The Inner Circle

 View Only
  • 1.  CCM for Serverless and Kubernetes

    Posted May 08, 2020 09:42:00 AM
    How are you guys working or dealing with security controls when it comes to serverless and Kubernetes. I think CCM will help me  but the question is around there is no physical server involved in serverless which can be easily eliminated however at the same time  what else can be eliminated or added specific to serverless. Hs anyone worked on something similar? 

    Thanks

    ------------------------------
    Adnan Rafique Cloud Security Leader
    ------------------------------


  • 2.  RE: CCM for Serverless and Kubernetes

    Posted May 10, 2020 02:57:00 PM
    Hello
    2 pointers for you for the serverless part.
    • "The Serverless Cloud Security Model: A Point Of View" [1]
    • "Deploy security controls for serverless apps with infrastructure-as-code tools" [2]

    [1] https://www.cloudtp.com/doppler/the-serverless-cloud-security-model-a-point-of-view/
    [2] https://conferences.oreilly.com/velocity/vl-ca-2018/public/schedule/detail/66568 for the slides.

    ------------------------------
    Olivier Caleff - CSA French Chapter - Chapter Leader - [email protected] - https://CloudSecurityAlliance.fr
    ------------------------------



  • 3.  RE: CCM for Serverless and Kubernetes

    Posted May 11, 2020 08:05:00 AM
    Edited by John Kinsella May 11, 2020 08:05:37 AM
    Adnan - the serverless security working group is researching this right now if you care to add your thoughts. You're asking the right question - it's not just what risks have gone away, but what new ones are we now faced with trying to mitigate?

    As to when a paper will be out - I'm not the lead so will stay mum there. :)

    ------------------------------
    John Kinsella
    ------------------------------



  • 4.  RE: CCM for Serverless and Kubernetes

    Posted May 11, 2020 11:13:00 AM
    Interesting, 
    Yes I'm working on a project or may be two and into a situation where I have to a security review and also develop a bas line framework which in my thought process should work across all the major CSP. However this is one of the most complex hybrid scenario I can think. 

    --

    Regards

    Adnan Rafique