{"product_id":"cloud-security-for-dummies-isbn-9781119790464","title":"Cloud Security For Dummies","description":"\u003cp\u003e\u003cb\u003eEmbrace the cloud and kick hackers to the curb with this accessible guide on cloud security \u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eCloud technology has changed the way we approach technology. It’s also given rise to a new set of security challenges caused by bad actors who seek to exploit vulnerabilities in a digital infrastructure. You can put the kibosh on these hackers and their dirty deeds by hardening the walls that protect your data. \u003c\/p\u003e \u003cp\u003eUsing the practical techniques discussed in \u003ci\u003eCloud Security For Dummies,\u003c\/i\u003e you’ll mitigate the risk of a data breach by building security into your network from the bottom-up. Learn how to set your security policies to balance ease-of-use and data protection and work with tools provided by vendors trusted around the world. \u003c\/p\u003e \u003cp\u003eThis book offers step-by-step demonstrations of how to: \u003c\/p\u003e \u003cul\u003e \u003cli\u003eEstablish effective security protocols for your cloud application, network, and infrastructure \u003c\/li\u003e \u003cli\u003eManage and use the security tools provided by different cloud vendors \u003c\/li\u003e \u003cli\u003eDeliver security audits that reveal hidden flaws in your security setup and ensure compliance with regulatory frameworks \u003c\/li\u003e \u003c\/ul\u003e \u003cp\u003eAs firms around the world continue to expand their use of cloud technology, the cloud is becoming a bigger and bigger part of our lives. You can help safeguard this critical component of modern IT architecture with the straightforward strategies and hands-on techniques discussed in this book.  \u003c\/p\u003e \u003cp\u003e\u003cb\u003eIntroduction\u003c\/b\u003e\u003cb\u003e 1\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eAbout This Book 2\u003c\/p\u003e \u003cp\u003eFoolish Assumptions 3\u003c\/p\u003e \u003cp\u003eIcons Used in This Book 3\u003c\/p\u003e \u003cp\u003eBeyond the Book 3\u003c\/p\u003e \u003cp\u003eWhere to Go from Here 4\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePart 1: Getting Started with Cloud Security\u003c\/b\u003e\u003cb\u003e 5\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 1: Clouds Aren’t Bulletproof\u003c\/b\u003e\u003cb\u003e 7\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eKnowing Your Business 8\u003c\/p\u003e \u003cp\u003eDiscovering the company jewels 8\u003c\/p\u003e \u003cp\u003eInitiating your plan 8\u003c\/p\u003e \u003cp\u003eAutomating the discovery process 8\u003c\/p\u003e \u003cp\u003eKnowing Your SLA Agreements with Service Providers 10\u003c\/p\u003e \u003cp\u003eWhere is the security? 10\u003c\/p\u003e \u003cp\u003eKnowing your part 11\u003c\/p\u003e \u003cp\u003eBuilding Your Team 11\u003c\/p\u003e \u003cp\u003eFinding the right people 12\u003c\/p\u003e \u003cp\u003eIncluding stakeholders 12\u003c\/p\u003e \u003cp\u003eCreating a Risk Management Plan 13\u003c\/p\u003e \u003cp\u003eIdentifying the risks 14\u003c\/p\u003e \u003cp\u003eAssessing the consequences of disaster 15\u003c\/p\u003e \u003cp\u003ePointing fingers at the right people 15\u003c\/p\u003e \u003cp\u003eDisaster planning 16\u003c\/p\u003e \u003cp\u003eWhen Security Is Your Responsibility 17\u003c\/p\u003e \u003cp\u003eDetermining which assets to protect 17\u003c\/p\u003e \u003cp\u003eKnowing your possible threat level 20\u003c\/p\u003e \u003cp\u003eVan Gogh with it (paint a picture of your scenario) 