SlideShare uma empresa Scribd logo
1 de 15
Through 2020, 95% of cloud security
failures will be the customer’s fault
Gartner
Source: Gartner Revels Top Predictions for IT Organizations and Users for 2016 and Beyond, October 2015
Insecure misconfiguration & lack of controls
#1 cause to cloud based data centers breaches
Source: https://www.forbes.com/sites/forbestechcouncil/2018/08/09/the-one-cloud-security-metric-every-ciso-should-know/#3ff8c87e5375 , Author: Josh Stella, Forbes council
80%
424%
Secure foundation
Physical assets
Datacenter operations
Cloud infrastructure and fabric
Google provides built-in controls
Virtual machines and networks
Apps and workloads
Data
Cloud security is a shared responsibility
It can feel hard to create a
secure cloud environment
We understand your dilemma
● Cloud Services are being created and destroyed
every minute
● Security is always changing; there are new threats
every week
● It’s hard to find experienced Cloud Security
Practitioners
● How do you keep your environment secure while
staying abreast of the latest security solutions?
How does your company
understand the quality of their
security posture against security
controls that are possible to
configure within GCP?
GCP Security Command Center
How does your company
understand and resolve its most
urgent cloud security issues?
This is how NovaQuantum reviews your environment
Assess
● Review the core security
configurations of your
environment
● Analyze data using an
automation engine to
detect findings
● Identify opportunities to
strengthen your existing
security controls
Recommend
● Identify security remediations to
address security gaps and other
opportunities that are identified
● Propose improvements to key
areas of your organization’s
security architecture
Review
● Deliver a detailed report of findings
and recommendations
1 2 3
How does your company
understand the quality of their
security posture against industry
recognized security standards?
Security and Compliance
Standard Author Description
GCP CIS 1.1.0 Center for Internet
Security
Set of security controls published by the Center
for Internet Security
PCI DSS 3.2.1 Payment Card Industry
Standards Council
Standards required for organizations that
manage payment card data
ISO 27001 International Standards
Organization
Set of security controls for information security
systems. Standard 27017 is cloud computing
specific.
NIST 800-53 National Institute of
Standards and
Technology
Security and Privacy Controls for Federal
Information Systems and Organizations.
By default, most of the environments are
NOT compliant with any security standards!
Our Proposal: let us manage your GCP security!
 Perform an initial assessment of the existing infrastructure and identify the critical components
 Enable auditing of the environment against one(or more) of the following regulatory standards: GCP
CIS 1.0.0, NIST 800-53, PCI DSS 3.2, ISO 27001, and SOC TSP.
 Provide continuous monitoring and enforcement (only for zero risk controls) of your custom security policies
 Provide monthly/weekly reports of the compliance status
 Provide a Cloud Security Posture Review:
 Review and evaluate the current architecture and security configurations of your GCP
environment, as compared to GCP security best practices
 Capture findings and develop a report with recommendations on how to improve the security
posture of your GCP environment.
We provide managed GCP Security services:
Resource Management
Identity, Authentication
& Authorization
Network Security VM Security
GCP org hierarchy
Environments & resource isolation
Project creation
Resource provisioning
Organization policies
User & group management
Administrative roles
Authentication
Assigning IAM roles
Service accounts
VPC architecture
Firewall rules
Network logging
VPC service controls
DDoS and WAF
Identity Aware Proxy
VM identities
Remote access
Image management
Deep dive analysis on the following security domains:
Cloud Security Posture Review topics
1 2 3 4
Data security Security operations GKE security
Encryption key management
Cloud Storage security
BigQuery security
Cloud SQL security
Data Loss Prevention
Logging
Monitoring
Policy scanning
Incident Response
GKE cluster provisioning
Secure cluster default configurations
Cluster IAM/RBAC
Container image building
Container lifecycle management
Container runtime security
Workload hardening and isolation
Cloud Security Posture Review topics(cont.)
Deep-dive analysis on the following security domains:
5 6 7
Pricing for our services
1. Initial deployment and configuration of your custom security policies – This is the effort associated with
the initial creation of the security framework that you want to be compliant with: not all the security
policies available in GCP by default would make sense for your particular environment as some of them
could impede your normal management operations, for example.
2. Creation of the Cloud Security Posture report: We review your current configurations and platform
controls, provide detailed recommendations, and present best practices to reduce risk and mitigate
common threats to your environment.
3. On-going management – This is the effort required for daily support of the GCP Security Compliance
service, monitoring of log sources, policy violations, remediation of security controls and on-going alerts
tune-up.
Plans that scale with your environment
Small Environments
(under 100 resources)
Medium Environments
(100-250 resources)
Large Environments
(>250 resources)
Initial fee: contact us! Initial fee: contact us! Initial fee: contact us!
Monthly fee: contact us! Monthly fee: contact us! Monthly fee: contact us!

Mais conteúdo relacionado

Último

Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
@Chandigarh #call #Girls 9053900678 @Call #Girls in @Punjab 9053900678
 
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
nirzagarg
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
dharasingh5698
 

Último (20)

Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
 
Al Barsha Night Partner +0567686026 Call Girls Dubai
Al Barsha Night Partner +0567686026 Call Girls  DubaiAl Barsha Night Partner +0567686026 Call Girls  Dubai
Al Barsha Night Partner +0567686026 Call Girls Dubai
 
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
VIP Model Call Girls NIBM ( Pune ) Call ON 8005736733 Starting From 5K to 25K...
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
6.High Profile Call Girls In Punjab +919053900678 Punjab Call GirlHigh Profil...
 
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts ServiceReal Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
 
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
 
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
 
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency""Boost Your Digital Presence: Partner with a Leading SEO Agency"
"Boost Your Digital Presence: Partner with a Leading SEO Agency"
 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
 
APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
 
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 
Trump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts SweatshirtTrump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts Sweatshirt
 

Destaque

Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Destaque (20)

Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 

NovaQuantum managed gcp security services

  • 1.
  • 2. Through 2020, 95% of cloud security failures will be the customer’s fault Gartner Source: Gartner Revels Top Predictions for IT Organizations and Users for 2016 and Beyond, October 2015
  • 3. Insecure misconfiguration & lack of controls #1 cause to cloud based data centers breaches Source: https://www.forbes.com/sites/forbestechcouncil/2018/08/09/the-one-cloud-security-metric-every-ciso-should-know/#3ff8c87e5375 , Author: Josh Stella, Forbes council 80% 424%
  • 4. Secure foundation Physical assets Datacenter operations Cloud infrastructure and fabric Google provides built-in controls Virtual machines and networks Apps and workloads Data Cloud security is a shared responsibility
  • 5. It can feel hard to create a secure cloud environment We understand your dilemma ● Cloud Services are being created and destroyed every minute ● Security is always changing; there are new threats every week ● It’s hard to find experienced Cloud Security Practitioners ● How do you keep your environment secure while staying abreast of the latest security solutions?
  • 6. How does your company understand the quality of their security posture against security controls that are possible to configure within GCP?
  • 8. How does your company understand and resolve its most urgent cloud security issues?
  • 9. This is how NovaQuantum reviews your environment Assess ● Review the core security configurations of your environment ● Analyze data using an automation engine to detect findings ● Identify opportunities to strengthen your existing security controls Recommend ● Identify security remediations to address security gaps and other opportunities that are identified ● Propose improvements to key areas of your organization’s security architecture Review ● Deliver a detailed report of findings and recommendations 1 2 3
  • 10. How does your company understand the quality of their security posture against industry recognized security standards?
  • 11. Security and Compliance Standard Author Description GCP CIS 1.1.0 Center for Internet Security Set of security controls published by the Center for Internet Security PCI DSS 3.2.1 Payment Card Industry Standards Council Standards required for organizations that manage payment card data ISO 27001 International Standards Organization Set of security controls for information security systems. Standard 27017 is cloud computing specific. NIST 800-53 National Institute of Standards and Technology Security and Privacy Controls for Federal Information Systems and Organizations. By default, most of the environments are NOT compliant with any security standards!
  • 12. Our Proposal: let us manage your GCP security!  Perform an initial assessment of the existing infrastructure and identify the critical components  Enable auditing of the environment against one(or more) of the following regulatory standards: GCP CIS 1.0.0, NIST 800-53, PCI DSS 3.2, ISO 27001, and SOC TSP.  Provide continuous monitoring and enforcement (only for zero risk controls) of your custom security policies  Provide monthly/weekly reports of the compliance status  Provide a Cloud Security Posture Review:  Review and evaluate the current architecture and security configurations of your GCP environment, as compared to GCP security best practices  Capture findings and develop a report with recommendations on how to improve the security posture of your GCP environment. We provide managed GCP Security services:
  • 13. Resource Management Identity, Authentication & Authorization Network Security VM Security GCP org hierarchy Environments & resource isolation Project creation Resource provisioning Organization policies User & group management Administrative roles Authentication Assigning IAM roles Service accounts VPC architecture Firewall rules Network logging VPC service controls DDoS and WAF Identity Aware Proxy VM identities Remote access Image management Deep dive analysis on the following security domains: Cloud Security Posture Review topics 1 2 3 4
  • 14. Data security Security operations GKE security Encryption key management Cloud Storage security BigQuery security Cloud SQL security Data Loss Prevention Logging Monitoring Policy scanning Incident Response GKE cluster provisioning Secure cluster default configurations Cluster IAM/RBAC Container image building Container lifecycle management Container runtime security Workload hardening and isolation Cloud Security Posture Review topics(cont.) Deep-dive analysis on the following security domains: 5 6 7
  • 15. Pricing for our services 1. Initial deployment and configuration of your custom security policies – This is the effort associated with the initial creation of the security framework that you want to be compliant with: not all the security policies available in GCP by default would make sense for your particular environment as some of them could impede your normal management operations, for example. 2. Creation of the Cloud Security Posture report: We review your current configurations and platform controls, provide detailed recommendations, and present best practices to reduce risk and mitigate common threats to your environment. 3. On-going management – This is the effort required for daily support of the GCP Security Compliance service, monitoring of log sources, policy violations, remediation of security controls and on-going alerts tune-up. Plans that scale with your environment Small Environments (under 100 resources) Medium Environments (100-250 resources) Large Environments (>250 resources) Initial fee: contact us! Initial fee: contact us! Initial fee: contact us! Monthly fee: contact us! Monthly fee: contact us! Monthly fee: contact us!

Notas do Editor

  1. Why are we here?