#ChatGPT explaining cross-account Security Group referencing pretty neatly. One of the easiest ways to implement an IP Address-free trust between connected apps in #AWS.
Also called #microsegmentation.
FOLLOW US as we explore cloud network security with #AI.
#chatgpt #aws #microsegmentation #ai #awssecurity
5 motivi per cui zero trust è il futuro della sicurezza degli endpoint
#15Novembre #Security #category-Computers&ElectronicsComputerSecurity #endpointdetectionandresponse #endpointprotectionplatforms(EPP) #endpointsecurity #ExtendedDetectionandResponse(XDR)Platforms #microsegmentation #NetworkSecurityandPrivacy #unifiedendpointmanagement #zerotrust #ZeroTrustNetworkAccess #zero-trustsecurity #zero-trustsecurityspecialissue https://parliamodi.news/detail/1882.html
#zero #zerotrustnetworkaccess #zerotrust #unifiedendpointmanagement #networksecurityandprivacy #microsegmentation #extendeddetectionandresponse #EndpointSecurity #endpointprotectionplatforms #EndpointDetectionandResponse #category #security #15novembre
@dob That's a big scope.
Some things we do to make our lives easier and doesn't cost $$$.
Enable #guardduty and pipe all the alerts into a slack channel (+email as well).
Enable #cloudtrail log everything to an #S3 bucket in another account. #cloudwatch alerts on auth failures (to slack + email (some go to pagerduty #infosec contact).
We also have some alerts on updates when a cidr is added to a #SecurityGroup.
Don't use #ssh or #bastion/#JumpHosts use #ssm to run automations on the hosts (package install, service restarts etc) also to get a shell on a box (if needed at all). (you can use #TransitiveTags with #RoleAssumption to give granular access).
Using #ssm for console access also logs the entire session (including someone doing sudo su - root etc!) into #S3
Use #MicroSegmentation within our #vpc. Instances behind an #alb will only accept traffic from the #alb #SecurityGroup etc.. #rds, #elasticache willl only accept traffic from instances in the appropriate #SecurityGroup. (Basically we don't use cidr ingress rules, we use security group ids) (this works across accounts in the same region with peering, but not across regions however).
#guardduty #cloudtrail #s3 #cloudwatch #infosec #securitygroup #ssh #bastion #ssm #transitivetags #roleassumption #microsegmentation #vpc #alb #rds #elasticache #aws