aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • Engineering
  • Practices

Cloud CISO Perspectives: November 2021

  • aster.cloud
  • December 2, 2021
  • 5 minute read

We’re coming up on the end of the year, yet many of the most pressing security themes from 2021 remain the same, from securing open source software, to enabling zero trust architectures and more. I’ll recap the latest updates from the Google Cybersecurity Action Team and industry progress on important security efforts in this month’s post.

Thoughts from around the industry

  • Securing open source software: Google’s Open Source Software team recently announced ClusterFuzzLite, a continuous fuzzing solution that can run as part of CI/CD workflows to find vulnerabilities. With just a few lines of code, GitHub users can integrate ClusterFuzzLite into their workflow and fuzz pull requests to catch bugs before they are committed. Implementing security checks as early as possible in developer workflows is paramount for improving supply chain security, and NIST’s guidelines for software verification specify fuzzing among the minimum standard requirements for code verification.
  • Runtime cloud-native security: Google Cloud’s Eric Brewer and I discussed the latest trends and the role of cloud providers and startups with InfoWorld in the ‘Race to Secure Kubernetes at Runtime’. Our work in this space goes back many years when we outlined our approach to cloud-native security through our BeyondProd framework, which details one of the core design principles of cloud-native security architectures: protections must extend to how code is changed and how user data in microservices is accessed.
  • The risks and opportunities of the transition to cloud computing: Office of the CISO Director Nick Godfrey and I sat down with Robert Sales of the Global Association of Risk Professionals to discuss the digital risk management landscape. Our discussion covers timely themes like how ensuring the safe adoption of cloud computing is becoming an increasing priority, reflecting the benefits that an organization can accrue from a digital transformation in terms of agility, quality of product and services provided to customers, and relevance in the marketplace and understanding how cloud-driven transformation can actually mitigate existing security, control and resilience risks. Check out the full webinar here.
  • Open source DDR controller framework for mitigating Rowhammer: Google and Antmicro developed a new Rowhammer Tester platform to enable memory security researchers and manufacturers to have access to a flexible platform for experimenting with new types of attacks and finding better Rowhammer mitigation techniques. This important work demonstrates how open source, vendor-neutral IP, tools and hardware can produce better platforms for more effective research and product development.
  • Ethical AI best practices: Many of you are likely engaged in your organizations on controls around AI including the ethical framework for the use of AI. Take a look at SEED (Security, Ethics, Explainability and Data) in this great summary from Maribel Lopez, Founder, Analyst & Author, Lopez Research, on the importance of controls in AI.
Read More  A Visual Tour Of Google Cloud Certifications

Google Cybersecurity Action Team Highlights

Here’s a snapshot of the latest updates, new services and resources across our Google Cybersecurity Action Team and Google Cloud Security products since our last post.


Partner with aster.cloud
for your next big idea.
Let us know here.



From our partners:

CITI.IO :: Business. Institutions. Society. Global Political Economy.
CYBERPOGO.COM :: For the Arts, Sciences, and Technology.
DADAHACKS.COM :: Parenting For The Rest Of Us.
ZEDISTA.COM :: Entertainment. Sports. Culture. Escape.
TAKUMAKU.COM :: For The Hearth And Home.
ASTER.CLOUD :: From The Cloud And Beyond.
LIWAIWAI.COM :: Intelligence, Inside and Outside.
GLOBALCLOUDPLATFORMS.COM :: For The World's Computing Needs.
FIREGULAMAN.COM :: For The Fire In The Belly Of The Coder.
ASTERCASTER.COM :: Supra Astra. Beyond The Stars.
BARTDAY.COM :: Prosperity For Everyone.

Security

  • Reducing risk and increasing sustainability: Veolia, the global leader in optimized resource management, is using Google Cloud’s Security Command Center (SCC) Premium as the core product for protecting the company’s technology environments. In a recent blog post, Thomas Meriadec, Technical Lead and Product Manager for Veolia’s Google Cloud implementation, discusses how SCC Premium serves as the company’s risk management platform and enables Veolia to streamline the process of security management.

Compliance

  • Google Cybersecurity Action Team’s Risk and Compliance as Code (RCaC) solution helps organizations prevent security misconfigurations and  automate cloud compliance. The solution enables compliance and security control automation through a combination of Google Cloud products, blueprints, partner integrations, workshops and services to simplify and accelerate time to value.
  • We announced new public sector authorizations including the Impact Level 4 designation for Google Cloud services and FedRAMP High for Google Workspace. These authorizations are a part of our ongoing commitment to help the US federal government modernize their security with cloud-native services at scale. For Google Workspace, this means that federal agencies now have an alternative and choice for productivity and collaboration tools that are completely cloud-native in the marketplace. With IL4 authorization for select GCP services, this is a demonstration of the efficacy of our security controls at scale across our public cloud infrastructure.

Controls

  • We released new security capabilities for Google Cloud’s enterprise-ready control plane product Traffic Director, which provides fully-managed workload credentials for Google Kubernetes Engine (GKE) via our managed CA Service, and policy enforcement to govern workload communications. The fully-managed credential  provides the foundation for expressing workload identities and securing  connections between workloads leveraging mutual TLS (mTLS), while following zero trust principles.
  • Review our timely guidance here on how to create and safeguard admin accounts in GCP including links to more in-depth guidance in our resource guides.
Read More  Google Cloud Collaborates With Comair To Provide Seamless Travel Experiences In Sub-Saharan Africa

Threat Intelligence 

  • Google’s Cybersecurity Action Team released the first issue of the new Threat Horizons report, which is based on cybersecurity threat intelligence observations from Google’s internal security teams. Part of offering a secure cloud computing platform is providing cloud users with cybersecurity threat intelligence so they can better configure their environments and defenses in manners most specific to their needs. This new report provides actionable intelligence that enables organizations to ensure their cloud environments are best protected against ever-evolving threats. Our future reports will continue to provide threat horizon scanning, trend tracking, and Early Warning announcements about emerging threats requiring immediate action. Learn more in our blog post or click here to download the executive summary.

