About Session:
This session aims to identify the tools that help us build secure applications and environments for Microsoft Azure during the development journey. The focus is on the developers and the tools we can use to ensure that our code is secure and aligned with all the available best practices and recommendations. It’s a hands-on session, limited to 10 slides and a lot of demos.
About Speaker:
Radu Vunvulea is a technology enthusiast working as Group Head of Cloud Delivery for Endava. He has a vast experience in different technologies and industries. Most of his time is spent working with the cloud, helping companies to innovate and finding solutions to their business problems. He enjoys building bridges between people and helping others to grow. He shares his knowledge on his personal blog and at different events where he is invited as a speaker. In his spare time, he drives an IT community and he is also a Microsoft Regional Director and Microsoft Azure MVP.
Register via Azure User Group Sweden registration link https://www.meetup.com/azureusergroupsundsvallsverige/events/303428344
Show More Show Less View Video Transcript
0:00
[Music]
0:22
show
0:25
[Music]
0:31
hello and welcome to Asher User Group
0:34
hello and welcome to Asher User Group
0:34
hello and welcome to Asher User Group Sweden now uh today uh we will
0:38
Sweden now uh today uh we will
0:38
Sweden now uh today uh we will unfortunately not have Jonah with us she
0:40
unfortunately not have Jonah with us she
0:40
unfortunately not have Jonah with us she had a bit of a sore throat there so she
0:43
had a bit of a sore throat there so she
0:43
had a bit of a sore throat there so she needed to rest but we have our guest Ru
0:48
needed to rest but we have our guest Ru
0:48
needed to rest but we have our guest Ru V who will speak about secure
0:50
V who will speak about secure
0:50
V who will speak about secure application development but before we
0:53
application development but before we
0:53
application development but before we start our stream I will just give some
0:55
start our stream I will just give some
0:55
start our stream I will just give some short background information about uh
0:58
short background information about uh
0:58
short background information about uh about me and also about our user group
1:01
about me and also about our user group
1:01
about me and also about our user group here so my name is hokan silog I work as
1:04
here so my name is hokan silog I work as
1:04
here so my name is hokan silog I work as an AI evangelist at sopra in Norway I'm
1:08
an AI evangelist at sopra in Norway I'm
1:08
an AI evangelist at sopra in Norway I'm also a Microsoft MVP in artificial
1:10
also a Microsoft MVP in artificial
1:10
also a Microsoft MVP in artificial intelligence a Microsoft certified
1:12
intelligence a Microsoft certified
1:12
intelligence a Microsoft certified trainer a public speaker and also a
1:15
trainer a public speaker and also a
1:15
trainer a public speaker and also a community
1:19
organizer so we have a code of conduct
1:21
organizer so we have a code of conduct
1:21
organizer so we have a code of conduct here for our meetups so we should be
1:25
here for our meetups so we should be
1:25
here for our meetups so we should be nice and friendly you should listen with
1:27
nice and friendly you should listen with
1:27
nice and friendly you should listen with purpose and be thoughtful you should be
1:29
purpose and be thoughtful you should be
1:29
purpose and be thoughtful you should be be respectful to others you seek to
1:32
be respectful to others you seek to
1:32
be respectful to others you seek to understand not criticize and be curious
1:34
understand not criticize and be curious
1:34
understand not criticize and be curious and open to share IDs and also be
1:37
and open to share IDs and also be
1:37
and open to share IDs and also be inclusive in your comments or
1:42
questions if you want to join our Meetup
1:44
questions if you want to join our Meetup
1:44
questions if you want to join our Meetup Community to keep track on when our next
1:46
Community to keep track on when our next
1:47
Community to keep track on when our next Meetup is scheduled you can scan this QR
1:50
Meetup is scheduled you can scan this QR
1:50
Meetup is scheduled you can scan this QR code and we are always looking out for
1:53
code and we are always looking out for
1:53
code and we are always looking out for speakers so regardless if you're an
1:55
speakers so regardless if you're an
1:55
speakers so regardless if you're an experienced speaker or if you have never
1:57
experienced speaker or if you have never
1:57
experienced speaker or if you have never spoken before you can submit the session
2:00
spoken before you can submit the session
2:00
spoken before you can submit the session here to our um s session IED call for
2:04
here to our um s session IED call for
2:04
here to our um s session IED call for speaker and if you are um if you're new
2:08
speaker and if you are um if you're new
2:08
speaker and if you are um if you're new both me and Jonah will be able to uh
2:11
both me and Jonah will be able to uh
2:11
both me and Jonah will be able to uh help you with your
2:15
presentation and at the end of our show
2:18
presentation and at the end of our show
2:18
presentation and at the end of our show we also would like to invite you here
2:20
we also would like to invite you here
2:20
we also would like to invite you here for a short digital F which is a short
2:23
for a short digital F which is a short
2:23
for a short digital F which is a short Zoom meeting where you'll be able to
2:25
Zoom meeting where you'll be able to
2:25
Zoom meeting where you'll be able to speak directly to our speaker and to us
2:29
speak directly to our speaker and to us
2:29
speak directly to our speaker and to us if you want to discuss things more in
2:31
if you want to discuss things more in
2:31
if you want to discuss things more in detail so you can scan this QR code I
2:34
detail so you can scan this QR code I
2:34
detail so you can scan this QR code I will show it also at the end of a
2:36
will show it also at the end of a
2:36
will show it also at the end of a session and I will also send out the
2:39
session and I will also send out the
2:39
session and I will also send out the link in in the chat
2:44
there so with that said I would like to
2:48
there so with that said I would like to
2:48
there so with that said I would like to invite Ru here onto the stage here so
2:52
invite Ru here onto the stage here so
2:52
invite Ru here onto the stage here so welome
