How to Secure Cloud and Microservice Workloads

448 views
•
August 2, 2019
by
RSAC Cybersecurity
YouTube video player
How to Secure Cloud and Microservice Workloads

TL;DR

Modern cloud security requires continuous monitoring, automated response, zero trust access, and guardrails embedded in DevOps workflows. Organizations should replace policies tied to hosts and IP addresses with controls based on services, names, and groups, while using cloud-native capabilities and communicating security priorities through business risk, reputation, strategic value, and revenue.

Transcript

Hello everyone. We're gonna spend the next twenty-odd minutes talking about the new rules of cybersecurity. Uh, you've spent-- You've heard, uh, across the last few minutes, um, about the various challenges we face and what that means in today's day and age. And so me, I'm Aarthi Borkar, I'm gonna walk you through what we think is the changing worl... Read More

Key Insights

  • Modern applications are collections of microservices created by many people through fast DevOps processes and distributed across internal systems and multiple cloud environments. This architecture prevents security teams from protecting applications and data as a single, centrally controlled system.
  • Critical data is distributed across data centers, multiple clouds, edge and non-edge nodes, and end-user devices. Security programs must protect business processes across this entire hybrid environment because the older model of centrally controlled data no longer reflects how applications operate.
  • Security must be integrated into the DevOps processes where developers build and release services. Adding protection within development workflows helps security operate at the same speed as cloud applications instead of relying on controls designed for long, centralized application projects.
  • Zero trust works by allowing recognized normal activity while denying everything else. The security objective should shift from identifying and stopping every presumed bad actor to explicitly permitting appropriate users, services, and behaviors based on established policies.
  • Continuous security requires constant monitoring instead of occasional testing. Because cloud applications and their weak points change rapidly across services and environments, teams need persistent visibility, instrumentation, and response capabilities that remain active as applications evolve.
  • Security guardrails define which development patterns are acceptable without placing a blocking gate at every microservice. When controls impede delivery, developers may bypass them, eliminating security visibility. Guardrails preserve development speed while producing data that helps teams monitor complex activity.
  • Security communication is more effective when expressed through business risk, strategic value, brand identity, reputation, and revenue. Technical terms such as zero-day vulnerabilities, kill chains, and indicators of compromise may remain useful among specialists but do not match how developers or boards discuss priorities.
  • Automated response runbooks can initiate scanning, identify vulnerabilities and malicious activity, analyze infected systems, determine which connections to block, and support rapid patching. This level of orchestration is necessary because manual remediation cannot match the speed and scale of distributed cloud systems.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: How should organizations secure cloud and microservice workloads?

Organizations should integrate security into DevOps, use cloud-native controls, monitor activity continuously, and automate incident response through established runbooks. Policies should identify services, names, and groups instead of depending primarily on hosts and IP addresses. Clear guardrails should define approved development patterns so teams can work quickly while security retains visibility and receives useful instrumentation from distributed environments.

Q: Why do microservices require a different security model?

Microservices are small services built by many people through fast-paced DevOps processes, and they may run across company systems and multiple clouds. They cannot be protected like a monolithic application planned over six, twelve, or eighteen months inside one data center. Their distributed design creates more weak points and requires continuous monitoring, cloud-aware controls, and faster automated responses.

Q: What is the role of zero trust in cloud security?

Zero trust changes the focus from trying to recognize and stop every bad person to allowing known, normal activity and rejecting everything else. In the model described, security policies are based on services, names, and groups rather than only hosts and IP addresses. This approach supports applications and data that move across internal systems, multiple clouds, edge nodes, and end devices.

Q: Why should security teams use guardrails instead of gates?

Guardrails tell developers which patterns are acceptable and which are not without placing a blocking checkpoint around every microservice. When security controls slow teams that are expected to move quickly, developers learn to work around those controls. Security then loses visibility and cannot instrument the bypassed activity. Approved guardrails preserve movement while producing information that helps teams monitor and manage the resulting complexity.

Q: How should cybersecurity leaders communicate with boards and developers?

Cybersecurity leaders should translate technical concerns into language centered on risk, strategic value, brand identity, reputation, and revenue. Developers and board members do not ordinarily frame decisions through terms such as zero-day vulnerabilities, kill chains, or indicators of compromise. Security specialists can retain that vocabulary internally, but broader conversations should connect proposed changes and partnerships to outcomes the rest of the company understands.

Q: How can automated runbooks improve vulnerability response?

Automated runbooks can connect an alert to a predefined remediation plan, initiate vulnerability scans, identify malicious activity, and analyze an infected system in near real time. The process should quickly determine which connections must be blocked and what must be controlled or stopped. It should then support preparation of patched systems for return to service within the next few hours.

Q: Why is continuous monitoring necessary for cloud applications?

Continuous monitoring is necessary because distributed applications operate constantly and change across microservices, clouds, edge nodes, and end devices. Periodic testing does not provide enough visibility for that pace or complexity. Security teams need instrumentation that continuously returns activity data, allowing them to identify vulnerabilities and malicious behavior, analyze affected systems, and coordinate responses as events occur.

Q: How must security culture change for cloud adoption?

Security culture must move beyond a strong preference for manual control and accept that cloud-based business transformation creates complex, changing environments. The shift begins with conversations in language the wider organization understands, followed by action involving leaders and the board. Teams should also seek help from colleagues, the security community, and people inside their organizations who have already managed similar transformations.

Summary & Key Takeaways

  • Applications built from microservices operate across company systems, multiple clouds, edge nodes, and end-user devices. This distribution breaks the older security model of protecting monolithic applications and centrally controlled data. Security must therefore operate continuously, integrate with DevOps, and apply policies to services, names, identities, and groups instead of fixed infrastructure.

  • Security teams should replace restrictive gates with clear guardrails that define acceptable and unacceptable development patterns. Developers often bypass controls that obstruct their required speed, leaving security teams without visibility or useful instrumentation. Approved patterns let developers continue building quickly while giving defenders the monitoring data needed to understand and manage complex environments.

  • Automated runbooks can transform incident response from a slow manual process into near-real-time detection, analysis, containment, and remediation. Alerts should initiate vulnerability scanning and identify malicious activity, infected systems should be analyzed rapidly, required connections should be blocked, and patched systems should be prepared to return to service within hours.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