Hands-On Workshop: Avoiding Data Disasters: Techniques to Identify and Address Cloud Storage Misconfigurations



It appears that every few months, there's news of yet another cloud breach stemming from a carelessly configured cloud storage solution. While this isn't the default for most cloud vendors, some users still manage to make their cloud data publicly accessible by going out of their way - sometimes to a significant extent. Whether it's out of ignorance or convenience, it doesn't matter - this practice must come to an end.

 

To address this issue, we've developed a workshop that equips attendees with various techniques and methods to identify and rectify cloud storage misconfigurations in their own cloud accounts. We'll even demonstrate some ways to prevent these misconfigurations from happening in the first place. Although the chosen vendor for this workshop is AWS, due to its Simple Storage Service (S3) being the one making headlines, misconfigurations could occur in any cloud environment. Hence, the techniques discussed in this workshop will be applicable to all cloud vendor environments, including Azure, Google Cloud Platform, and Oracle.

 

LEARNING OBJECTIVES:

  • Discover all-too-common cloud storage security deficiencies present as either insecure vendor defaults or careless mistakes
  • Correct these issues using a variety of means (e.g., cloud management console, command line tools, and Infrastructure-as-Code)

PREREQUISITE KNOWLEDGE:
None.

 

SYSTEM REQUIREMENTS:
Laptop with a modern web browser
AWS account with root access or an IAM user with Administrator Access permissions

This workshop supports both SEC388: Introduction to Cloud Computing and Security and SEC488: Cloud Security Essentials.

Speaker and Presenter Information

Ryan Nicholson

Relevant Government Agencies

Other Federal Agencies, Federal Government, State & Local Government


Event Type
Webcast


When
Wed, Sep 6, 2023, 10:00am ET


Cost
Complimentary:    $ 0.00


Website
Click here to visit event website


Organizer
SANS Institute


Contact Event Organizer



Return to search results