2:53
welome
2:53
welome Ru hi hello everybody and thank you for
2:57
Ru hi hello everybody and thank you for
2:57
Ru hi hello everybody and thank you for having me today
3:00
having me today
3:00
having me today yeah so yes a little bit more former
3:02
yeah so yes a little bit more former
3:02
yeah so yes a little bit more former introduction here so Ru is a technology
3:05
introduction here so Ru is a technology
3:05
introduction here so Ru is a technology Enthusiast he's working as a group head
3:07
Enthusiast he's working as a group head
3:07
Enthusiast he's working as a group head of cloud delivery for endava and he has
3:10
of cloud delivery for endava and he has
3:10
of cloud delivery for endava and he has a vast experience in different
3:11
a vast experience in different
3:11
a vast experience in different Technologies and industries most of his
3:14
Technologies and industries most of his
3:14
Technologies and industries most of his time is spent working with the cloud
3:15
time is spent working with the cloud
3:15
time is spent working with the cloud helping companies to innovate and
3:17
helping companies to innovate and
3:17
helping companies to innovate and finding solution to their business
3:19
finding solution to their business
3:19
finding solution to their business problems he enjoys Building Bridges
3:21
problems he enjoys Building Bridges
3:21
problems he enjoys Building Bridges between people and helping others to
3:23
between people and helping others to
3:23
between people and helping others to grow and he shares his knowledge on both
3:26
grow and he shares his knowledge on both
3:26
grow and he shares his knowledge on both his personal blog and also at different
3:28
his personal blog and also at different
3:28
his personal blog and also at different events where he's invited as speaker and
3:30
events where he's invited as speaker and
3:30
events where he's invited as speaker and he a spare time he drives an IT
3:33
he a spare time he drives an IT
3:33
he a spare time he drives an IT community and is also a Microsoft
3:35
community and is also a Microsoft
3:35
community and is also a Microsoft Regional director and a Microsoft Asher
3:39
Regional director and a Microsoft Asher
3:39
Regional director and a Microsoft Asher MVP so we're very happy to have you here
3:42
MVP so we're very happy to have you here
3:42
MVP so we're very happy to have you here with
3:43
with
3:43
with us thank you thank you for our
3:45
us thank you thank you for our
3:45
us thank you thank you for our invitation and I hope that you will
3:48
invitation and I hope that you will
3:48
invitation and I hope that you will enjoy uh the session that I prepared so
3:52
enjoy uh the session that I prepared so
3:52
enjoy uh the session that I prepared so will would you like to say a couple of
3:53
will would you like to say a couple of
3:53
will would you like to say a couple of words about your session for our viewers
3:55
words about your session for our viewers
3:55
words about your session for our viewers here what they will learn today yes uh
3:59
here what they will learn today yes uh
3:59
here what they will learn today yes uh ially the first time when I buil this
4:01
ially the first time when I buil this
4:01
ially the first time when I buil this session was in
4:03
session was in
4:03
session was in 2022 it was very focused on
4:07
2022 it was very focused on
4:07
2022 it was very focused on developer
4:09
developer
4:09
developer uh uh tools and so on but things change
4:12
uh uh tools and so on but things change
4:13
uh uh tools and so on but things change and uh we realize that there are so many
4:15
and uh we realize that there are so many
4:15
and uh we realize that there are so many other services that we need to consider
4:17
other services that we need to consider
4:17
other services that we need to consider we need
4:18
we need
4:18
we need to integrate with our application layer
4:22
to integrate with our application layer
4:22
to integrate with our application layer that uh I have 10 main topics 10 main
4:26
that uh I have 10 main topics 10 main
4:26
that uh I have 10 main topics 10 main area that I would like to share with you
4:30
area that I would like to share with you
4:30
area that I would like to share with you for some of them you might know them but
4:32
for some of them you might know them but
4:32
for some of them you might know them but what I notified uh because on my side
4:35
what I notified uh because on my side
4:35
what I notified uh because on my side time I'm also doing different
4:37
time I'm also doing different
4:37
time I'm also doing different assessments for Cloud solution that many
4:40
assessments for Cloud solution that many
4:40
assessments for Cloud solution that many time these are the main components that
4:44
time these are the main components that
4:44
time these are the main components that applications uh don't cover them fully
4:48
applications uh don't cover them fully
4:48
applications uh don't cover them fully or just think hit them a little bit and
4:52
or just think hit them a little bit and
4:52
or just think hit them a little bit and most of the cases is because the
4:54
most of the cases is because the
4:54
most of the cases is because the business value to them is not presented
4:56
business value to them is not presented
4:56
business value to them is not presented right or just because of time
5:00
right or just because of time
5:00
right or just because of time and money that the customer or the
5:03
and money that the customer or the
5:03
and money that the customer or the business has to do to invest in them but
5:06
business has to do to invest in them but
5:06
business has to do to invest in them but they are crucial if you want to have a
5:10
they are crucial if you want to have a
5:10
they are crucial if you want to have a secure
5:14
application nice yeah so it sounds it's
5:16
application nice yeah so it sounds it's
5:16
application nice yeah so it sounds it's also one thing I forgot to mention here
5:18
also one thing I forgot to mention here
5:18
also one thing I forgot to mention here is say October is cyber security
5:20
is say October is cyber security
5:21
is say October is cyber security awareness month so that's also very
5:23
awareness month so that's also very
5:23
awareness month so that's also very fitting here with the topic for today so
5:27
fitting here with the topic for today so
5:27
fitting here with the topic for today so uh before we start here we just got some
5:29
uh before we start here we just got some
5:29
