Security Automation on AWS
Presented by James Galt and Felicia Haggarty
How can we prevent data breaches that are caused by very simple processes like closing an AWS bucket?
The crown jewel of DevSecOps is not only identifying vulnerabilities and analyzing them, but being able to resolve them before there is a breach. Automating this last step solves several problems:
-
Less exposure time means less chance of breach
-
Saves time fixing the violation or learning how to fix it
-
Developers need not get involved with every security incident
In this session, we will show you an example of a customer that had an unauthenticated queue on AWS, how it was resolved, and how these failed attacks extend their cloud security posture.