21\u003c\/p\u003e \u003cp\u003eSetting up a risk assessment database 22\u003c\/p\u003e \u003cp\u003eAvoiding Security Work with the Help of the Cloud 24\u003c\/p\u003e \u003cp\u003eHaving someone else ensure physical security 25\u003c\/p\u003e \u003cp\u003eMaking sure providers have controls to separate customer data 25\u003c\/p\u003e \u003cp\u003eRecognizing that cloud service providers can offer better security 25\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 2: Getting Down to Business\u003c\/b\u003e\u003cb\u003e 27\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eNegotiating the Shared Responsibility Model 28\u003c\/p\u003e \u003cp\u003eColoring inside the lines 29\u003c\/p\u003e \u003cp\u003eLearning what to expect from a data center 29\u003c\/p\u003e \u003cp\u003eTaking responsibility for your 75 percent 31\u003c\/p\u003e \u003cp\u003eSaaS, PaaS, IaaS, AaaA! 31\u003c\/p\u003e \u003cp\u003eSaaS 31\u003c\/p\u003e \u003cp\u003eSaaS security 32\u003c\/p\u003e \u003cp\u003ePaaS 32\u003c\/p\u003e \u003cp\u003ePaaS security 33\u003c\/p\u003e \u003cp\u003eIaaS 33\u003c\/p\u003e \u003cp\u003eIaaS security 34\u003c\/p\u003e \u003cp\u003eFaaS 34\u003c\/p\u003e \u003cp\u003eSaaS, PaaS, IaaS, FaaS responsibilities 34\u003c\/p\u003e \u003cp\u003eManaging Your Environment 35\u003c\/p\u003e \u003cp\u003eRestricting access 36\u003c\/p\u003e \u003cp\u003eAssessing supply chain risk 36\u003c\/p\u003e \u003cp\u003eManaging virtual devices 38\u003c\/p\u003e \u003cp\u003eApplication auditing 38\u003c\/p\u003e \u003cp\u003eManaging Security for Devices Not Under Your Control 39\u003c\/p\u003e \u003cp\u003eInventorying devices 39\u003c\/p\u003e \u003cp\u003eUsing a CASB solution 40\u003c\/p\u003e \u003cp\u003eApplying Security Patches 41\u003c\/p\u003e \u003cp\u003eLooking Ahead 42\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 3: Storing Data in the Cloud \u003c\/b\u003e\u003cb\u003e43\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDealing with the Data Silo Dilemma 44\u003c\/p\u003e \u003cp\u003eCataloging Your Data 45\u003c\/p\u003e \u003cp\u003eSelecting a data catalog software package 46\u003c\/p\u003e \u003cp\u003eThree steps to building a data catalog 46\u003c\/p\u003e \u003cp\u003eControlling data access 47\u003c\/p\u003e \u003cp\u003eWorking with labels 49\u003c\/p\u003e \u003cp\u003eDeveloping label-based security 50\u003c\/p\u003e \u003cp\u003eApplying sensitivity levels 50\u003c\/p\u003e \u003cp\u003eAssessing impact to critical functions 50\u003c\/p\u003e \u003cp\u003eWorking with Sample Classification Systems 51\u003c\/p\u003e \u003cp\u003eTokenizing Sensitive Data 54\u003c\/p\u003e \u003cp\u003eDefining data tokens 54\u003c\/p\u003e \u003cp\u003eIsolating your tokenization system 55\u003c\/p\u003e \u003cp\u003eAccessing a token system 55\u003c\/p\u003e \u003cp\u003eSegmenting Data 56\u003c\/p\u003e \u003cp\u003eAnonymizing Data 56\u003c\/p\u003e \u003cp\u003eEncrypting Data in Motion, in Use, and at Rest 58\u003c\/p\u003e \u003cp\u003eSecuring data in motion 59\u003c\/p\u003e \u003cp\u003eEncrypting stored data 59\u003c\/p\u003e \u003cp\u003eProtecting data in use by applications 60\u003c\/p\u003e \u003cp\u003eCreating Data Access Security Levels 60\u003c\/p\u003e \u003cp\u003eControlling User Access 61\u003c\/p\u003e \u003cp\u003eRestricting IP access 61\u003c\/p\u003e \u003cp\u003eLimiting device access 62\u003c\/p\u003e \u003cp\u003eBuilding the border wall and other geofencing techniques 63\u003c\/p\u003e \u003cp\u003eGetting rid of stale data 64\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 