uh before we start here we just got some a message here so we got message from
5:32
a message here so we got message from
5:32
a message here so we got message from Nikos Nikos deis saying good morning
5:34
Nikos Nikos deis saying good morning
5:34
Nikos Nikos deis saying good morning from Chile Malo n is also one of our
5:37
from Chile Malo n is also one of our
5:37
from Chile Malo n is also one of our community members and we got the message
5:40
community members and we got the message
5:40
community members and we got the message here from Jona good good noon everyone H
5:45
here from Jona good good noon everyone H
5:45
here from Jona good good noon everyone H and
5:46
and
5:46
and everyone with that said I will uh add
5:49
everyone with that said I will uh add
5:49
everyone with that said I will uh add your presentation here and then the
5:51
your presentation here and then the
5:51
your presentation here and then the stage is is
5:53
stage is is
5:53
stage is is yours okay I think it is time to start
5:56
yours okay I think it is time to start
5:56
yours okay I think it is time to start uh I'm planning to finish at 55
5:59
uh I'm planning to finish at 55
5:59
uh I'm planning to finish at 55 55
6:01
55
6:01
55 uh some people time it's 1555 for me so
6:06
uh some people time it's 1555 for me so
6:06
uh some people time it's 1555 for me so hi guys uh nice meeting you
6:09
hi guys uh nice meeting you
6:09
hi guys uh nice meeting you all uh today secure application
6:13
all uh today secure application
6:13
all uh today secure application development we'll talk about a lot of
6:14
development we'll talk about a lot of
6:15
development we'll talk about a lot of azure
6:15
azure
6:16
azure Services um short story long we have
6:20
Services um short story long we have
6:20
Services um short story long we have framework for for M aure also we have
6:23
framework for for M aure also we have
6:23
framework for for M aure also we have for AWS and for Google Cloud but you
6:26
for AWS and for Google Cloud but you
6:26
for AWS and for Google Cloud but you know but we know that
6:27
know but we know that
6:28
know but we know that time uh available budget and in the end
6:33
time uh available budget and in the end
6:33
time uh available budget and in the end team size provides us constraints about
6:37
team size provides us constraints about
6:37
team size provides us constraints about what we can do and what we can add and
6:39
what we can do and what we can add and
6:39
what we can do and what we can add and today I want to emphasize what are the
6:41
today I want to emphasize what are the
6:41
today I want to emphasize what are the core things that we need to put in
6:44
core things that we need to put in
6:44
core things that we need to put in place and just to give you an example
6:47
place and just to give you an example
6:47
place and just to give you an example how sec how important is security and
6:50
how sec how important is security and
6:50
how sec how important is security and what is the what can be the impact cost
6:55
what is the what can be the impact cost
6:55
what is the what can be the impact cost um I'm working for andava and one of our
6:59
um I'm working for andava and one of our
6:59
um I'm working for andava and one of our core
7:00
core
7:00
core uh business is building Financial
7:05
uh business is building Financial
7:05
uh business is building Financial applications uh payments payment getways
7:07
applications uh payments payment getways
7:07
applications uh payments payment getways for example in a payment Gateway space
7:10
for example in a payment Gateway space
7:10
for example in a payment Gateway space if you're building an aure solution and
7:12
if you're building an aure solution and
7:12
if you're building an aure solution and you are at the beginning you're a small
7:14
you are at the beginning you're a small
7:14
you are at the beginning you're a small payment Gateway that you don't still
7:16
payment Gateway that you don't still
7:16
payment Gateway that you don't still have large customer High number of
7:18
have large customer High number of
7:19
have large customer High number of transactions you can end up easily in
7:21
transactions you can end up easily in
7:21
transactions you can end up easily in the first year to have around 40 50% of
7:25
the first year to have around 40 50% of
7:25
the first year to have around 40 50% of your
7:27
your
7:27
your consumption uh done only by the secure
7:32
consumption uh done only by the secure
7:32
consumption uh done only by the secure Appliance secure virtual appliances like
7:35
Appliance secure virtual appliances like
7:35
Appliance secure virtual appliances like firewall monitoring tools and so on why
7:39
firewall monitoring tools and so on why
7:39
firewall monitoring tools and so on why because of the pcss and other compliance
7:41
because of the pcss and other compliance
7:41
because of the pcss and other compliance that are requiring you to have that exp
7:44
that are requiring you to have that exp
7:44
that are requiring you to have that exp explicit layer even if you don't need to
7:46
explicit layer even if you don't need to
7:47
explicit layer even if you don't need to follow any kind of compliancy
7:48
follow any kind of compliancy
7:48
follow any kind of compliancy regulations you need to consider that
7:51
regulations you need to consider that
7:51
regulations you need to consider that any kind of secure serves that you're
7:54
any kind of secure serves that you're
7:54
any kind of secure serves that you're adding also might or might not add an an
7:58
adding also might or might not add an an
7:58
adding also might or might not add an an additional cost in most the cases would
8:00
additional cost in most the cases would
8:00
additional cost in most the cases would add but sometimes we have out of the
8:02
add but sometimes we have out of the
8:02
add but sometimes we have out of the share Solutions or features that we need
8:05
share Solutions or features that we need
8:05
share Solutions or features that we need to consider so this is my mission to for
8:09
to consider so this is my mission to for
8:09
to consider so this is my mission to for today to
8:11
today to
8:11
today to see what are the services that we need
8:14
see what are the services that we need
8:14
see what are the services that we need to
8:15
to
8:15
to consider so who who who am I um thank
8:19
consider so who who who am I um thank
8:19
consider so who who who am I um thank you for the short for the short B for
8:23
you for the short for the short B for
8:23
