- Cybersecurity:Attack and Defense Strategies
- Yuri Diogenes Erdal Ozkaya
- 198字
- 2021-06-30 19:15:51
Updating your IR process to include cloud
Ideally, you should have one single incident response process that covers both major scenarios—on-premises and cloud. This means you will need to update your current process to include all relevant information related to the cloud.
Make sure that you review the entire IR life cycle to include cloud-computing-related aspects. For example, during the preparation, you need to update the contact list to include the cloud provider contact information, on-call process, and so on. The same applies to other phases:
- Detection: Depending on the cloud model that you are using, you want to include the cloud provider solution for detection in order to assist you during the investigation (7).
- Containment: Revisit the cloud provider capabilities to isolate an incident in case it occurs, which will also vary according to the cloud model that you are using. For example, if you have a compromised VM in the cloud, you may want to isolate this VM from others in a different virtual network and temporarily block access from outside.
For more information about incident response in the cloud, we recommend that you read Domain 9 of the Cloud Security Alliance Guidance (8).
推薦閱讀
- Learning OpenDaylight
- Modern Web Testing with TestCafe
- Linux實(shí)戰(zhàn)
- Linux內(nèi)核完全注釋(20周年版·第2版)
- 白話區(qū)塊鏈
- 精通Linux內(nèi)核開發(fā)
- 玩到極致 iPhone 4S完全攻略
- 高性能Linux服務(wù)器構(gòu)建實(shí)戰(zhàn):系統(tǒng)安全、故障排查、自動(dòng)化運(yùn)維與集群架構(gòu)
- Mastering Reactive JavaScript
- 分布式高可用架構(gòu)之道
- Multi-Cloud for Architects
- 完美應(yīng)用Ubuntu(第2版)
- Java EE 8 High Performance
- Docker for Developers
- 用“芯”探核:基于龍芯的Linux內(nèi)核探索解析