Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Chris Dotson

Rating No ratings yet

With their rapidly changing architecture and API-driven automation, cloud platforms come with unique security challenges and opportunities. This hands-on book guides you through security best practices for multivendor cloud environments, whether your company plans to move legacy on-premises projects to the cloud or build a new infrastructure from the ground up. Developers, IT architects, and security professionals will learn cloud-specific techniques for securing popular cloud platforms such as Amazon Web Services, Microsoft Azure, and IBM Cloud. Chris Dotson—an IBM senior technical staff member—shows you how to establish data asset management, identity and access management, vulnerability management, network security, and incident response in your cloud environment.

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A practical, vendor-neutral guide for developers, IT architects, and security professionals who need to secure multi-cloud environments (AWS, Azure, IBM Cloud, etc.), covering everything from data classification to incident response with actionable checklists and design patterns. 【Book Arc】 - **Opening (~0%–10%)**: Introduces core security principles (least privilege, defense in depth) and the cloud shared responsibility model, using simple diagrams (e.g., "Pizza as a Service") to clarify who secures what in IaaS, PaaS, and SaaS. - **Early (~10%–25%)**: Focuses on data asset management—classification levels (low/moderate/high), tagging resources consistently across providers, and protecting data via tokenization and encryption, including key management options (KMS vs. HSM). - **Early–Middle (~25%–40%)**: Expands to cloud asset management, contrasting traditional IT with cloud assets (compute, storage, network). Discusses VM risks (hypervisor breakout, noisy neighbors) and container security models (native vs. mini-VM), emphasizing trust boundaries. - **Middle (~40%–55%)**: Covers storage and network assets in detail—block, file, object storage—plus source code repositories and deployment pipelines as critical integrity assets. Introduces VPCs/subnets as network boundaries. - **Late (~55%–100%)**: (Excerpts thin here) Likely covers vulnerability management, network security controls, and incident response, building on earlier asset inventories to operationalize security. 【Key Takeaways】 - **Least privilege is non-negotiable in cloud** (Early): Cloud consoles often grant godlike default privileges; enforce deny-by-default policies and tightly control console access, just as you would physical data centers. - **Data classification drives security priorities** (Early): Use a simple three-tier system (low/moderate/high) to focus resources; resist overcomplicating—most data falls into "moderate" and needs need-to-know controls. - **Tags are your inventory backbone** (Early): Standardize tag keys/values across all cloud providers and enforce them via automation; tags enable access decisions, alerting, and scanning, even if providers limit counts (15–64 per resource). - **Encryption at rest is a layered defense, not a checkbox** (Early–Middle): It foils physical media theft and platform breaches, but fails if keys are stored with data; use KMS for cost-effective key management and cryptographic erasure to destroy data by revoking keys. - **Containers are not a trust boundary** (Middle): Shared kernels have a large attack surface (300+ syscalls); avoid mixing internet-facing code with sensitive data in containers—use VMs or hybrid isolation for different security levels. - **Source code integrity is a cloud asset** (Middle): Track repositories and pipelines to prevent tampering; vulnerability scanners can't find what they don't know about, so maintain a complete inventory. - **Network assets define communication boundaries** (Middle): VPCs and subnets are high-level controls; good inventories of these are prerequisites for effective scanning and access management. 【Reading Tips】 - **Skim Chapter 1 if experienced**: The principles (least privilege, defense in depth) are standard; focus on the shared responsibility model diagrams to understand cloud-specific divisions. - **Deep-read Chapter 2 for data protection**: Encryption and key management sections are dense but critical—pay attention to KMS vs. HSM trade-offs and cryptographic erasure examples. - **Use the asset type breakdowns as reference**: Chapters 3–4 list compute, storage, and network assets with specific risks; bookmark these for quick lookup when designing your own architecture. - **Watch for vendor-specific tables**: The book includes comparisons (e.g., AWS CloudHSM vs. Azure Key Vault); use these to map recommendations to your chosen provider. - **Take away the diagramming method**: The "draw boxes and lines" approach for mapping components, data stores, and admin access is a practical tool for threat modeling any application. 【Coverage Limits】 Excerpts cover roughly the first half of the book (principles, data/asset management, compute/storage/network basics). Later chapters on vulnerability management, network security controls, and incident response are not represented in this guide.
Excerpt 1
6 Risk Management 10 2. Data Asset Management and Protection. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13 Data Identificat...
View in text
Excerpt 2
inst). Once you have an idea of the known risks, you can do one of four things with them: 1. Avoid the risk. In information security this typically means you...
View in text
Excerpt 3
56-bit key. How encryption foils different types of attacks As we’ve discussed, encryption of data, at rest can protect data from attackers by lim‐ iting the...
View in text
Excerpt 4
thing specific to you that sits around waiting for incoming requests. This means you don’t have to track both an “image” and the “instances” that are created...
View in text
Excerpt 5
d analogies) can get complicated very quickly. For example, imagine a system where instead of showing your license everywhere, you check out an access badge...
View in text
Excerpt 6
s to not store the passwords themselves, but to store some‐ thing that can be used to verify the passwords. This is implemented using a one-way hash, which i...
View in text
Excerpt 7
Sample Application | 73 CHAPTER 5 Vulnerability Management In Greek mythology, Achilles was killed by an arrow to his only weak spot—his heel. Achilles clear...
View in text
Excerpt 8
security-relevant settings and what the correct values are. These should be enforced when the component is initially brought into service and then checked re...
View in text
Tags
AI categories
Cloud NativeCybersecurityDevOps
ISBN: 1492037516
Publisher: O’Reilly Media
Publish Year: 2019
Language: English
Pages: 196
File Format: PDF
File Size: 6.6 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…