you for the short for the short B for the short presentation in the meantime
8:25
the short presentation in the meantime
8:26
the short presentation in the meantime my hat inside the Dava change I'm now VP
8:28
my hat inside the Dava change I'm now VP
8:28
my hat inside the Dava change I'm now VP of cluct this is not important what is
8:30
of cluct this is not important what is
8:30
of cluct this is not important what is more important here in this context is
8:32
more important here in this context is
8:32
more important here in this context is that I started my journey in Cloud on
8:35
that I started my journey in Cloud on
8:35
that I started my journey in Cloud on Windows Azure as we used to call it in
8:37
Windows Azure as we used to call it in
8:37
Windows Azure as we used to call it in the past in 2009 and starting from then
8:40
the past in 2009 and starting from then
8:40
the past in 2009 and starting from then I think that around 90 95% of my time
8:43
I think that around 90 95% of my time
8:43
I think that around 90 95% of my time was around Cloud around asure and around
8:47
was around Cloud around asure and around
8:47
was around Cloud around asure and around AWS I was involved in different type of
8:49
AWS I was involved in different type of
8:49
AWS I was involved in different type of projects
8:51
projects
8:51
projects and I've done and I saw a lot of
8:55
and I've done and I saw a lot of
8:55
and I've done and I saw a lot of mistakes from which I learn so what I'm
8:58
mistakes from which I learn so what I'm
8:58
mistakes from which I learn so what I'm trying now to do is is to learn from the
9:00
trying now to do is is to learn from the
9:00
trying now to do is is to learn from the past experience and to apply that layer
9:03
past experience and to apply that layer
9:03
past experience and to apply that layer of best practices that uh provide a good
9:08
of best practices that uh provide a good
9:08
of best practices that uh provide a good uh balance between how much you invest
9:10
uh balance between how much you invest
9:10
uh balance between how much you invest and what you get depending on your
9:13
and what you get depending on your
9:13
and what you get depending on your business in the industry that you're
9:14
business in the industry that you're
9:14
business in the industry that you're part of and what you would like to
9:16
part of and what you would like to
9:16
part of and what you would like to achieve and of of course what is
9:20
achieve and of of course what is
9:20
achieve and of of course what is the life cycle and the lifespan of the
9:23
the life cycle and the lifespan of the
9:23
the life cycle and the lifespan of the application that you're
9:27
building I will start with with 2020 and
9:30
building I will start with with 2020 and
9:30
building I will start with with 2020 and why this is very important because in
9:32
why this is very important because in
9:32
why this is very important because in 2020 we saw a high level of migration of
9:39
2020 we saw a high level of migration of
9:39
2020 we saw a high level of migration of application to the cloud there was a
9:42
application to the cloud there was a
9:42
application to the cloud there was a trend that I think that went around one
9:45
trend that I think that went around one
9:45
trend that I think that went around one year one year and a half where everybody
9:47
year one year and a half where everybody
9:47
year one year and a half where everybody was doing clouds everybody was migrating
9:49
was doing clouds everybody was migrating
9:49
was doing clouds everybody was migrating to Cloud it was but everybody was
9:51
to Cloud it was but everybody was
9:51
to Cloud it was but everybody was running to Cloud meaning they were just
9:54
running to Cloud meaning they were just
9:54
running to Cloud meaning they were just investing taking the payloads taking the
9:57
investing taking the payloads taking the
9:57
investing taking the payloads taking the data pushing them to the cloud and
9:59
data pushing them to the cloud and
9:59
data pushing them to the cloud and nothing more than that after that people
10:02
nothing more than that after that people
10:02
nothing more than that after that people expect it or we expected that um people
10:06
expect it or we expected that um people
10:06
expect it or we expected that um people will start to go on the cloud
10:08
will start to go on the cloud
10:08
will start to go on the cloud modernization journey in the cloud
10:11
modernization journey in the cloud
10:11
modernization journey in the cloud acceleration part meaning that okay
10:15
acceleration part meaning that okay
10:15
acceleration part meaning that okay we've done the migration now we need to
10:17
we've done the migration now we need to
10:17
we've done the migration now we need to consolidate it from security from how
10:20
consolidate it from security from how
10:20
consolidate it from security from how you run your workloads and payloads from
10:23
you run your workloads and payloads from
10:23
you run your workloads and payloads from the data point of view and so on but not
10:26
the data point of view and so on but not
10:26
the data point of view and so on but not all the time this happen this is why for
10:28
all the time this happen this is why for
10:28
all the time this happen this is why for example we see in we saw in U in U only
10:31
example we see in we saw in U in U only
10:31
example we see in we saw in U in U only the first year in 2020 an increase of
10:33
the first year in 2020 an increase of
10:33
the first year in 2020 an increase of cyber attacks around 250 and the trend
10:36
cyber attacks around 250 and the trend
10:36
cyber attacks around 250 and the trend went with the same
10:39
went with the same
10:39
went with the same value uh large scale Brees Brees only in
10:43
value uh large scale Brees Brees only in
10:43
value uh large scale Brees Brees only in 2020 increased with around 273 and it's
10:47
2020 increased with around 273 and it's
10:47
2020 increased with around 273 and it's huge and what is more interesting with
10:50
huge and what is more interesting with
10:50
huge and what is more interesting with with people that were working from home
10:52
with people that were working from home
10:52
with people that were working from home around half of
10:54
around half of
10:54
around half of them fall in fishing scams now fishing
10:58
them fall in fishing scams now fishing
10:58
them fall in fishing scams now fishing scam don't think about all the times
10:59
scam don't think about all the times
10:59
scam don't think about all the times related
