Buch, Englisch, 300 Seiten, Format (B × H): 156 mm x 234 mm, Gewicht: 453 g
Managing Emerging Threats
Buch, Englisch, 300 Seiten, Format (B × H): 156 mm x 234 mm, Gewicht: 453 g
ISBN: 978-1-032-47078-8
Verlag: Taylor & Francis Ltd
In an era when the cloud environment is facing new threats such as advanced phishing campaigns, data exfiltration, and zero-day attacks, its cybersecurity should be viewed from both an offensive and defensive perspective. Offensive security measures include penetration testing to discover authentication, authorization, and network access management issues in the cloud environment. The DevSecOps captures a shift-left approach to address security early in the software development life cycle. It covers static analysis, code reviews, software component analysis, and dynamic analysis with continuous integration/continuous-deployment (CI/CD) used for deploying code in the cloud. Defensive security measures entail defense against emerging threats using vulnerability management using native tools and commercial vulnerability management software. Knowledge of threat modeling for cloud environments based on possible attack vectors and threat modeling tools specific to the cloud are essential.
The book reviews the zero-trust model that deviates from the traditional definition of trust boundaries and validates all interactions in a cloud environment. The incident response life cycle is used to prepare for, identify, contain, and eradicate security threats in the cloud. The book discusses how automation and autonomous cyber defense tools based on Artificial Intelligence and Machine Learning and techniques can help resource-constrained security teams address cloud security at a scale. It also elaborates upon some helpful case studies on the practical deployment of cloud security solutions, their limitations, and lessons learned based on case-studies experience in cloud security.
Zielgruppe
Academic
Autoren/Hrsg.
Fachgebiete
Weitere Infos & Material
Preface. Architecture of Cloud Platforms. Emerging Threats and Threat Modeling. Penetration Testing for Cloud Platform. DevSecOps in Cloud. Cloud Governance, Risks and Compliance. Designing Secure Cloud. Security Automation: AI and ML in Cloud Security. Incident Response in Cloud. Case Studies in Cloud Security. References. Index.