hardening has got to be responding to new regulation and compliance regimes, how do you incorporate new controls and stay responsive to the changing world around us?
Are there cases where we have taken lessons from hardening at scale and converted those into product improvements?
What metrics do you track to keep your teams moving, and what metrics do your leads look at to understand how you're doing? [Spoiler: the answer here is VERY fun!]
Resources:
"Why Shared Fate is a Better Way to Manage Cloud Risk" article (and this too)
CIS for GCP
GCP IAM Deny
CloudSecList by Marco Lancini

2,009 Listeners

372 Listeners

651 Listeners

1,020 Listeners

319 Listeners

416 Listeners

8,059 Listeners

179 Listeners

314 Listeners

189 Listeners

204 Listeners

74 Listeners

57 Listeners

139 Listeners

44 Listeners