11:01
related
11:01
related to a fishing
11:03
to a fishing
11:03
to a fishing scam stealing your credit card
11:05
scam stealing your credit card
11:05
scam stealing your credit card information or taking control of your
11:08
information or taking control of your
11:08
information or taking control of your business account and so on fishing
11:10
business account and so on fishing
11:10
business account and so on fishing attack scams also were related to
11:13
attack scams also were related to
11:13
attack scams also were related to joining uh online events when they were
11:16
joining uh online events when they were
11:16
joining uh online events when they were able to steal your name your profile
11:18
able to steal your name your profile
11:18
able to steal your name your profile your email and so on or trapping you in
11:21
your email and so on or trapping you in
11:21
your email and so on or trapping you in different
11:24
different
11:24
different uh websites or systems where they were
11:28
uh websites or systems where they were
11:28
uh websites or systems where they were getting your your data I will not name
11:30
getting your your data I will not name
11:30
getting your your data I will not name but there also were some uh
11:33
but there also were some uh
11:33
but there also were some uh online video platforms where you were
11:37
online video platforms where you were
11:37
online video platforms where you were able to join and to see all the other
11:39
able to join and to see all the other
11:39
able to join and to see all the other that were joining or their Facebook
11:41
that were joining or their Facebook
11:41
that were joining or their Facebook account and so on so there there what
11:44
account and so on so there there what
11:44
account and so on so there there what all of the scams and ways how you could
11:46
all of the scams and ways how you could
11:46
all of the scams and ways how you could collect data building people profiles
11:49
collect data building people profiles
11:49
collect data building people profiles and so on so fishing attacks increased
11:52
and so on so fishing attacks increased
11:52
and so on so fishing attacks increased increased increased up to 3 350 per year
11:57
increased increased up to 3 350 per year
11:57
increased increased up to 3 350 per year and also uh
11:59
and also uh
11:59
and also uh the
12:00
the
12:01
the interest for cloud went up meaning that
12:06
interest for cloud went up meaning that
12:06
interest for cloud went up meaning that only for a paring with around 70% the
12:08
only for a paring with around 70% the
12:08
only for a paring with around 70% the same in in Europe in Japan in Americas
12:13
same in in Europe in Japan in Americas
12:13
same in in Europe in Japan in Americas and also different worklow increase
12:15
and also different worklow increase
12:15
and also different worklow increase drastical especially the retail and the
12:18
drastical especially the retail and the
12:18
drastical especially the retail and the insurance I don't know
12:20
insurance I don't know
12:21
insurance I don't know how is in different uh places in the
12:24
how is in different uh places in the
12:24
how is in different uh places in the world but I would say until 2020 for
12:26
world but I would say until 2020 for
12:26
world but I would say until 2020 for example making an online Insurance to
12:29
example making an online Insurance to
12:30
example making an online Insurance to your car or personal life and so was not
12:32
your car or personal life and so was not
12:32
your car or personal life and so was not so common nowadays everybody's doing
12:35
so common nowadays everybody's doing
12:35
so common nowadays everybody's doing what does this mean a lot of business
12:38
what does this mean a lot of business
12:38
what does this mean a lot of business went to the cloud retails the same thing
12:42
went to the cloud retails the same thing
12:42
went to the cloud retails the same thing maybe you heard in us a lot of retails
12:45
maybe you heard in us a lot of retails
12:45
maybe you heard in us a lot of retails closeth physically because there are not
12:47
closeth physically because there are not
12:47
closeth physically because there are not so many people that are going to store
12:50
so many people that are going to store
12:50
so many people that are going to store any any anymore and so
12:54
any any anymore and so
12:54
any any anymore and so on and just in two or three months
12:57
on and just in two or three months
12:57
on and just in two or three months around half of people half people were
12:59
around half of people half people were
12:59
around half of people half people were already uh affected by breaches that I
13:03
already uh affected by breaches that I
13:03
already uh affected by breaches that I was giving you an example video
13:05
was giving you an example video
13:05
was giving you an example video conferences where people were storing
13:08
conferences where people were storing
13:08
conferences where people were storing the data
13:10
the data
13:10
the data so what is my mission to today and why I
13:13
so what is my mission to today and why I
13:13
so what is my mission to today and why I went back to 2020 I went back to 2020
13:16
went back to 2020 I went back to 2020
13:16
went back to 2020 I went back to 2020 because 2020 was a trigger was the
13:20
because 2020 was a trigger was the
13:20
because 2020 was a trigger was the moment in time when Cloud adoption had a
13:25
moment in time when Cloud adoption had a
13:25
moment in time when Cloud adoption had a big spike a good one a bad one I don't
13:29
big spike a good one a bad one I don't
13:29
big spike a good one a bad one I don't know but that Spike triggered that a lot
13:32
know but that Spike triggered that a lot
13:32
know but that Spike triggered that a lot of systems end up somewhere in the cloud
13:36
of systems end up somewhere in the cloud
13:36
of systems end up somewhere in the cloud many time running and build in the same
13:39
many time running and build in the same
13:40
many time running and build in the same way as on on Prem not only from the
13:42
way as on on Prem not only from the
13:42
way as on on Prem not only from the payloads and from the data and storage
13:44
payloads and from the data and storage
13:44
payloads and from the data and storage point of view but also the way how
13:47
point of view but also the way how
13:47
point of view but also the way how security is designed manage and
13:52
front cloud and on Prem you might say
13:55
front cloud and on Prem you might say
13:55
front cloud and on Prem you might say that they're similar and yes they have
13:57
that they're similar and yes they have
13:57
that they're similar and yes they have the same Concepts
13:59
the same Concepts
13:59
the same Concepts nevertheless they're a little bit
14:01
nevertheless they're a little bit
14:01
nevertheless they're a little bit different because there are different
14:02
different because there are different
14:02
different because there are different aspects that you need to
14:04
aspects that you need to
14:04
aspects that you need to consider some of them are virtual some
14:07
consider some of them are virtual some
14:07
consider some of them are virtual some of them are the one you don't need to
14:11
of them are the one you don't need to
14:11
of them are the one you don't need to manage on on on PR and you know and you
14:14
manage on on on PR and you know and you
14:14
manage on on on PR and you know and you need to know
14:15
need to know
14:15
need to know exactly how you can tackle them so this
14:18
exactly how you can tackle them so this
14:18
exactly how you can tackle them so this is my mission take 10 different
14:22
is my mission take 10 different
14:22
is my mission take 10 different dimensions of security of application in
14:25
dimensions of security of application in
14:25
dimensions of security of application in the cloud and try to cover them in the
14:28
the cloud and try to cover them in the
14:28
the cloud and try to cover them in the next
14:31
40 35 40
14:34
40 35 40
14:34
40 35 40 minutes so nothing more than that we
14:38
minutes so nothing more than that we
14:38
minutes so nothing more than that we just take one by one and go with
14:40
just take one by one and go with
14:40
just take one by one and go with different examples and so on I will try
14:42
different examples and so on I will try
14:42
different examples and so on I will try to emphasize in for each aspects the one
14:46
to emphasize in for each aspects the one
14:46
to emphasize in for each aspects the one that I I'm considering more relevant for
14:50
that I I'm considering more relevant for
14:50
that I I'm considering more relevant for us now we are not yet at the final
14:53
us now we are not yet at the final
14:53
us now we are not yet at the final thoughts this is will be for for a for a
14:56
thoughts this is will be for for a for a
14:56
thoughts this is will be for for a for a little bit uh at the end so let's start
14:59
little bit uh at the end so let's start
14:59
little bit uh at the end so let's start with the first one identity and access
15:02
with the first one identity and access
15:02
with the first one identity and access management when I'm saying identity and
15:04
management when I'm saying identity and
15:04
management when I'm saying identity and access management I'm I'm considering
15:07
access management I'm I'm considering
15:07
access management I'm I'm considering this more than um how users are
15:11
this more than um how users are
15:11
this more than um how users are accessing their application yeah this is
15:13
accessing their application yeah this is
15:13
accessing their application yeah this is one part but I want ensure that the
15:16
one part but I want ensure that the
15:16
one part but I want ensure that the current audience that we have here you
15:18
current audience that we have here you
15:18
current audience that we have here you might be developers devops testers
15:22
might be developers devops testers
15:22
might be developers devops testers infrastructure data data science
15:24
infrastructure data data science
15:24
infrastructure data data science engineers and so on and what is one of
15:27
engineers and so on and what is one of
15:27
engineers and so on and what is one of the trends that I see on the market if
15:29
the trends that I see on the market if
15:29
the trends that I see on the market if you're working for a company let's say
15:30
you're working for a company let's say
15:30
you're working for a company let's say for 10 years and you're moving from one
15:32
for 10 years and you're moving from one
15:33
for 10 years and you're moving from one project to another you're working for
15:34
project to another you're working for
15:34
project to another you're working for the same customer let's say for five
15:37
the same customer let's say for five
15:37
the same customer let's say for five years you might request access to a
15:39
years you might request access to a
15:39
years you might request access to a pre-production environment maybe you're
15:41
pre-production environment maybe you're
15:41
pre-production environment maybe you're doing level three support for even for
15:44
doing level three support for even for
15:44
doing level three support for even for production environment and you're
15:45
production environment and you're
15:45
production environment and you're getting access to different system to
15:47
getting access to different system to
15:47
getting access to different system to different parts of the systems of
15:50
different parts of the systems of
15:50
different parts of the systems of different application and so on and the
15:53
different application and so on and the
15:53
different application and so on and the truth is that I I'm not now we are not
15:56
truth is that I I'm not now we are not
15:56
truth is that I I'm not now we are not in a physical room to say raise your
15:58
in a physical room to say raise your
15:58
in a physical room to say raise your hand but I'm than sure that many of you
16:00
hand but I'm than sure that many of you
16:00
hand but I'm than sure that many of you you have full
16:02
you have full
16:02
you have full access uh to some production parts of
16:06
access uh to some production parts of
16:06
access uh to some production parts of the systems or you got access a few
16:09
the systems or you got access a few
16:09
the systems or you got access a few months or years ago and you can still
16:11
months or years ago and you can still
16:11
months or years ago and you can still have access to the systems even you
16:14
have access to the systems even you
16:14
have access to the systems even you shouldn't have access to it anymore and
16:18
shouldn't have access to it anymore and
16:18
shouldn't have access to it anymore and everything is reduced in a simple way to
16:21
everything is reduced in a simple way to
16:21
everything is reduced in a simple way to access Ro based access control and I
16:24
access Ro based access control and I
16:24
access Ro based access control and I want to highlight especially the one
16:25
want to highlight especially the one
16:25
want to highlight especially the one that is from Microsoft on uh entra ID
16:30
that is from Microsoft on uh entra ID
16:30
that is from Microsoft on uh entra ID socalled Azure ID we have three three
16:33
socalled Azure ID we have three three
16:33
socalled Azure ID we have three three main components we need to consider
16:35
main components we need to consider
16:35
main components we need to consider security principle roles and scope what
16:40
security principle roles and scope what
16:40
security principle roles and scope what is the security principle security
16:43
is the security principle security
16:43
is the security principle security principle is who has access and we're
16:46
principle is who has access and we're
16:46
principle is who has access and we're not talking about only users uh we can
16:49
not talking about only users uh we can
16:49
not talking about only users uh we can have a security principle a service
16:51
have a security principle a service
16:51
have a security principle a service principle and that can be for example an
16:55
principle and that can be for example an
16:55
principle and that can be for example an Azure function or a job
16:59
Azure function or a job
16:59
Azure function or a job and that can be
17:01
and that can be
17:01
and that can be identified by aure and that sure that he
17:04
identified by aure and that sure that he
17:04
identified by aure and that sure that he has a specific role let's say a role of
17:09
has a specific role let's say a role of
17:09
has a specific role let's say a role of um he he can have a a role of read read
17:13
um he he can have a a role of read read
17:13
um he he can have a a role of read read read and write and so on in know to a
17:16
read and write and so on in know to a
17:16
read and write and so on in know to a specific scope can be a storage can be
17:18
specific scope can be a storage can be
17:18
specific scope can be a storage can be Cosmos VP can be anything what is here
17:22
Cosmos VP can be anything what is here
17:22
Cosmos VP can be anything what is here important to keep in mind that you don't
17:25
important to keep in mind that you don't
17:25
important to keep in mind that you don't need to manage uh the tokens access keys
17:30
need to manage uh the tokens access keys
17:30
need to manage uh the tokens access keys and like that when you're working with
17:32
and like that when you're working with
17:32
and like that when you're working with aure Services you you can rely on manage
17:36
aure Services you you can rely on manage
17:36
aure Services you you can rely on manage identities and on service principle to
17:38
identities and on service principle to
17:38
identities and on service principle to ensure that another service can access
17:41
ensure that another service can access
17:41
ensure that another service can access can have the right access role to a stor
17:44
can have the right access role to a stor
17:44
can have the right access role to a stor to a database or to any other
17:50
resource what we need to consider and
17:53
resource what we need to consider and
17:53
resource what we need to consider and this is very very important is that
17:55
this is very very important is that
17:55
this is very very important is that except what kind of passwords we are
17:57
except what kind of passwords we are
17:57
except what kind of passwords we are using to use single sign on and
18:00
using to use single sign on and
18:00
using to use single sign on and multifactor is to think about how you're
18:02
multifactor is to think about how you're
18:02
multifactor is to think about how you're building the application who has access
18:04
building the application who has access
18:04
building the application who has access to what one are the customers on the
18:07
to what one are the customers on the
18:07
to what one are the customers on the other side is the technical team and
18:10
other side is the technical team and
18:10
other side is the technical team and when I'm talking about the technical
18:11
when I'm talking about the technical
18:11
when I'm talking about the technical team you need to ensure that you provide
18:15
team you need to ensure that you provide
18:15
team you need to ensure that you provide the least prev access and this is
18:17
the least prev access and this is
18:17
the least prev access and this is something that is very hard to
18:19
something that is very hard to
18:19
something that is very hard to implement because to be able to have an
18:22
implement because to be able to have an
18:22
implement because to be able to have an endtoend solution where you say for
18:24
endtoend solution where you say for
18:24
endtoend solution where you say for example devops have access to the
18:27
example devops have access to the
18:27
example devops have access to the pipeline can modify by the pipeline can
18:31
pipeline can modify by the pipeline can
18:31
pipeline can modify by the pipeline can um trigger maybe with some gate uh roll
18:37
um trigger maybe with some gate uh roll
18:37
um trigger maybe with some gate uh roll out in pre-production in production
18:39
out in pre-production in production
18:39
out in pre-production in production environments they don't have access to
18:41
environments they don't have access to
18:41
environments they don't have access to that environment to that databases there
18:44
that environment to that databases there
18:44
that environment to that databases there something that you need to consider
18:46
something that you need to consider
18:46
something that you need to consider another thing is that when somebody has
18:49
another thing is that when somebody has
18:49
another thing is that when somebody has access to the portal to the Azure
18:52
access to the portal to the Azure
18:52
access to the portal to the Azure portal and for example they have access
18:54
portal and for example they have access
18:54
portal and for example they have access to do some configurations maybe even in
18:57
to do some configurations maybe even in
18:57
to do some configurations maybe even in pre-production or testing or other
19:00
pre-production or testing or other
19:00
pre-production or testing or other environment you might need to ensure
19:02
environment you might need to ensure
19:02
environment you might need to ensure that they cannot
19:04
that they cannot
19:04
that they cannot access the data the storage so playing
19:08
