Cloud Security Podcast by Google

EP200 Zero Touch Prod, Security Rings, and Foundational Services: How Google Does Workload Security


Listen Later

Guest:

  • Michael Czapinski, Security & Reliability Enthusiast, Google

Topics:

  • “How Google protects its production services” paper covers how Google's infrastructure balances several crucial aspects, including security, reliability, development speed, and maintainability. How do you prioritize these competing demands in a real-world setting?
  • What attack vectors do you consider most critical in the production environment, and how has Google’s defenses against these vectors improved over time?
  • Can you elaborate on the concept of Foundational services and their significance in Google's security posture?
  • How does your security approach adapt to this vast spectrum of sensitivity and purpose of our servers and services, actually?
  • How do you implement this principle of zero touch prod for both human and service accounts within our complex infrastructure? 
  • Can you talk us through the broader approach you take through Workload Security Rings and how this helps?

Resources:

  • “How Google protects its production services” paper (deep!)
  • SLSA framework 
  • EP189 How Google Does Security Programs at Scale: CISO Insights
  • EP109 How Google Does Vulnerability Management: The Not So Secret Secrets!
  • EP176 Google on Google Cloud: How Google Secures Its Own Cloud Use
  • EP75 How We Scale Detection and Response at Google: Automation, Metrics, Toil
  • SREcon presentation on zero touch prod. 
  • The SRS book (free access)

 

...more
View all episodesView all episodes
Download on the App Store

Cloud Security Podcast by GoogleBy Anton Chuvakin

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

38 ratings


More shows like Cloud Security Podcast by Google

View all
Risky Business by Patrick Gray

Risky Business

365 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

626 Listeners

The Cloudcast by Massive Studios

The Cloudcast

152 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

366 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,006 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

201 Listeners

Click Here by Recorded Future News

Click Here

408 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

166 Listeners

Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

Kubernetes Podcast from Google

181 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

189 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

74 Listeners

Cloud Security Podcast by Cloud Security Podcast Team

Cloud Security Podcast

58 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

127 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

43 Listeners