Knowledgebase

Cloud Security: Everything That Matters, Briefly Print

  • 0

The summary.

THE ERROR THAT CAUSES MOST SERIOUS CLOUD INCIDENTS

Storage left publicly accessible, usually after a setting was changed to make something work and never reverted.

Check what is public, across every storage location, and repeat the check periodically.

THE SECOND

Access keys committed to a repository. They are found by automated scanning within minutes and used to run expensive workloads at your cost.

Never place credentials in code.

WHAT TO DO WITH THE OWNER ACCOUNT

Use it rarely. Work from restricted accounts day to day, with a second authentication step on everything.

WHAT MUST BE ENABLED BEFORE YOU NEED IT

Logging. It cannot be enabled retrospectively, and an incident without it cannot be investigated.

WHAT ENCRYPTION BY THE PROVIDER PROTECTS AGAINST

Physical access to their hardware. Not a compromised account of yours.

Access control is what protects against that.

THE SHORT LIST FOR A SMALL TEAM

Second authentication step, individual accounts with minimum permissions, public access closed, billing alerts, access removed on departure.

That prevents most cloud incidents, and none of it is expensive.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot