Cloud Security Podcast by Google

EP140 System Hardening at Google Scale: New Challenges, New Solutions


Listen Later

Guest: 

  • Andrew Hoying, Senior Security Engineering Manager @ Google

Topics:

  • What is different about system hardening today vs 20 years ago? 

  • Also, what is special about hardening systems at Google massive scale?

  • Can I just apply CIS templates and be done with it?

  • Part of hardening has to be following up with developers after they have un-hardened things – how do we operationalize that at scale without getting too much in the way of productivity?

  • A part of hardening has got to be responding to new regulation and compliance regimes, how do you incorporate new controls and stay responsive to the changing world around us?

  • Are there cases where we have taken lessons from hardening at scale and converted those into product improvements?

  • What metrics do you track to keep your teams moving, and what metrics do your leads look at to understand how you’re doing? [Spoiler: the answer here is VERY fun!]

Resources:

  • “Why Shared Fate is a Better Way to Manage Cloud Risk” article (and this too)

  • CIS for GCP

  • GCP IAM Deny

  • CloudSecList by Marco Lancini

...more
View all episodesView all episodes
Download on the App Store

Cloud Security Podcast by GoogleBy Anton Chuvakin

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

38 ratings


More shows like Cloud Security Podcast by Google

View all
Risky Business by Patrick Gray

Risky Business

363 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

633 Listeners

The Cloudcast by Massive Studios

The Cloudcast

154 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

372 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,008 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

199 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

313 Listeners

Click Here by Recorded Future News

Click Here

387 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

141 Listeners

Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

Kubernetes Podcast from Google

182 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

187 Listeners

Hacking Humans by N2K Networks

Hacking Humans

308 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

72 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

120 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners