Hi guys, Rafael here!
It's mid January 2021 and we have been working really hard during Christmas.
We have some glitches, some bugs that we have struggled through.
If anyone was under the impression that bugs doesn't exist in the cloud, you might
think again, they do still exist on that altitude.
Today's episode, we are totally focused on the aspect of security.
So I'm so happy to be able to have this chat with our experts and my colleagues Firdous Bath and Arturo Viveros.
So, hi guys! So happy to be able to talk to you.
I guess when it comes to security in the cloud we could spend hours, but let's elaborate a little bit about
the concept of shared responsibility model and zero trust, which is two important things to bring with you.
So I'll start with you Firdous, could you elaborate on the shared responsibility model?
Well, shared responsibility in my opinion, this is the fundamental concept of the security.
While cloud provider manages security of the cloud, security in the cloud is the responsibility of the customer.
Let me put it in this way, I'm renting a house, that security of the actual house is landlord responsibility.
Like fencing the house, set up fire alarm, proper door lock system etcetera.
Security of the objects are the items of things which we stored inside the house is my responsibility.
If I leave the door wide open for some reason and somebody comes and robs me, I cannot blame
the landlord for that, the fault is mine.
Okay, a shared responsibility right?
Yes!
Okay, Arturo, what about zero trust?
I guess that's something to think about when we really want to tight things up?
Yeah, definitely so it's understood that you have a big responsibility as an organisation through the security wise in the cloud.
How do you cope, how do you fulfill your end of the deal. So a proper way to do this is by implementing a zero trust architecture.
Which means that no one is trusted by default, no one get's any privileges even if they are friends or known to you.
So if you have your house as it was and you were to invite people in, they don't have
access to every room, every drawer, every cabinet to your safe where you keep your valuables.
If you gonna give them access, it needs to be very specific, and it needs to be shortlived and even through your house
once they leave, they cannot come back unless you invite them again so don't get to keep the keys and this is what
you need to do in the cloud because you are facing challenges, multi-tenancies for example,
identity propagation, multiple providers, so that's how you cope.
Ok, cool, so shared responsibility and think about building a zero trust architecture, right?
Right!
Great! Thank you guys! Bye bye!