
Sign up to save your podcasts
Or
Guest:
Andrew Hoying, Senior Security Engineering Manager @ Google
Topics:
What is different about system hardening today vs 20 years ago?
Also, what is special about hardening systems at Google massive scale?
Can I just apply CIS templates and be done with it?
Part of hardening has to be following up with developers after they have un-hardened things – how do we operationalize that at scale without getting too much in the way of productivity?
A part of hardening has got to be responding to new regulation and compliance regimes, how do you incorporate new controls and stay responsive to the changing world around us?
Are there cases where we have taken lessons from hardening at scale and converted those into product improvements?
What metrics do you track to keep your teams moving, and what metrics do your leads look at to understand how you’re doing? [Spoiler: the answer here is VERY fun!]
Resources:
“Why Shared Fate is a Better Way to Manage Cloud Risk” article (and this too)
CIS for GCP
GCP IAM Deny
CloudSecList by Marco Lancini
4.8
3838 ratings
Guest:
Andrew Hoying, Senior Security Engineering Manager @ Google
Topics:
What is different about system hardening today vs 20 years ago?
Also, what is special about hardening systems at Google massive scale?
Can I just apply CIS templates and be done with it?
Part of hardening has to be following up with developers after they have un-hardened things – how do we operationalize that at scale without getting too much in the way of productivity?
A part of hardening has got to be responding to new regulation and compliance regimes, how do you incorporate new controls and stay responsive to the changing world around us?
Are there cases where we have taken lessons from hardening at scale and converted those into product improvements?
What metrics do you track to keep your teams moving, and what metrics do your leads look at to understand how you’re doing? [Spoiler: the answer here is VERY fun!]
Resources:
“Why Shared Fate is a Better Way to Manage Cloud Risk” article (and this too)
CIS for GCP
GCP IAM Deny
CloudSecList by Marco Lancini
363 Listeners
633 Listeners
154 Listeners
372 Listeners
1,008 Listeners
199 Listeners
313 Listeners
387 Listeners
141 Listeners
182 Listeners
187 Listeners
308 Listeners
72 Listeners
120 Listeners
33 Listeners