
CloudX Security Practical Guide
Description
Book Introduction
“Cloud security is not an option, it’s a necessity!”
A Security Practice Guide for Establishing DevSecOps and Security Governance in Various Cloud Environments
The "Cloud × Security Practice Guide" approaches security from a security perspective to address security issues that may arise during the introduction and transition of cloud systems.
First, we will help readers broaden their understanding of the cloud environment by examining the basic concepts of cloud technology and security threats and incident cases.
This sets the standard for how much security needs to be strengthened and raises awareness of the importance of secure design.
Next, we will examine cloud security design, models, and services in detail, and present cloud security threats and countermeasures that may vary depending on the purpose.
Additionally, we explore how to further enhance security by leveraging various tools such as ChatGPT, Python, API, Ansible, and Lambda functions.
By providing practical examples and solutions, this book will help readers gain a deeper understanding of cloud security and feel confident in strengthening security in real-world environments.
This will be an essential guide for anyone seeking to create a secure environment while adopting or migrating to cloud technology.
A Security Practice Guide for Establishing DevSecOps and Security Governance in Various Cloud Environments
The "Cloud × Security Practice Guide" approaches security from a security perspective to address security issues that may arise during the introduction and transition of cloud systems.
First, we will help readers broaden their understanding of the cloud environment by examining the basic concepts of cloud technology and security threats and incident cases.
This sets the standard for how much security needs to be strengthened and raises awareness of the importance of secure design.
Next, we will examine cloud security design, models, and services in detail, and present cloud security threats and countermeasures that may vary depending on the purpose.
Additionally, we explore how to further enhance security by leveraging various tools such as ChatGPT, Python, API, Ansible, and Lambda functions.
By providing practical examples and solutions, this book will help readers gain a deeper understanding of cloud security and feel confident in strengthening security in real-world environments.
This will be an essential guide for anyone seeking to create a secure environment while adopting or migrating to cloud technology.
- You can preview some of the book's contents.
Preview
index
1 Cloud Overview
_1 Cloud concept
__1.1 Cloud Definition
__1.2 Cloud Features
_2 Cloud Type
__2.1 Cloud types according to deployment model
__2.2 Cloud types according to service model
__2.3 Cloud Pros and Cons
_3 Market Status of Cloud Services
__3.1 Global Market Status
__3.2 Domestic Market Status
_4 The Need for Cloud Security
__4.1 Cloud Security Threats and Incident Cases
__4.2 Cloud Security Management Standards and Guidelines
Jang Cloud Security Design
_1 Basic Concepts of Cloud Security
__1.1 Cloud Properties and Security Specificities
__1.2 Differences between general security and cloud security
__1.3 Scope of Responsibility
__1.4 Cloud Security Model
_2 Cloud Security Design
__2.1 Cloud Migration Process
__2.2 Cloud Adoption Strategy
_3 Cloud Security Architecture Design
__3.1 Status Analysis Stage
__3.2 Introduction target selection stage
__3.3 Cloud Security Risk Assessment Steps
__3.4 Security Architecture Design Phase
_4 Measures for Cloud Security Management
3 Cloud Security Services
_1 Common Security Services
__1.1 Cloud Management Portal (CMP) Security
__1.2 Logging and Monitoring
__1.3 Gold Environment (Custom Environment)
__1.4 Marketplace Utilization
_2 Network Security Services
__2.1 Virtual Private Cloud (VPC)
__2.2 Subnet
__2.3 Access Control List (ACL)
__2.4 Firewall (Security Group)
__2.5 Network Section Encryption (TLS)
__2.6 Virtual Private Network (VPN)
__2.7 Dedicated Line Construction (Direct Connect)
__2.8 External Intrusion Detection/Blocking (IDS/IPS)
__2.9 DDoS prevention service
_3 Computing (server) resource and storage security services
__3.1 Relay Server (Bastion-host)
__3.2 Configuring an Inner Gateway Between Cloud Service Resources
_4 Application Security Services
__4.1 Web Application Firewall (WAF)
__4.2 API Protection Service
__4.3 Security Inspector
_5 Content Security Service
