Security, DevOps and Life In the Cloud - A discussion about security as it relates to cloud computing and all the technology and process that comes with it.
…
continue reading
It's the final episode of Head In The Cloud, but it's not the end of one of your favourite security podcasters! Listen up to hear what's in store for the podcast and why I'm shutting down Head In The Cloud. Some links: Purple Squad Security Purple Squad Security Slack Signup Bot Head In The Cloud was proud to be a part of the GonnaGeek Podcast Netw…
…
continue reading

1
AWS, Breaches, Chihuahuas, and more with Corey Quinn
45:38
45:38
Play later
Play later
Lists
Like
Liked
45:38I speak with Corey Quinn about AWS and their recent news headlines related to various breaches amongst other things... Corey Quinn joins me on today's podcast to talk about AWS and how they've been in the news lately for all the wrong reasons. We talk about the shared security model, things we like and may not like so much about AWS, as well as ...…
…
continue reading
A brief look at disaster recovery and how it applies to the cloud. Disaster recovery is an important part of any security plan you have for your organization. Disaster recovery in the cloud is equally important but is often overlooked. In this episode I take a look at different levels of disaster recover, how to apply them to the cloud and some ide…
…
continue reading

1
Uncovering flAWS In Your AWS Cloud Environment
41:28
41:28
Play later
Play later
Lists
Like
Liked
41:28Scott Piper (@0xdabbad00) joins me to talk about flAWS, a website he created that is part capture the flag (CTF), red/blue team training, AWS security guide and honeypot! Lots of interesting topics of discussion in this episode you definitely don't want to miss! Some links: flAWS SummitRoute Downclimb Blog Article - Free Tools for Auditing The Secu…
…
continue reading
Looking at the different *aaS solutions, what they are and what the security concerns around them are. The big three! The "ah-s" or "as-s" if you will. I discuss what IaaS, PaaS, and SaaS are, what they stand for and what security related concerns you should have regarding each one. Some links: CIS Hardening Benchmarks Proud to be part of the Gonna…
…
continue reading
I talk about Malware and some protections we can take in preventing its spread. Today's episode is all about Malware - what can we do to protect ourselves, what are some best practices we can follow, etc. I'm a firm believer that Malware is something we can help curtail if we all do our part in protecting ourselves. The fewer systems there are to i…
…
continue reading

1
DevSecOps and Rugged DevOps with Anurag “Archie” Agarwal
31:36
31:36
Play later
Play later
Lists
Like
Liked
31:36I speak with Anurag “Archie” Agarwal from ThreadModeler about DevSecOps, Rugged DevOps, their differences and a bit about threat modeling. In this episode I speak with "Archie" Agarwal about DevSecOps and Rugged DevOps before venturing off to some other topics. Great interview, Archie is very knowledgable and a great guest! Have a listen and make s…
…
continue reading
In this episode, I take a look at the different colours that often come up in security discussions, such as black, white, red, blue, gray, and purple! Looking at each one in turn as well as figuring out what they mean is the purpose of this episode. And people thought InfoSec was boring... Happy to be part of the GonnaGeek Podcast Network! Want to …
…
continue reading
Taking a look at IDSs, what they are, how they work and how they relate to cloud security. In this week's podcast I take a look at Intrusion Detection Systems (IDSs), what they are, what they do, how they work and how they fit into a cloud security model. I went a bit long on this one but I think it's necessary given the breadth of this topic. Some…
…
continue reading

1
Data Residency and Privacy with Ishay Tentser
38:15
38:15
Play later
Play later
Lists
Like
Liked
38:15I speak with Ishay Tentser, CEO of IniTech-Digital Products & Innovation, about Data Residency and Privacy. In this week's podcast I welcome Ishay Tentser to discuss data residency, privacy and law. This is an important topic that can get overlooked as you focus on security, but with a global economy, it's important to keep it at the forefront. Ish…
…
continue reading
Are you a security dictator or a respected colleague? Soft skills and relationship building are on the menu for this episode! Taking a bit of a different turn in this episode. I will be looking at relationship building, whom to start with and who may require a softer touch. Do you want to be the security dictator or someone who is viewed as a peer?…
…
continue reading

1
A high level overview of DevOps and Related Tools
52:27
52:27
Play later
Play later
Lists
Like
Liked
52:27In today's podcast I take a look at system provisioning and the tools your DevOps team may want to look into, and how these tools can help increase your security stance in the cloud! Back from a mini-break for Mother's Day, in today's podcast I take a look at system provisioning and the tools your DevOps team may want to look into, and how these to…
…
continue reading
I interview Loïc Simon about Scout2, a great tool to help assess your security posturing on AWS! In this episode I speak with Loïc Simon, the author of Scout2, a great tool to assess your security posture on AWS. We cover what Scout2 is, why it came about and how it differs from other tools like AWS Trusted Advisor. It's a great interview with an a…
…
continue reading

1
CIS AWS Foundations Benchmark – Sections 2-4
43:44
43:44
Play later
Play later
Lists
Like
Liked
43:44Completing our review of the CIS AWS Foundations Benchmark, sections 2 through 4. In this episode we will finish off the remaining sections of the CIS AWS Foundations Benchmark, looking at sections 2 through 4. Lots of good stuff in here, including a number of things you may not have considered if you're new to AWS, so it's definitely worth a liste…
…
continue reading

1
CIS AWS Foundations Benchmark – Section 1
28:17
28:17
Play later
Play later
Lists
Like
Liked
28:17In this, my second episode, I look at the first section of the CIS AWS Foundations Benchmark and answer the question, what should you do first to lock down your cloud systems? In the second episode of the podcast I take a look at some first steps in securing your AWS account by looking at the Center for Internet Security's AWS Foundations Benchmark…
…
continue reading
Meet the host and hear about 5 common cloud security misconceptions and why you should ignore them. In this first podcast I introduce myself and then cover 5 common security misconceptions related to cloud computing, in no particular order. Still getting my bearings, so please bear with me. Some links: Synergy Research Group Cloud Provider Market S…
…
continue reading