avatarTeri Radichel

Summary

Teri Radichel's content provides insights into cloud governance, emphasizing the importance of automating governance processes, utilizing proper software development lifecycle practices, and implementing effective cloud security measures to prevent data breaches and misconfigurations in AWS environments.

Abstract

The website content is a compilation of stories and technical guidance on cloud governance by cybersecurity expert Teri Radichel, focusing on AWS. It advocates for moving beyond traditional paper policies to automated governance, leveraging a proper Software Development Lifecycle (SDLC) with distinct teams for governance code development, quality assurance, and operations. Radichel stresses the use of separation of duties to design secure architectures that require multiple parties for critical actions, thereby reducing the risk of egregious misconfiguration and limiting potential damage from compromised administrator credentials. The content includes links to detailed articles on establishing AWS Organizations, implementing Service Control Policies (SCPs), managing tags for governance and security, and strategies for handling account closures and migrations. Radichel also discusses the importance of executive support for cybersecurity efforts, risk management policies, and the creation of a Cloud Security Center of Excellence. The articles cover a range of topics from setting up AWS Organizations and SCPs to managing KMS keys and deployment systems, all aimed at enhancing security and governance in the cloud.

Opinions

  • Paper policies are insufficient for cloud environments; automation is key.
  • Utilizing an SDLC with separate development, QA, and operations teams is crucial for governance code.
  • Separation of duties is recommended to prevent misconfigurations and limit security risks.
  • Executive support is essential for effective cybersecurity efforts.
  • Cybersecurity metrics should be automated and aligned with organizational goals.
  • AWS Organizations, SCPs, and tags are important tools for cloud governance.
  • Customized governance and SCPs provide better control than standard solutions like AWS Control Tower.
  • Naming conventions and programmatic governance are vital for organizing and managing AWS resources.
  • Monitoring account spending can be a strategy for detecting security issues.
  • Deployment systems can significantly impact cybersecurity risk, and should be designed with security in mind.

Cloud Governance

Stories on Cloud Governance by Teri Radichel

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

⚙️ Part of my series on Automating Cybersecurity Metrics. The Code.

🔒 Related Stories: Multicloud Security | Data Breaches | Cloud Governance

💻 Free Content on Jobs in Cybersecurity | ✉️ Sign up for the Email List

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Cloud Governance is one of the most critical things you can do to prevent data breaches in your cloud accounts. But you must do it in a manner that actually prevents attacks. Stop writing paper polices and automate your governance. Allow your governance team to develop and deploy the rules. New tools from cloud providers make this much easier than it has been in the past.

Use a proper Software Development Lifecycle (SDLC) that includes separate development, QA, and operations or production teams for governance code. Use separation of duties to design architectures that require multiple parties to take an action to help prevent egregious misconfiguration and limit the blast radius should an administrators credentials get compromised.

Cloud Governance on AWS

Had some issues with AWS Organizations and Control Tower. Some of this has been resolved, but not all.

The chapters not published in my blog that are in my book — Cybersecurity for Executives in the Age of Cloud.

Most of my blog series on automating cybersecurity metrics has an element of Cloud Governance to it:

Naming conventions for AWS resources in an organization.

Tags are useful for tracking resources on AWS, but also come with some caveats. Hint: Automate tags and lock them down if you are counting on them.

Autoamted VPC Flow Logs Governance

I opted to remove or decommission AWS Control Tower in favor of more customized governance and SCPs I can better control.

At some point I started over without Control Tower, creating a new AWS account from scratch but can reuse a lot of the elements I had already created to improve governance in AWS. This post covers some of the elements and proceed from there to see how they are used in the new AWS Organization structure.

Increase the number of accounts you can have in an organization:

On closing and migrating accounts:

Governance for Executives, risk management, policies, and exceptions

Follow for updates.

Teri Radichel | © 2nd Sight Lab 2023

About Teri Radichel:
~~~~~~~~~~~~~~~~~~~~
⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab
Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation
Follow for more stories like this:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
❤️ Sign Up my Medium Email List
❤️ Twitter: @teriradichel
❤️ LinkedIn: https://www.linkedin.com/in/teriradichel
❤️ Mastodon: @teriradichel@infosec.exchange
❤️ Facebook: 2nd Sight Lab
❤️ YouTube: @2ndsightlab
Governance
Cybersecurity
Risk Management
Cloud
Topics
Recommended from ReadMedium