__5.1 Key Management Service (KMS)
__5.2 Key Management Security Module (Cloud HSM)
__5.3 Sensitive Information Automatic Search, Classification, and Protection Service (DLP)
__5.4 Environment Variable Management Service
_6 Managed Security Services
__6.1 Cloud Access Security Broker (CASB)
__6.2 Cloud Security Service (SECaaS)
__6.3 Security Operations Outsourcing (MSSP)
4. Building a purpose-specific security architecture
_1 Service security considering availability
__1.1 Multi-region based architecture and security
__1.2 Multi-cloud-based architecture and security
__1.3 Container-based architecture and security
_2 Architectural Security for High Performance
__2.1 Auto-scale up/out performance guarantee architecture and security
__2.2 Performance-Guaranteed Architecture and Security through FaaS
__2.3 Architecture and security built with dedicated allocated resources with guaranteed performance
__2.4 Architecture and security considering improving global service performance
_3 Architecture security that takes into account the safety of applications and data
__3.1 Hybrid Cloud-Based Data Architecture and Security
__3.2 Architecture and Security Based on Application/Data Encryption
__3.3 Architecture and security for linking local and cloud environments
_4 Security architecture with cost-effectiveness in mind
__4.1 Cloud architecture and security built with low-cost cloud services
__4.2 Architecture and security that involve resource flexibility according to the service environment
__4.3 Architecture and Security Using Discounted Resources with Resource Consumption Patterns
__4.4 Architecture and Security for Selecting Service Levels Based on Maintenance Costs
_5 Security architecture with an emphasis on DevOps efficiency
__5.1 Security Architecture with Automated Deployment Process
__5.2 Security architecture based on automatic infrastructure construction
__5.3 Security Architecture Utilizing Application-Level Service Forms
5 Cloud Security Management Tools
_1 Security Management Using Python
__1.1 Python Overview
__1.2 Configuring Python environment using CLI
__Scenario 1 - Managing IAM User Account Permissions
__Scenario 2 - Checking CloudTrail Log Settings
__Scenario 3 - Checking Security Group Policies
__1.3 Configuring the Python environment using the integrated development environment
_2 Security Automation Practice Using Ansible
__2.1 Ansible Overview
__2.2 Installing Ansible
__2.3 Target Server Preset
__Scenario 4 - Password Change
__Scenario 5 - Changing to an unknown port
_3 Automation Practice Using Lambda Services
__3.1 Scheduling-based resource batch change practice
_4 Automating S3 Data Encryption via CLI
Scenario 6 - Encrypting S3 Data in Practice
6 Cloud Security Governance
_1 Security Governance When Using Small Clouds
__1.1 Security Basic Policy Management
__1.2 Utilizing basic cloud features
__1.3 Enhanced Cloud Security Features
_2 Security Governance for Large-Scale Cloud Utilization
__2.1 Cloud Usage, Termination Process
__2.2 Cloud Security Management Process
__2.3 Cloud Security Settings and Security Check Process
_3 Cloud Security Issues and Solutions in the Field
__3.1 Security management case for projects with frequent changes in developers
__3.2 Case of applying an automated vulnerability inspection tool to the cloud
__3.3 Case study on improving the cloud application and cancellation process
__3.4 Vulnerability Case of Accessing Server with Jupyter Notebook
__3.5 Vulnerability Cases Where Information Can Be Leaked Through Inter-Network Access
Search
_1 Cloud concept
__1.1 Cloud Definition
__1.2 Cloud Features
_2 Cloud Type
__2.1 Cloud types according to deployment model
__2.2 Cloud types according to service model
__2.3 Cloud Pros and Cons
_3 Market Status of Cloud Services
__3.1 Global Market Status
__3.2 Domestic Market Status
_4 The Need for Cloud Security
__4.1 Cloud Security Threats and Incident Cases
__4.2 Cloud Security Management Standards and Guidelines
Jang Cloud Security Design
_1 Basic Concepts of Cloud Security
__1.1 Cloud Properties and Security Specificities
__1.2 Differences between general security and cloud security
__1.3 Scope of Responsibility
__1.4 Cloud Security Model
_2 Cloud Security Design
__2.1 Cloud Migration Process
__2.2 Cloud Adoption Strategy
_3 Cloud Security Architecture Design
__3.1 Status Analysis Stage
__3.2 Introduction target selection stage
__3.3 Cloud Security Risk Assessment Steps
__3.4 Security Architecture Design Phase
_4 Measures for Cloud Security Management