4: Developing Secure Software\u003c\/b\u003e\u003cb\u003e 65\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eTurbocharging Development 65\u003c\/p\u003e \u003cp\u003eNo more waterfalls 66\u003c\/p\u003e \u003cp\u003eCI\/CD: Continuous integration\/continuous delivery 68\u003c\/p\u003e \u003cp\u003eShifting left and adding security in development 68\u003c\/p\u003e \u003cp\u003eTackling security sooner rather than later 69\u003c\/p\u003e \u003cp\u003ePutting security controls in place first 70\u003c\/p\u003e \u003cp\u003eCircling back 70\u003c\/p\u003e \u003cp\u003eImplementing DevSecOps 71\u003c\/p\u003e \u003cp\u003eAutomating Testing during Development 71\u003c\/p\u003e \u003cp\u003eUsing static and dynamic code analysis 72\u003c\/p\u003e \u003cp\u003eTaking steps in automation 73\u003c\/p\u003e \u003cp\u003eLeveraging software composition analysis 74\u003c\/p\u003e \u003cp\u003eProving the job has been done right 76\u003c\/p\u003e \u003cp\u003eLogging and monitoring 76\u003c\/p\u003e \u003cp\u003eEnsuring data accountability, data assurance, and data dependability 77\u003c\/p\u003e \u003cp\u003eRunning Your Applications 78\u003c\/p\u003e \u003cp\u003eTaking advantage of cloud agnostic integration 79\u003c\/p\u003e \u003cp\u003eRecognizing the down sides of cloud agnostic development 80\u003c\/p\u003e \u003cp\u003eGetting started down the cloud agnostic path 81\u003c\/p\u003e \u003cp\u003eLike DevOps but for Data 82\u003c\/p\u003e \u003cp\u003eTesting, 1-2-3 84\u003c\/p\u003e \u003cp\u003eIs this thing working? 85\u003c\/p\u003e \u003cp\u003eWorking well with others 85\u003c\/p\u003e \u003cp\u003eBaking in trust 85\u003c\/p\u003e \u003cp\u003eDevSecOps for DataOps 86\u003c\/p\u003e \u003cp\u003eConsidering data security 87\u003c\/p\u003e \u003cp\u003eEnding data siloes 88\u003c\/p\u003e \u003cp\u003eDeveloping your data store 89\u003c\/p\u003e \u003cp\u003eMeeting the Challenges of DataSecOps 90\u003c\/p\u003e \u003cp\u003eUnderstanding That No Cloud Is Perfect 92\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 5: Restricting Access\u003c\/b\u003e\u003cb\u003e 95\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDetermining the Level of Access Required 95\u003c\/p\u003e \u003cp\u003eCatching flies with honey 96\u003c\/p\u003e \u003cp\u003eDetermining roles 97\u003c\/p\u003e \u003cp\u003eAuditing user requirements 97\u003c\/p\u003e \u003cp\u003eUnderstanding Least Privilege Policy 98\u003c\/p\u003e \u003cp\u003eGranting just-in-time privileges 99\u003c\/p\u003e \u003cp\u003eThe need-to-know strategy 99\u003c\/p\u003e \u003cp\u003eGranting access to trusted employees 99\u003c\/p\u003e \u003cp\u003eRestricting access to contractors 100\u003c\/p\u003e \u003cp\u003eImplementing Authentication 101\u003c\/p\u003e \u003cp\u003eMultifactor authentication (Or, who’s calling me now?) 101\u003c\/p\u003e \u003cp\u003eAuthenticating with API keys 102\u003c\/p\u003e \u003cp\u003eUsing Firebase authentication 102\u003c\/p\u003e \u003cp\u003eEmploying OAuth 103\u003c\/p\u003e \u003cp\u003eGoogle and Facebook authentication methods 103\u003c\/p\u003e \u003cp\u003eIntroducing the Alphabet Soup of Compliance 104\u003c\/p\u003e \u003cp\u003eGlobal compliance 104\u003c\/p\u003e \u003cp\u003eComplying with PCI 105\u003c\/p\u003e \u003cp\u003eComplying with GDPR 106\u003c\/p\u003e \u003cp\u003eHIPAA compliance 107\u003c\/p\u003e \u003cp\u003eGovernment compliance 109\u003c\/p\u003e \u003cp\u003eCompliance in general 110\u003c\/p\u003e \u003cp\u003eMaintaining Compliance and CSPM 110\u003c\/p\u003e \u003cp\u003eDiscovering and remediating threats with CSPM applications 112\u003c\/p\u003e \u003cp\u003eAutomating Compliance 113\u003c\/p\u003e \u003cp\u003eIntegrating with DevOps 113\u003c\/p\u003e \u003cp\u003eControlling Access to the Cloud 114\u003c\/p\u003e \u003cp\u003eUsing a cloud access security broker (CASB) 115\u003c\/p\u003e \u003cp\u003eMiddleware protection systems 117\u003c\/p\u003e \u003cp\u003eGetting Certified 121\u003c\/p\u003e \u003cp\u003eISO 27001 Compliance 121\u003c\/p\u003e \u003cp\u003eSOC 2 compliance 122\u003c\/p\u003e \u003cp\u003ePCI certification 124\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePart 2: Acceptance\u003c\/b\u003e\u003cb\u003e 125\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 6: Managing Cloud Resources\u003c\/b\u003e\u003cb\u003e 127\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDefending Your Cloud Resources from Attack 128\u003c\/p\u003e \u003cp\u003eLiving in a Virtual World 129\u003c\/p\u003e \u003cp\u003eMoving to virtualization 130\u003c\/p\u003e \u003cp\u003eAddressing VM security concerns 130\u003c\/p\u003e \u003cp\u003eUsing containers 131\u003c\/p\u003e \u003cp\u003eSecuring Cloud Resources with Patch Management 132\u003c\/p\u003e \u003cp\u003ePatching VMs and containers 133\u003c\/p\u003e \u003cp\u003eImplementing patch management 133\u003c\/p\u003e \u003cp\u003eKeeping Your Cloud Assets Straight in Your Mind 134\u003c\/p\u003e \u003cp\u003eKeeping Tabs with Logs 136\u003c\/p\u003e \u003cp\u003eUsing Google Cloud Management software 136\u003c\/p\u003e \u003cp\u003eUsing AWS log management 137\u003c\/p\u003e \u003cp\u003eUsing Azure log management 139\u003c\/p\u003e \u003cp\u003eWorking with third-party log management software 139\u003c\/p\u003e \u003cp\u003eLogging containers 140\u003c\/p\u003e \u003cp\u003eBuilding Your Own Defenses 141\u003c\/p\u003e \u003cp\u003eCreating your development team 141\u003c\/p\u003e \u003cp\u003eUsing open-source security 142\u003c\/p\u003e \u003cp\u003eProtecting your containers 143\u003c\/p\u003e \u003cp\u003eProtecting your codebase 143\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 7: The Role of AIOps in Cloud Security\u003c\/b\u003e\u003cb\u003e 145\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eTaking the AIOps Route 146\u003c\/p\u003e \u003cp\u003eDetecting the problem 148\u003c\/p\u003e \u003cp\u003eUsing dynamic thresholds 149\u003c\/p\u003e \u003cp\u003eCatching attacks early in the Cyber Kill chain 149\u003c\/p\u003e \u003cp\u003ePrioritizing incidents 150\u003c\/p\u003e \u003cp\u003eAssigning tasks 150\u003c\/p\u003e \u003cp\u003eDiagnosing the root problem 151\u003c\/p\u003e \u003cp\u003eReducing time to MTTR 151\u003c\/p\u003e \u003cp\u003eSpotting transitory problems 152\u003c\/p\u003e \u003cp\u003eDigging into the past 152\u003c\/p\u003e \u003cp\u003eSolving the problem 153\u003c\/p\u003e \u003cp\u003eAchieving resolution 154\u003c\/p\u003e \u003cp\u003eAutomating security responses 154\u003c\/p\u003e \u003cp\u003eContinually improving 155\u003c\/p\u003e \u003cp\u003eMaking Things Visible 155\u003c\/p\u003e \u003cp\u003eImplementing resource discovery 155\u003c\/p\u003e \u003cp\u003eAutomating discovery 156\u003c\/p\u003e \u003cp\u003eManaging Resources, CMDB-Style 157\u003c\/p\u003e \u003cp\u003eSeeing potential impacts 157\u003c\/p\u003e \u003cp\u003eAdding configuration items 158\u003c\/p\u003e \u003cp\u003eEmploying CSDM 158\u003c\/p\u003e \u003cp\u003eUsing AIOps 159\u003c\/p\u003e \u003cp\u003eGaining insights 159\u003c\/p\u003e \u003cp\u003eExamining a wireless networking