SlideShare una empresa de Scribd logo
1 de 15
Through 2020, 95% of cloud security
failures will be the customer’s fault
Gartner
Source: Gartner Revels Top Predictions for IT Organizations and Users for 2016 and Beyond, October 2015
Insecure misconfiguration & lack of controls
#1 cause to cloud based data centers breaches
Source: https://www.forbes.com/sites/forbestechcouncil/2018/08/09/the-one-cloud-security-metric-every-ciso-should-know/#3ff8c87e5375 , Author: Josh Stella, Forbes council
80%
424%
Secure foundation
Physical assets
Datacenter operations
Cloud infrastructure and fabric
Google provides built-in controls
Virtual machines and networks
Apps and workloads
Data
Cloud security is a shared responsibility
It can feel hard to create a
secure cloud environment
We understand your dilemma
● Cloud Services are being created and destroyed
every minute
● Security is always changing; there are new threats
every week
● It’s hard to find experienced Cloud Security
Practitioners
● How do you keep your environment secure while
staying abreast of the latest security solutions?
How does your company
understand the quality of their
security posture against security
controls that are possible to
configure within GCP?
GCP Security Command Center
How does your company
understand and resolve its most
urgent cloud security issues?
This is how NovaQuantum reviews your environment
Assess
● Review the core security
configurations of your
environment
● Analyze data using an
automation engine to
detect findings
● Identify opportunities to
strengthen your existing
security controls
Recommend
● Identify security remediations to
address security gaps and other
opportunities that are identified
● Propose improvements to key
areas of your organization’s
security architecture
Review
● Deliver a detailed report of findings
and recommendations
1 2 3
How does your company
understand the quality of their
security posture against industry
recognized security standards?
Security and Compliance
Standard Author Description
GCP CIS 1.1.0 Center for Internet
Security
Set of security controls published by the Center
for Internet Security
PCI DSS 3.2.1 Payment Card Industry
Standards Council
Standards required for organizations that
manage payment card data
ISO 27001 International Standards
Organization
Set of security controls for information security
systems. Standard 27017 is cloud computing
specific.
NIST 800-53 National Institute of
Standards and
Technology
Security and Privacy Controls for Federal
Information Systems and Organizations.
By default, most of the environments are
NOT compliant with any security standards!
Our Proposal: let us manage your GCP security!
 Perform an initial assessment of the existing infrastructure and identify the critical components
 Enable auditing of the environment against one(or more) of the following regulatory standards: GCP
CIS 1.0.0, NIST 800-53, PCI DSS 3.2, ISO 27001, and SOC TSP.
 Provide continuous monitoring and enforcement (only for zero risk controls) of your custom security policies
 Provide monthly/weekly reports of the compliance status
 Provide a Cloud Security Posture Review:
 Review and evaluate the current architecture and security configurations of your GCP
environment, as compared to GCP security best practices
 Capture findings and develop a report with recommendations on how to improve the security
posture of your GCP environment.
We provide managed GCP Security services:
Resource Management
Identity, Authentication
& Authorization
Network Security VM Security
GCP org hierarchy
Environments & resource isolation
Project creation
Resource provisioning
Organization policies
User & group management
Administrative roles
Authentication
Assigning IAM roles
Service accounts
VPC architecture
Firewall rules
Network logging
VPC service controls
DDoS and WAF
Identity Aware Proxy
VM identities
Remote access
Image management
Deep dive analysis on the following security domains:
Cloud Security Posture Review topics
1 2 3 4
Data security Security operations GKE security
Encryption key management
Cloud Storage security
BigQuery security
Cloud SQL security
Data Loss Prevention
Logging
Monitoring
Policy scanning
Incident Response
GKE cluster provisioning
Secure cluster default configurations
Cluster IAM/RBAC
Container image building
Container lifecycle management
Container runtime security
Workload hardening and isolation
Cloud Security Posture Review topics(cont.)
Deep-dive analysis on the following security domains:
5 6 7
Pricing for our services
1. Initial deployment and configuration of your custom security policies – This is the effort associated with
the initial creation of the security framework that you want to be compliant with: not all the security
policies available in GCP by default would make sense for your particular environment as some of them
could impede your normal management operations, for example.
2. Creation of the Cloud Security Posture report: We review your current configurations and platform
controls, provide detailed recommendations, and present best practices to reduce risk and mitigate
common threats to your environment.
3. On-going management – This is the effort required for daily support of the GCP Security Compliance
service, monitoring of log sources, policy violations, remediation of security controls and on-going alerts
tune-up.
Plans that scale with your environment
Small Environments
(under 100 resources)
Medium Environments
(100-250 resources)
Large Environments
(>250 resources)
Initial fee: contact us! Initial fee: contact us! Initial fee: contact us!
Monthly fee: contact us! Monthly fee: contact us! Monthly fee: contact us!

Más contenido relacionado

Último

Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Chandigarh Call girls 9053900678 Call girls in Chandigarh
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
imonikaupta
 
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
dharasingh5698
 

Último (20)

Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
Wagholi & High Class Call Girls Pune Neha 8005736733 | 100% Gennuine High Cla...
 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
 
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
Russian Call Girls in %(+971524965298  )#  Call Girls in DubaiRussian Call Girls in %(+971524965298  )#  Call Girls in Dubai
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
 
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
 
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
 
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts ServiceReal Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
 
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting  High Prof...
VIP Model Call Girls Hadapsar ( Pune ) Call ON 9905417584 Starting High Prof...
 