3 Cloud Security Services
_1 Common Security Services
__1.1 Cloud Management Portal (CMP) Security
__1.2 Logging and Monitoring
__1.3 Gold Environment (Custom Environment)
__1.4 Marketplace Utilization
_2 Network Security Services
__2.1 Virtual Private Cloud (VPC)
__2.2 Subnet
__2.3 Access Control List (ACL)
__2.4 Firewall (Security Group)
__2.5 Network Section Encryption (TLS)
__2.6 Virtual Private Network (VPN)
__2.7 Dedicated Line Construction (Direct Connect)
__2.8 External Intrusion Detection/Blocking (IDS/IPS)
__2.9 DDoS prevention service
_3 Computing (server) resource and storage security services
__3.1 Relay Server (Bastion-host)
__3.2 Configuring an Inner Gateway Between Cloud Service Resources
_4 Application Security Services
__4.1 Web Application Firewall (WAF)
__4.2 API Protection Service
__4.3 Security Inspector
_5 Content Security Service
__5.1 Key Management Service (KMS)
__5.2 Key Management Security Module (Cloud HSM)
__5.3 Sensitive Information Automatic Search, Classification, and Protection Service (DLP)
__5.4 Environment Variable Management Service
_6 Managed Security Services
__6.1 Cloud Access Security Broker (CASB)
__6.2 Cloud Security Service (SECaaS)
__6.3 Security Operations Outsourcing (MSSP)
4. Building a purpose-specific security architecture
_1 Service security considering availability
__1.1 Multi-region based architecture and security
__1.2 Multi-cloud-based architecture and security
__1.3 Container-based architecture and security
_2 Architectural Security for High Performance
__2.1 Auto-scale up/out performance guarantee architecture and security
__2.2 Performance-Guaranteed Architecture and Security through FaaS
__2.3 Architecture and security built with dedicated allocated resources with guaranteed performance
__2.4 Architecture and security considering improving global service performance
_3 Architecture security that takes into account the safety of applications and data
__3.1 Hybrid Cloud-Based Data Architecture and Security
__3.2 Architecture and Security Based on Application/Data Encryption
__3.3 Architecture and security for linking local and cloud environments
_4 Security architecture with cost-effectiveness in mind
__4.1 Cloud architecture and security built with low-cost cloud services
__4.2 Architecture and security that involve resource flexibility according to the service environment
__4.3 Architecture and Security Using Discounted Resources with Resource Consumption Patterns
__4.4 Architecture and Security for Selecting Service Levels Based on Maintenance Costs
_5 Security architecture with an emphasis on DevOps efficiency
__5.1 Security Architecture with Automated Deployment Process
__5.2 Security architecture based on automatic infrastructure construction
__5.3 Security Architecture Utilizing Application-Level Service Forms
5 Cloud Security Management Tools
_1 Security Management Using Python
__1.1 Python Overview
__1.2 Configuring Python environment using CLI
__Scenario 1 - Managing IAM User Account Permissions
__Scenario 2 - Checking CloudTrail Log Settings
__Scenario 3 - Checking Security Group Policies
__1.3 Configuring the Python environment using the integrated development environment
_2 Security Automation Practice Using Ansible
__2.1 Ansible Overview
__2.2 Installing Ansible
__2.3 Target Server Preset
__Scenario 4 - Password Change
__Scenario 5 - Changing to an unknown port
_3 Automation Practice Using Lambda Services
__3.1 Scheduling-based resource batch change practice
_4 Automating S3 Data Encryption via CLI
Scenario 6 - Encrypting S3 Data in Practice
6 Cloud Security Governance
_1 Security Governance When Using Small Clouds
__1.1 Security Basic Policy Management
__1.2 Utilizing basic cloud features
__1.3 Enhanced Cloud Security Features
_2 Security Governance for Large-Scale Cloud Utilization
__2.1 Cloud Usage, Termination Process
__2.2 Cloud Security Management Process
__2.3 Cloud Security Settings and Security Check Process
_3 Cloud Security Issues and Solutions in the Field
__3.1 Security management case for projects with frequent changes in developers
__3.2 Case of applying an automated vulnerability inspection tool to the cloud
__3.3 Case study on improving the cloud application and cancellation process
__3.4 Vulnerability Case of Accessing Server with Jupyter Notebook
__3.5 Vulnerability Cases Where Information Can Be Leaked Through Inter-Network Access
Search
Detailed image

Publisher's Review
Many people are well-versed in security, but why not cloud security?