use case 159\u003c\/p\u003e \u003cp\u003eUsing Splunk to Manage Clouds 161\u003c\/p\u003e \u003cp\u003eObservability 161\u003c\/p\u003e \u003cp\u003eAlerts 162\u003c\/p\u003e \u003cp\u003eSplunk and AIOps 163\u003c\/p\u003e \u003cp\u003ePredictive analytics 163\u003c\/p\u003e \u003cp\u003eAdaptive thresholding 163\u003c\/p\u003e \u003cp\u003eViews of everything 164\u003c\/p\u003e \u003cp\u003eDeep Dive in Splunk 164\u003c\/p\u003e \u003cp\u003eEvent Analytics in Splunk 164\u003c\/p\u003e \u003cp\u003eSplunk On-Call 165\u003c\/p\u003e \u003cp\u003ePhantom 166\u003c\/p\u003e \u003cp\u003ePutting ServiceNow Through Its Paces 167\u003c\/p\u003e \u003cp\u003eAIOps require an overhead view 167\u003c\/p\u003e \u003cp\u003eReact to problems 167\u003c\/p\u003e \u003cp\u003eGauge system health 168\u003c\/p\u003e \u003cp\u003eAutomation makes it all happen 169\u003c\/p\u003e \u003cp\u003eGetting the Job Done with IT Service Management 170\u003c\/p\u003e \u003cp\u003eHow ITSM is different 170\u003c\/p\u003e \u003cp\u003ePerformance analytics 170\u003c\/p\u003e \u003cp\u003eChanging Your Team 171\u003c\/p\u003e \u003cp\u003eA (Not So Final) Word 172\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 8: Implementing Zero Trust\u003c\/b\u003e\u003cb\u003e 173\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eMaking the Shift from Perimeter Security 174\u003c\/p\u003e \u003cp\u003eExamining the Foundations of Zero Trust Philosophy 175\u003c\/p\u003e \u003cp\u003eTwo-way authentication 175\u003c\/p\u003e \u003cp\u003eEndpoint device management 176\u003c\/p\u003e \u003cp\u003eEnd-to-end encryption 177\u003c\/p\u003e \u003cp\u003ePolicy based access 179\u003c\/p\u003e \u003cp\u003eAccountability 181\u003c\/p\u003e \u003cp\u003eLeast privilege 182\u003c\/p\u003e \u003cp\u003eNetwork access control and beyond 182\u003c\/p\u003e \u003cp\u003eCSPM risk automation 184\u003c\/p\u003e \u003cp\u003eDealing with Zero Trust Challenges 185\u003c\/p\u003e \u003cp\u003eChoose a roadmap 186\u003c\/p\u003e \u003cp\u003eTake a simple, step-by-step approach 186\u003c\/p\u003e \u003cp\u003eKeep in mind some challenges you face in implementing zero trust 190\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 9: Dealing with Hybrid Cloud Environments\u003c\/b\u003e\u003cb\u003e 195\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003ePublic Clouds Make Pretty Sunsets 196\u003c\/p\u003e \u003cp\u003eControlling your environment 197\u003c\/p\u003e \u003cp\u003eOptimizing for speed 197\u003c\/p\u003e \u003cp\u003eManaging security 198\u003c\/p\u003e \u003cp\u003ePrivate Clouds for Those Special Needs 199\u003c\/p\u003e \u003cp\u003eWrapping Your Mind around Hybrid Cloud Options 200\u003c\/p\u003e \u003cp\u003eHybrid storage solution 201\u003c\/p\u003e \u003cp\u003eTiered data storage 202\u003c\/p\u003e \u003cp\u003eGauging the Advantages of the Hybrid Cloud Setup 203\u003c\/p\u003e \u003cp\u003eIt’s scalable 203\u003c\/p\u003e \u003cp\u003eThe costs 203\u003c\/p\u003e \u003cp\u003eYou maintain control 203\u003c\/p\u003e \u003cp\u003eThe need for speed 204\u003c\/p\u003e \u003cp\u003eOvercoming data silos 204\u003c\/p\u003e \u003cp\u003eCompliance 206\u003c\/p\u003e \u003cp\u003eStruggling with Hybrid Challenges 207\u003c\/p\u003e \u003cp\u003eHandling a larger attack surface 207\u003c\/p\u003e \u003cp\u003eData leakage 207\u003c\/p\u003e \u003cp\u003eData transport times 208\u003c\/p\u003e \u003cp\u003eComplexity 208\u003c\/p\u003e \u003cp\u003eRisks to your service level agreements 208\u003c\/p\u003e \u003cp\u003eOvercoming Hybrid Challenges 