githubEdit

Cloud native

Be careful with your cloud ☁️

About

Cloud-native security refers to a set of security practices and technologies designed specifically for applications built and deployed in cloud environments. It involves a shift in mindset from traditional security approaches, which often rely on network-based protections, to a more application-focused approach that emphasizes identity and access management, container security and workload security, and continuous monitoring and response.

In a cloud-native security approach, security is built into the application and infrastructure from the ground up, rather than added on as an afterthought. This requires a combination of automated security controls, DevOps processes, and skilled security professionals who can manage the complex and dynamic nature of cloud environments. The goal of cloud native-security is to protect against threats and vulnerabilities that are unique to cloud environments, while also ensuring compliance with regulations and standards. [1]

Best practices

From OWASP Cloud-Native Application Security Top 10arrow-up-right [2] (CNAS, by order), try to avoid:

Resources

Find here a complete list of resources related to cloud security.

Governance

AWS Governance

MultiCloud Governance

Standards

Compliances

Benchmarks

Tools

Infrastructure

Container

SaaS

Native tools

Incident Response

Examples

Others

Reading

Podcasts

Testing & Learning

Others

Sources

[1]: What Is Cloud-Native Security? - Palo Alto Networksarrow-up-right

[2]: OWASP Cloud-Native Application Security Top 10 | OWASP Foundationarrow-up-right

[3]: 4ndersonLin/awesome-cloud-security: 🛡️ Awesome Cloud Security Resources ⚔️ (github.com)arrow-up-right

[4]: Funkmyster/awesome-cloud-security: Curated list of awesome cloud security blogs, podcasts, standards, projects, and examples. (github.com)arrow-up-right

[5]: teamssix/awesome-cloud-security: awesome cloud security 收集一些国内外不错的云安全资源,该项目主要面向国内的安全人员 (github.com)arrow-up-right

Last updated