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
 
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
 
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
 
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 BookingVIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
VIP Call Girls Himatnagar 7001035870 Whatsapp Number, 24/07 Booking
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 

Destacado

Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Destacado (20)

Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 

NovaQuantum managed gcp security services

  • 1.
  • 2. Through 2020, 95% of cloud security failures will be the customer’s fault Gartner Source: Gartner Revels Top Predictions for IT Organizations and Users for 2016 and Beyond, October 2015
  • 3. Insecure misconfiguration & lack of controls #1 cause to cloud based data centers breaches Source: https://www.forbes.com/sites/forbestechcouncil/2018/08/09/the-one-cloud-security-metric-every-ciso-should-know/#3ff8c87e5375 , Author: Josh Stella, Forbes council 80% 424%
  • 4. Secure foundation Physical assets Datacenter operations Cloud infrastructure and fabric Google provides built-in controls Virtual machines and networks Apps and workloads Data Cloud security is a shared responsibility
  • 5. It can feel hard to create a secure cloud environment We understand your dilemma ● Cloud Services are being created and destroyed every minute ● Security is always changing; there are new threats every week ● It’s hard to find experienced Cloud Security Practitioners ● How do you keep your environment secure while staying abreast of the latest security solutions?
  • 6. How does your company understand the quality of their security posture against security controls that are possible to configure within GCP?
  • 8. How does your company understand and resolve its most urgent cloud security issues?
  • 9. This is how NovaQuantum reviews your environment Assess ● Review the core security configurations of your environment ● Analyze data using an automation engine to detect findings ● Identify opportunities to strengthen your existing security controls Recommend ● Identify security remediations to address security gaps and other opportunities that are identified ● Propose improvements to key areas of your organization’s security architecture Review ● Deliver a detailed report of findings and recommendations 1 2 3
  • 10. How does your company understand the quality of their security posture against industry recognized security standards?
  • 11. Security and Compliance Standard Author Description GCP CIS 1.1.0 Center for Internet Security Set of security controls published by the Center for Internet Security PCI DSS 3.2.1 Payment Card Industry Standards Council Standards required for organizations that manage payment card data ISO 27001 International Standards Organization Set of security controls for information security systems. Standard 27017 is cloud computing specific. NIST 800-53 National Institute of Standards and Technology Security and Privacy Controls for Federal Information Systems and Organizations. By default, most of the environments are NOT compliant with any security standards!
  • 12. Our Proposal: let us manage your GCP security!  Perform an initial assessment of the existing infrastructure and identify the critical components  Enable auditing of the environment against one(or more) of the following regulatory standards: GCP CIS 1.0.0, NIST 800-53, PCI DSS 3.2, ISO 27001, and SOC TSP.  Provide continuous monitoring and enforcement (only for zero risk controls) of your custom security policies  Provide monthly/weekly reports of the compliance status  Provide a Cloud Security Posture Review:  Review and evaluate the current architecture and security configurations of your GCP environment, as compared to GCP security best practices  Capture findings and develop a report with recommendations on how to improve the security posture of your GCP environment. We provide managed GCP Security services:
  • 13. Resource Management Identity, Authentication & Authorization Network Security VM Security GCP org hierarchy Environments & resource isolation Project creation Resource provisioning Organization policies User & group management Administrative roles Authentication Assigning IAM roles Service accounts VPC architecture Firewall rules Network logging VPC service controls DDoS and WAF Identity Aware Proxy VM identities Remote access Image management Deep dive analysis on the following security domains: Cloud Security Posture Review topics 1 2 3 4
  • 14. Data security Security operations GKE security Encryption key management Cloud Storage security BigQuery security Cloud SQL security Data Loss Prevention Logging Monitoring Policy scanning Incident Response GKE cluster provisioning Secure cluster default configurations Cluster IAM/RBAC Container image building Container lifecycle management Container runtime security Workload hardening and isolation Cloud Security Posture Review topics(cont.) Deep-dive analysis on the following security domains: 5 6 7
  • 15. Pricing for our services 1. Initial deployment and configuration of your custom security policies – This is the effort associated with the initial creation of the security framework that you want to be compliant with: not all the security policies available in GCP by default would make sense for your particular environment as some of them could impede your normal management operations, for example. 2. Creation of the Cloud Security Posture report: We review your current configurations and platform controls, provide detailed recommendations, and present best practices to reduce risk and mitigate common threats to your environment. 3. On-going management – This is the effort required for daily support of the GCP Security Compliance service, monitoring of log sources, policy violations, remediation of security controls and on-going alerts tune-up. Plans that scale with your environment Small Environments (under 100 resources) Medium Environments (100-250 resources) Large Environments (>250 resources) Initial fee: contact us! Initial fee: contact us! Initial fee: contact us! Monthly fee: contact us! Monthly fee: contact us! Monthly fee: contact us!

Notas del editor

  1. Why are we here?