209\u003c\/p\u003e \u003cp\u003eAsset management 209\u003c\/p\u003e \u003cp\u003eSAM 210\u003c\/p\u003e \u003cp\u003eHAM 211\u003c\/p\u003e \u003cp\u003eIT asset management 211\u003c\/p\u003e \u003cp\u003eLatency issues 212\u003c\/p\u003e \u003cp\u003eOn the Move: Migrating to a Hybrid Cloud 213\u003c\/p\u003e \u003cp\u003eData migration readiness 213\u003c\/p\u003e \u003cp\u003eMaking a plan 213\u003c\/p\u003e \u003cp\u003ePicking the right cloud service 214\u003c\/p\u003e \u003cp\u003eUsing a migration calendar 215\u003c\/p\u003e \u003cp\u003eMaking it happen 215\u003c\/p\u003e \u003cp\u003eDealing with compatibility issues 215\u003c\/p\u003e \u003cp\u003eUsing a Package 216\u003c\/p\u003e \u003cp\u003eHPE Hybrid Cloud Solution 216\u003c\/p\u003e \u003cp\u003eAmazon Web Services 216\u003c\/p\u003e \u003cp\u003eMicrosoft Azure 217\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 10: Data Loss and Disaster Recovery\u003c\/b\u003e\u003cb\u003e 219\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eLinking Email with Data Loss 220\u003c\/p\u003e \u003cp\u003eData loss from malware 221\u003c\/p\u003e \u003cp\u003eThe nefarious ransomware 222\u003c\/p\u003e \u003cp\u003eRansomware and the cloud 223\u003c\/p\u003e \u003cp\u003eCrafting Data Loss Prevention Strategies 224\u003c\/p\u003e \u003cp\u003eBacking up your data 226\u003c\/p\u003e \u003cp\u003eTiered backups 226\u003c\/p\u003e \u003cp\u003eMinimizing Cloud Data Loss 229\u003c\/p\u003e \u003cp\u003eWhy Cloud DLP? 229\u003c\/p\u003e \u003cp\u003eCloud access security brokers 229\u003c\/p\u003e \u003cp\u003eRecovering from Disaster 232\u003c\/p\u003e \u003cp\u003eRecovery planning 232\u003c\/p\u003e \u003cp\u003eBusiness continuity 232\u003c\/p\u003e \u003cp\u003eRTO and RPO 233\u003c\/p\u003e \u003cp\u003eComing up with the recovery plan itself 233\u003c\/p\u003e \u003cp\u003eChaos Engineering 235\u003c\/p\u003e \u003cp\u003ePractical chaos engineering 236\u003c\/p\u003e \u003cp\u003eListing what could go wrong 238\u003c\/p\u003e \u003cp\u003eSeeing how bad it can get 239\u003c\/p\u003e \u003cp\u003eAttaining resiliency 239\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePart 3: Business as Usual\u003c\/b\u003e\u003cb\u003e 241\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 11: Using Cloud Security Services\u003c\/b\u003e\u003cb\u003e 243\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eCustomizing Your Data Protection 244\u003c\/p\u003e \u003cp\u003eValidating Your Cloud 244\u003c\/p\u003e \u003cp\u003eMultifactor authentication 245\u003c\/p\u003e \u003cp\u003eOne-time passwords 245\u003c\/p\u003e \u003cp\u003eManaging file transfers 250\u003c\/p\u003e \u003cp\u003eHSM: Hardware Security Modules for the Big Kids 251\u003c\/p\u003e \u003cp\u003eLooking at HSM cryptography 252\u003c\/p\u003e \u003cp\u003eManaging keys with an HSM 253\u003c\/p\u003e \u003cp\u003eBuilding in tamper resistance 255\u003c\/p\u003e \u003cp\u003eUsing HSMs to manage your own keys 255\u003c\/p\u003e \u003cp\u003eMeeting financial data security requirements with HSMs 256\u003c\/p\u003e \u003cp\u003eDNSSEC 256\u003c\/p\u003e \u003cp\u003eOpenDNSSEC 257\u003c\/p\u003e \u003cp\u003eEvaluating HSM products 258\u003c\/p\u003e \u003cp\u003eLooking at cloud HSMs 259\u003c\/p\u003e \u003cp\u003eKMS: Key Management Services for Everyone Else 259\u003c\/p\u003e \u003cp\u003eSSH compliance 260\u003c\/p\u003e \u003cp\u003eThe encryption-key lifecycle 262\u003c\/p\u003e \u003cp\u003eSetting Up Crypto Service Gateways 263\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 