《1沈珑-企业云安全建设之路(19页).pdf》由会员分享,可在线阅读,更多相关《1沈珑-企业云安全建设之路(19页).pdf(19页珍藏版)》请在三个皮匠报告上搜索。
1、企业云安全建设之路Robin Shen,Nov 2021Agenda 云安全面临的挑战 如何制定企业的云安全策略和路线图 云安全控制点设计 云安全管理平台 CSPM 云源生的安全能力 CWPP Q&AGartner 公有云支出报告Revenue&Cost2022202120202019$243B$270B$332B$397B23%INCREASEPublic Cloud Service Spending Forecast(Total Market Worldwide)SOURCE:Gartner Research/Nov 2020&Apr 2021Gartner Predict:2022,80
2、%企业服务会部署在云端云安全挑战5数字化转型DevOps/敏捷开发容器化/微服务/开源技术跨部门协作 多云环境旧数据中心,旧的应用系统威胁无处不在内部/外部威胁勒索软件隐私与合规越来越多,越来越严的合规趋势1243多云支持,全球部署统一的账号管理和身份安全统一的安全策略(SDSec)统一的管理平台统一的合规管理和监控云安全战略的愿景123451)战略一致性2)差距分析评估3)优先级分析 4)技术工具、方案选型5)部署安全控制措施和工具7)持续监控和改进6)运维支持SOC 支持统一日志平台监控实现愿景的7步骤云安全-常见问题PaaS SecuritySQL PaaS Enable Public
3、AccessEnsure that Public access level is set to Private for blob containersNetwork SecuritySSH/RDP access is not restricted from the internet Ensure HTTPS TLS 1.2 higher enabledKey ManagementEnsure the key vault is recoverableHost SecurityEnsure that the endpoint protection for all Virtual Machines
4、is installedLog managementEnsure that Send alerts to is setEnsure that Auditing is set to OnEnsure audit profile captures all the activitiesEnsure that Activity Log Retention is set 180 days or greaterSecurity OperationClouds assets out of security control/monitoring(legacy or shadow IT)Identity pro
5、tection云安全运维-账号安全,共享运维账号,使用特权账号运维云安全-常见问题PaaS SecuritySQL PaaS Enable Public AccessEnsure that Public access level is set to Private for blob containersNetwork SecuritySSH/RDP access is not restricted from the internet Ensure HTTPS TLS 1.2 higher enabledKey ManagementEnsure the key vault is recovera
6、bleHost SecurityEnsure that the endpoint protection for all Virtual Machines is installedLog managementEnsure that Send alerts to is setEnsure that Auditing is set to OnEnsure audit profile captures all the activitiesEnsure that Activity Log Retention is set 180 days or greaterSecurity OperationClou