Date: Wed, 27 May 2020 00:00:00 +0000
<p>We’re discussing security operations on the podcast this week with your hosts <a href="https://twitter.com/pvergadia">Priyanka Vergadia</a> and <a href="https://twitter.com/markmirch">Mark Mirchandani</a>. They’re joined by Elliott Abraham and Jason Bisson who start the interview explaining that they created the CLAM framework to help customers use Google Cloud security features to their fullest potential to create safe projects and relaxed clients.</p> <p>The CLAM (Cloud Logging Alerting and Monitoring) framework came about specifically to help customers transition products to, and run products securely in, the cloud. Using the Mitre GCP Matrix, the security team addressed each element with GCP product solutions, from initial access to persistence and beyond. CLAM is GCP specific, taking into account the default security measures GCP already provides and supplementing these measures with appropriate procedures for each client. Once the framework is in place and things are secure, clients can build on that with operational controls, such as SRE best practices.</p> <p>Elliott explains the shared security model and how clients can shift more of the security responsibility to the cloud service provider by employing more managed services. Jason tells us about VPC Service Controls and how they allow clients to set specific security rules such as from where data can be accessed. They go on to describe the GCP Security Command Center and the tools available there.</p> <p>We wrap up the interview with some tips from our guests, including what to do if you are compromised.</p> <h5 id="elliott-abraham">Elliott Abraham</h5> <p>Elliott Abraham is a Security and Compliance Specialist based in Atlanta. Elliott works with Financial Services, Healthcare and Life Sciences and other Select Accounts migrating to or expanding their footprint on the Google Cloud Platform. Elliott has helped many customers to operationalize GCP Security solutions in alignment with their security, compliance, and regulatory requirements.</p> <h5 id="jason-bisson">Jason Bisson</h5> <p>Jason Bisson is a Security and Compliance Specialist based in NYC. He works with Financial Services, Healthcare, Government, and Retail customers to explain the security, compliance, and regulatory abilities of Google Cloud Platform.</p> <h5 id="cool-things-of-the-week">Cool things of the week</h5> <ul> <li>Announcing Google Cloud Next ‘20: OnAir <a href="https://cloud.google.com/blog/topics/google-cloud-next/announcing-google-cloud-next20-onair"> blog</a></li> <li>Celebrating a decade of data: BigQuery turns 10 <a href="https://googlecloudpodcast.libsyn.com/Celebrating%20a%20decade%20of%20data:%20BigQuery%20turns%2010">blog</a> <ul> <li>A very special BigQuery Day (The Data Show, w/ Felipe Hoffa & Yufeng Guo) <a href="https://www.youtube.com/watch?v=U2q9lfjw9EE&lis=">video</a></li> </ul> </li> </ul> <h5 id="interview">Interview</h5> <ul> <li>CLAM Framework <a href="https://storage.googleapis.com/gcppodcast_files/CLAM%20Framework%20for%20Google%20Cloud.pdf"> pdf</a></li> <li>Mitre <a href="https://www.mitre.org">site</a></li> <li>Mitre ATT&CK <a href="https://attack.mitre.org">site</a></li> <li>Mitre GCP Matrix <a href="https://attack.mitre.org/beta/matrices/enterprise/cloud/gcp/">site</a></li> <li>SRE Handbook <a href="https://landing.google.com/sre/books/">site</a></li> <li>VPC Service Controls <a href="https://cloud.google.com/vpc-service-controls">site</a></li> <li>Cloud Audit Logs <a href="https://cloud.google.com/audit-logs">site</a></li> <li>Cloud Data Loss Prevention <a href="https://cloud.google.com/dlp">site</a></li> <li>GCP Podcast Episode 218: Chronicle Security with Dr. Anton Chuvakin and Ansh Patniak<a href="https://www.gcppodcast.com/post/episode-218-chronicle-security-with-dr-anton-chuvakin-and-ansh-patniak/">podcast</a></li> <li>GCP Podcast Episode 221: BeyondCorp with Robert Sadowski <a href="https://www.gcppodcast.com/post/episode-221-beyondcorp-with-robert-sadowski/"> podcast</a></li> </ul> <h5 id="tip-of-the-week">Tip of the week</h5> <p>Yuri Grinshteyn talks about the <a href="https://cloud.google.com/logging/docs/view/logs-viewer-interface">new logging feature</a>.</p> <h5 id="what-s-something-cool-you-re-working-on">What’s something cool you’re working on?</h5> <p>Priyanka is working on <a href="https://webinars.devops.com/building-an-unbreakable-google-cloud-pipeline?utm_campaign=DO%20xMatters%20Webinar%205.27.20&utm_content=129280973&utm_medium=social&utm_source=twitter&hss_channel=tw-130933506"> Building an Unbreakable DevOps Pipeline with Google Cloud</a>.</p> <p>Mark is working on more videos and will be speaking at Next.</p>