12: When Things Go Wrong\u003c\/b\u003e\u003cb\u003e 265\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eFinding Your Focus 265\u003c\/p\u003e \u003cp\u003eStealing Data 101 266\u003c\/p\u003e \u003cp\u003eLanding, expanding, and exfiltrating 267\u003c\/p\u003e \u003cp\u003eOffboarding employees 273\u003c\/p\u003e \u003cp\u003ePreventing the Preventable and Managing Employee Security 276\u003c\/p\u003e \u003cp\u003eNavigating Cloud Native Breaches 280\u003c\/p\u003e \u003cp\u003eMinimizing employee error 281\u003c\/p\u003e \u003cp\u003eGuarding against insider data thefts 283\u003c\/p\u003e \u003cp\u003ePreventing employee data spillage 284\u003c\/p\u003e \u003cp\u003eCleaning up after the spill 285\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 13: Security Frameworks\u003c\/b\u003e\u003cb\u003e 289\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eLooking at Common Frameworks 290\u003c\/p\u003e \u003cp\u003eCOBIT 290\u003c\/p\u003e \u003cp\u003eSABSA 291\u003c\/p\u003e \u003cp\u003eFederal Financial Institutions Examination Council (FFIEC) Cyber Assessment Tool (CAT) 292\u003c\/p\u003e \u003cp\u003eFederal Risk and Authorization Management Program (FEDRAMP) 292\u003c\/p\u003e \u003cp\u003ePersonal Information Protection and Electronic Documents Act (PIPEDA) 293\u003c\/p\u003e \u003cp\u003ePayment Card Industry — Data Security Standard (PCI–DSS) 293\u003c\/p\u003e \u003cp\u003eGLBA 293\u003c\/p\u003e \u003cp\u003eSCF 294\u003c\/p\u003e \u003cp\u003eDFARS 252.204-7012\/ NIST 800-171 294\u003c\/p\u003e \u003cp\u003eISO\/IEC 27000 Series 295\u003c\/p\u003e \u003cp\u003eCIS Critical Security Controls 295\u003c\/p\u003e \u003cp\u003eCIS Benchmarks 295\u003c\/p\u003e \u003cp\u003eCommon Criteria 296\u003c\/p\u003e \u003cp\u003eFDA regulations on electronic records and signatures 296\u003c\/p\u003e \u003cp\u003eITIL 297\u003c\/p\u003e \u003cp\u003eIntroducing SASE Architecture 298\u003c\/p\u003e \u003cp\u003eThe sassy side of SASE 299\u003c\/p\u003e \u003cp\u003eSassy makeup 300\u003c\/p\u003e \u003cp\u003eThe Cloud Native Application Protection Platform 303\u003c\/p\u003e \u003cp\u003eWorking with CWPP 304\u003c\/p\u003e \u003cp\u003eManaging with CSPM 305\u003c\/p\u003e \u003cp\u003eNIST Risk Management Framework 305\u003c\/p\u003e \u003cp\u003eFederal Information Security Modernization Act 306\u003c\/p\u003e \u003cp\u003eCybersecurity Strategy and Implementation Plan 307\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 14: Security Consortiums\u003c\/b\u003e\u003cb\u003e 311\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDoing the Right Thing 311\u003c\/p\u003e \u003cp\u003eMembership in the Cloud Security Alliance 313\u003c\/p\u003e \u003cp\u003eCompany membership 314\u003c\/p\u003e \u003cp\u003eIndividual membership 315\u003c\/p\u003e \u003cp\u003eGetting that Stamp of Approval 317\u003c\/p\u003e \u003cp\u003eCCSK Certification 317\u003c\/p\u003e \u003cp\u003eCISA: Certified Security Information Systems Auditor 317\u003c\/p\u003e \u003cp\u003eCRISC: Certified Risk and Information Systems Control 318\u003c\/p\u003e \u003cp\u003eCCAK: Certificate of Cloud Auditing Knowledge 318\u003c\/p\u003e \u003cp\u003eAdvanced Cloud Security Practitioner 318\u003c\/p\u003e \u003cp\u003eGDPR Lead Auditor and Consultant 319\u003c\/p\u003e \u003cp\u003eInformation Security Alliances, Groups, and Consortiums 319\u003c\/p\u003e \u003cp\u003eWords for the Road 321\u003c\/p\u003e \u003cp\u003e\u003cb\u003ePart 4: The Part of Tens\u003c\/b\u003e\u003cb\u003e 323\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 