
Sign up to save your podcasts
Or


Guest:
Andrew Hoying, Senior Security Engineering Manager @ Google
Topics:
What is different about system hardening today vs 20 years ago?
Also, what is special about hardening systems at Google massive scale?
Can I just apply CIS templates and be done with it?
Part of hardening has to be following up with developers after they have un-hardened things – how do we operationalize that at scale without getting too much in the way of productivity?
A part of hardening has got to be responding to new regulation and compliance regimes, how do you incorporate new controls and stay responsive to the changing world around us?
Are there cases where we have taken lessons from hardening at scale and converted those into product improvements?
What metrics do you track to keep your teams moving, and what metrics do your leads look at to understand how you're doing? [Spoiler: the answer here is VERY fun!]
Resources:
"Why Shared Fate is a Better Way to Manage Cloud Risk" article (and this too)
CIS for GCP
GCP IAM Deny
CloudSecList by Marco Lancini
By Anton Chuvakin4.8
3939 ratings
Guest:
Andrew Hoying, Senior Security Engineering Manager @ Google
Topics:
What is different about system hardening today vs 20 years ago?
Also, what is special about hardening systems at Google massive scale?
Can I just apply CIS templates and be done with it?
Part of hardening has to be following up with developers after they have un-hardened things – how do we operationalize that at scale without getting too much in the way of productivity?
A part of hardening has got to be responding to new regulation and compliance regimes, how do you incorporate new controls and stay responsive to the changing world around us?
Are there cases where we have taken lessons from hardening at scale and converted those into product improvements?
What metrics do you track to keep your teams moving, and what metrics do your leads look at to understand how you're doing? [Spoiler: the answer here is VERY fun!]
Resources:
"Why Shared Fate is a Better Way to Manage Cloud Risk" article (and this too)
CIS for GCP
GCP IAM Deny
CloudSecList by Marco Lancini

1,722 Listeners

4,424 Listeners

2,010 Listeners

373 Listeners

1,025 Listeners

347 Listeners

8,079 Listeners

177 Listeners

211 Listeners

58 Listeners

140 Listeners

29,300 Listeners

681 Listeners

168 Listeners

9 Listeners