Hands-On Workshop: Mastering Cloud Security Policy as Code
The Cloud is enabling businesses to quickly adopt and use technology in ways that we've never imagined before. Security teams need to find ways to keep up; automation is the solution. By using Policy as Code tools we can define and enforce security guardrails. This allows developers and cloud engineers to continue shipping features while bringing the confidence to everybody that security requirements are being met.
Learning Objectives:
- Examine how unsafe systems can accidentally be deployed into production
- Automatically identify cloud environments that don't meet security requirements
- Prevent further misconfigurations via automated Policy as Code enforcement points using tools such as easy_infra and Checkov
- Remediate misconfigured systems
- Automate reassessing cloud systems, and generate evidence for compliance and audit teams
Prerequisites:
- Comfortable with Linux command line tools
- Comfortable with git-based version control systems
- Comfortable reading configuration files
System Requirements:
- A modern web browser, preferably Chrome
- AWS account with root access or an IAM user with Administrator Access permissions
If you need an AWS account, you can create a free tier account with root access at https://aws.amazon.com/free/ The cost to complete the workshop will be minimal (pennies).
This content supports materials and concepts from SEC540: Cloud Security and DevSecOps Automation.
Speaker and Presenter Information
Relevant Government Agencies
Other Federal Agencies, Federal Government, State & Local Government
Event Type
Webcast
When
Wed, Nov 1, 2023, 11:30am
ET
Cost
Complimentary: $ 0.00
Website
Click here to visit event website
Organizer
SANS Institute