15: Ten Steps to Better Cloud Security\u003c\/b\u003e\u003cb\u003e 325\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eScoping Out the Dangers 326\u003c\/p\u003e \u003cp\u003eInspiring the Right People to Do the Right Thing 327\u003c\/p\u003e \u003cp\u003eKeeping Configuration Management on the Straight and Narrow 328\u003c\/p\u003e \u003cp\u003eAdopting AIOps 329\u003c\/p\u003e \u003cp\u003eGetting on board with DataOps 330\u003c\/p\u003e \u003cp\u003eBefriending Zero Trust 330\u003c\/p\u003e \u003cp\u003eKeeping the Barn Door Closed 331\u003c\/p\u003e \u003cp\u003eComplying with Compliance Mandates 332\u003c\/p\u003e \u003cp\u003eJoining the Cloud Security Club 333\u003c\/p\u003e \u003cp\u003ePreparing for the Future 333\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 16: Cloud Security Solutions \u003c\/b\u003e\u003cb\u003e335\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eCheckpoint CloudGuard 335\u003c\/p\u003e \u003cp\u003eCloudPassage Halo 336\u003c\/p\u003e \u003cp\u003eThreat Stack Cloud Security Platform 336\u003c\/p\u003e \u003cp\u003eSymantec Cloud Workload Protection 336\u003c\/p\u003e \u003cp\u003eDatadog Monitoring Software 337\u003c\/p\u003e \u003cp\u003eAzure AD 338\u003c\/p\u003e \u003cp\u003ePalo Alto Prisma 338\u003c\/p\u003e \u003cp\u003eFortinet Cloud Security 338\u003c\/p\u003e \u003cp\u003eServiceNow AIOps 339\u003c\/p\u003e \u003cp\u003eLacework 340\u003c\/p\u003e \u003cp\u003eIndex 341\u003c\/p\u003e  \u003cp\u003e\u003cb\u003eTed Coombs\u003c\/b\u003e is a direct descendant of King Edward of England, a former world record holder for most miles roller skated in a day, and a longtime technology guru and author. He’s written over a dozen technology books on a wide array of topics ranging from database programming to building an internet site. Along the way he helped create early artificial intelligence tools and served as cybersecurity professional focused on computer forensics.   \u003c\/p\u003e\u003cp\u003e\u003cb\u003eStrengthen the digital walls around your cloud\u003c\/b\u003e \u003c\/p\u003e\u003cp\u003eIn addition to being one of the most exciting developments in information technology in years, cloud technology has also given rise to a ton of new security challenges. This book shares practical and straightforward techniques to mitigate the risk of a data breach by building security into your systems from the ground up. Balance user-friendliness and data protection as you work with tools provided by the world’s most trusted cloud vendors, including Microsoft, Amazon, and Google. \u003c\/p\u003e\u003cp\u003e\u003cb\u003eInside... \u003cul\u003e\n\u003cli\u003eSafely store data in the cloud\u003c\/li\u003e \u003cli\u003eDevelop secure cloud software\u003c\/li\u003e \u003cli\u003eManage cloud resources\u003c\/li\u003e \u003cli\u003eIntegrate AIOps into cloud security\u003c\/li\u003e \u003cli\u003eDeploy hybrid environments\u003c\/li\u003e \u003cli\u003eEmploy data loss Prevention\u003c\/li\u003e \u003cli\u003eCreate a security policy\u003c\/li\u003e \u003cli\u003eImplement zero trust solutions\u003c\/li\u003e\n\u003c\/ul\u003e\u003c\/b\u003e\u003c\/p\u003e","brand":"For Dummies","offers":[{"title":"Default Title","offer_id":47988936802533,"sku":"NP9781119790464","price":34.99,"currency_code":"USD","in_stock":false}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/1842\/7735\/files\/9781119790464.jpg?v=1761782122","url":"https:\/\/k12savings.com\/products\/cloud-security-for-dummies-isbn-9781119790464","provider":"K12savings","version":"1.0","type":"link"}