Must-listen podcasts 

  • Our Cloud Security Podcast has some must-listen episodes this month. Hear from MK Palmore,  a new director in Google Cloud’s Office of the CISO and member of the Cybersecurity Action Team on how Missing Diversity Hurts Your Security and other topics like why email phishing still isn’t solved with Ryan Noon, CEO at Material Security, and the difference between cloud misconfigurations and on-premise infra misconfiguration with the GSK team. Finally, an interview with a Chronicle customer about their SIEM experience is covered in the latest episode.

Upcoming Q4 Security Talks – all things Zero Trust

  • Our Google Cloud Security Talks event for Q4 will focus on a topic that we’ve emphasized continuously in our Cloud CISO Perspectives – Zero Trust. Join us on December 15 to hear from leaders across Google as well as leading-edge customers on the many facets of an enterprise zero trust journey. Click here to reserve your spot and we’ll see you there (virtually).
Read More  Test Your Skills In The Google Maps Platform Hackathon

If you’d like to have this Cloud CISO Perspectives post delivered every month to your inbox, click here to sign-up. We’ll be back next month for our final Cloud CISO Perspectives blog of 2021.

 

By: Phil Venables (VP/CISO, Google Cloud)
Source: Google Cloud Blog


For enquiries, product placements, sponsorships, and collaborations, connect with us at [email protected]. We'd love to hear from you!

Our humans need coffee too! Your support is highly appreciated, thank you!

aster.cloud

Related Topics
  • CISO
  • Google Cloud
  • Google Cybersecurity Action Team
  • Security
You May Also Like
View Post
  • Engineering
  • Technology

Guide: Our top four AI Hypercomputer use cases, reference architectures and tutorials

  • March 9, 2025
View Post
  • Computing
  • Engineering

Why a decades old architecture decision is impeding the power of AI computing

  • February 19, 2025
View Post
  • Engineering
  • Software Engineering

This Month in Julia World

  • January 17, 2025
View Post
  • Engineering
  • Software Engineering

Google Summer of Code 2025 is here!

  • January 17, 2025
View Post
  • Data
  • Engineering

Hiding in Plain Site: Attackers Sneaking Malware into Images on Websites

  • January 16, 2025
View Post
  • Computing
  • Design
  • Engineering
  • Technology

Here’s why it’s important to build long-term cryptographic resilience

  • December 24, 2024
IBM and Ferrari Premium Partner
View Post
  • Data
  • Engineering

IBM Selected as Official Fan Engagement and Data Analytics Partner for Scuderia Ferrari HP

  • November 7, 2024
View Post
  • Engineering

Transforming the Developer Experience for Every Engineering Role

  • July 14, 2024

Stay Connected!
LATEST
  • college-of-cardinals-2025 1
    The Definitive Who’s Who of the 2025 Papal Conclave
    • May 7, 2025
  • conclave-poster-black-smoke 2
    The World Is Revalidating Itself
    • May 6, 2025
  • 3
    Conclave: How A New Pope Is Chosen
    • April 25, 2025
  • Getting things done makes her feel amazing 4
    Nurturing Minds in the Digital Revolution
    • April 25, 2025
  • 5
    AI is automating our jobs – but values need to change if we are to be liberated by it
    • April 17, 2025
  • 6
    Canonical Releases Ubuntu 25.04 Plucky Puffin
    • April 17, 2025
  • 7
    United States Army Enterprise Cloud Management Agency Expands its Oracle Defense Cloud Services
    • April 15, 2025
  • 8
    Tokyo Electron and IBM Renew Collaboration for Advanced Semiconductor Technology
    • April 2, 2025
  • 9
    IBM Accelerates Momentum in the as a Service Space with Growing Portfolio of Tools Simplifying Infrastructure Management
    • March 27, 2025
  • 10
    Tariffs, Trump, and Other Things That Start With T – They’re Not The Problem, It’s How We Use Them
    • March 25, 2025
about
Hello World!

We are aster.cloud. We’re created by programmers for programmers.

Our site aims to provide guides, programming tips, reviews, and interesting materials for tech people and those who want to learn in general.

We would like to hear from you.

If you have any feedback, enquiries, or sponsorship request, kindly reach out to us at:

[email protected]
Most Popular
  • 1
    IBM contributes key open-source projects to Linux Foundation to advance AI community participation
    • March 22, 2025
  • 2
    Co-op mode: New partners driving the future of gaming with AI
    • March 22, 2025
  • 3
    Mitsubishi Motors Canada Launches AI-Powered “Intelligent Companion” to Transform the 2025 Outlander Buying Experience
    • March 10, 2025
  • PiPiPi 4
    The Unexpected Pi-Fect Deals This March 14
    • March 13, 2025
  • Nintendo Switch Deals on Amazon 5
    10 Physical Nintendo Switch Game Deals on MAR10 Day!
    • March 9, 2025
  • /
  • Technology
  • Tools
  • About
  • Contact Us

Input your search keywords and press Enter.