Cloud security is difficult to even begin without understanding the differences between on-premises and cloud service environments.
Because the purpose and direction of cloud adoption differ for each company, the technologies applied also differ.
appropriate service
To utilize it, you need to know your users' security environment and the types of services and scope of application of various platforms.
Applying optimal security to the cloud you use requires a lot of learning and experience, and in addition to the technical aspects, there are also legal aspects.
We must also consider the scope of responsibility, including the parts and policies.
Let's make concepts and principles easy to understand with pictures, and practical examples to make them useful in practice.
The basic concepts and principles of unfamiliar clouds are explained in pictures for easy understanding.
In addition, security threats and accident cases
Starting with an overview, we will learn about cloud security design, security models, security services, etc., and from security in common areas to networks,
Security services that can be utilized in all areas, including servers, applications, and data, and cases that can be immediately applied to practice.
It is presented in a practical format.
Learn how to establish a security architecture and address different cloud security threats for different purposes.
By utilizing security management tools such as Python, API, Ansible, and Lambda functions, you can build more efficient security.
It is.
Many companies want to build their systems using cloud computing for reasons such as cost savings, business agility, security resolution, and infrastructure provision.
However, cloud security itself doesn't solve everything.
Additionally, cloud security issues are hindering cloud adoption.
This book will help security managers at companies using cloud services understand what to prioritize when implementing security, explain how on-premises and cloud environments differ, and dispel the misconception that cloud service providers will solve all security issues.
The cloud is definitely not a magic carpet.
Using the cloud requires a lot of learning and experience.
It's virtually impossible to give a definitive answer about cloud security for each company.
Therefore, the "Cloud x Security Practice Guide" is a compass-like book that shows you how and in what direction to approach cloud security.
I hope this book will serve as a helpful guide for users considering their first cloud adoption.
Cloud security is difficult to even begin without understanding the differences between on-premises and cloud service environments.
Because the purpose and direction of cloud adoption differ for each company, the technologies applied also differ.
appropriate service
To utilize it, you need to know your users' security environment and the types of services and scope of application of various platforms.
Applying optimal security to the cloud you use requires a lot of learning and experience, and in addition to the technical aspects, there are also legal aspects.
We must also consider the scope of responsibility, including the parts and policies.
Let's make concepts and principles easy to understand with pictures, and practical examples to make them useful in practice.
The basic concepts and principles of unfamiliar clouds are explained in pictures for easy understanding.
In addition, security threats and accident cases
Starting with an overview, we will learn about cloud security design, security models, security services, etc., and from security in common areas to networks,
Security services that can be utilized in all areas, including servers, applications, and data, and cases that can be immediately applied to practice.
It is presented in a practical format.
Learn how to establish a security architecture and address different cloud security threats for different purposes.
By utilizing security management tools such as Python, API, Ansible, and Lambda functions, you can build more efficient security.
It is.
Many companies want to build their systems using cloud computing for reasons such as cost savings, business agility, security resolution, and infrastructure provision.
However, cloud security itself doesn't solve everything.
Additionally, cloud security issues are hindering cloud adoption.
This book will help security managers at companies using cloud services understand what to prioritize when implementing security, explain how on-premises and cloud environments differ, and dispel the misconception that cloud service providers will solve all security issues.
The cloud is definitely not a magic carpet.
Using the cloud requires a lot of learning and experience.
It's virtually impossible to give a definitive answer about cloud security for each company.
Therefore, the "Cloud x Security Practice Guide" is a compass-like book that shows you how and in what direction to approach cloud security.
I hope this book will serve as a helpful guide for users considering their first cloud adoption.
GOODS SPECIFICS
- Date of issue: March 28, 2024
- Page count, weight, size: 472 pages | 182*232*30mm
- ISBN13: 9788965403845
- ISBN 10: 8965403847
You may also like
카테고리
korean
korean