access the data the storage so playing
19:08
access the data the storage so playing with this role based access control with
19:10
with this role based access control with
19:10
with this role based access control with the groups and so on even if you might
19:12
the groups and so on even if you might
19:12
the groups and so on even if you might say oh it's easy when you put everything
19:15
say oh it's easy when you put everything
19:15
say oh it's easy when you put everything in place it's a challenge because you
19:17
in place it's a challenge because you
19:17
in place it's a challenge because you need to consider all all the flows and
19:20
need to consider all all the flows and
19:20
need to consider all all the flows and when new cases pop ups you need to see
19:22
when new cases pop ups you need to see
19:22
when new cases pop ups you need to see okay how I can cover them what is the
19:25
okay how I can cover them what is the
19:25
okay how I can cover them what is the best way to cover them
19:30
best way to cover them
19:30
best way to cover them the second topic that uh I would like to
19:32
the second topic that uh I would like to
19:32
the second topic that uh I would like to cover is about data Pro uh protection
19:35
cover is about data Pro uh protection
19:35
cover is about data Pro uh protection and now with the data protection you all
19:37
and now with the data protection you all
19:37
and now with the data protection you all we already know about encryption about
19:40
we already know about encryption about
19:40
we already know about encryption about the key and so on but now I will say
19:44
the key and so on but now I will say
19:44
the key and so on but now I will say that the biggest challenge when we say
19:46
that the biggest challenge when we say
19:46
that the biggest challenge when we say data protection is when we put AI on top
19:49
data protection is when we put AI on top
19:49
data protection is when we put AI on top of it because until now for example we
19:53
of it because until now for example we
19:53
of it because until now for example we had our
19:56
had our
19:56
had our applications in different um
19:59
applications in different um
19:59
applications in different um uh running in different maybe
20:00
uh running in different maybe
20:00
uh running in different maybe subscriptions or resour group for each
20:03
subscriptions or resour group for each
20:03
subscriptions or resour group for each subsystems and now with the AI you need
20:05
subsystems and now with the AI you need
20:05
subsystems and now with the AI you need to maybe to consolidate them in inside a
20:10
to maybe to consolidate them in inside a
20:10
to maybe to consolidate them in inside a large L like Microsoft like Microsoft
20:13
large L like Microsoft like Microsoft
20:13
large L like Microsoft like Microsoft fabric but on top of that you need now
20:16
fabric but on top of that you need now
20:16
fabric but on top of that you need now to provide access to a system like let's
20:19
to provide access to a system like let's
20:19
to provide access to a system like let's say open
20:20
say open
20:20
say open Ai and now the challenge is how you
20:23
Ai and now the challenge is how you
20:23
Ai and now the challenge is how you protect this data because you need to do
20:25
protect this data because you need to do
20:25
protect this data because you need to do the labeling you need to have that
20:28
the labeling you need to have that
20:28
the labeling you need to have that catalog and you need to ensure that the
20:31
catalog and you need to ensure that the
20:31
catalog and you need to ensure that the person or the system that is on the
20:34
person or the system that is on the
20:34
person or the system that is on the other side and is accessing through that
20:37
other side and is accessing through that
20:37
other side and is accessing through that AI solution maybe through a chat or
20:40
AI solution maybe through a chat or
20:40
AI solution maybe through a chat or through through a boat and like that the
20:42
through through a boat and like that the
20:42
through through a boat and like that the data has the right access to be able to
20:45
data has the right access to be able to
20:45
data has the right access to be able to see the to see the data to access them
20:48
see the to see the data to access them
20:48
see the to see the data to access them and so on how you're doing this there
20:50
and so on how you're doing this there
20:50
and so on how you're doing this there are some mechanis but in the end you
20:53
are some mechanis but in the end you
20:53
are some mechanis but in the end you need to have the labeling you have you
20:55
need to have the labeling you have you
20:55
need to have the labeling you have you need to have the groups and you need to
20:56
need to have the groups and you need to
20:57
need to have the groups and you need to ensure that for example only people
20:59
ensure that for example only people
20:59
ensure that for example only people maybe from the financial from the legal
21:02
maybe from the financial from the legal
21:02
maybe from the financial from the legal and from the sales can have access for
21:05
and from the sales can have access for
21:05
and from the sales can have access for example to information related to the
21:07
example to information related to the
21:07
example to information related to the opportunities related to The Grow margin
21:10
opportunities related to The Grow margin
21:10
opportunities related to The Grow margin and so on and the rest of the uh people
21:13
and so on and the rest of the uh people
21:13
and so on and the rest of the uh people that are part of the company don't have
21:15
that are part of the company don't have
21:15
that are part of the company don't have access to this kind of
21:19
access to this kind of
21:19
access to this kind of information another component that uh is
21:23
information another component that uh is
21:23
information another component that uh is very important is about how you mon how
21:26
very important is about how you mon how
21:26
very important is about how you mon how you do the monitoring
21:29
you do the monitoring
21:29
you do the monitoring and how you and how you react to it and
21:32
and how you and how you react to it and
21:32
and how you and how you react to it and let's start with the monitoring part
21:35
let's start with the monitoring part
21:35
let's start with the monitoring part there are lot of services uh some of
21:38
there are lot of services uh some of
21:38
there are lot of services uh some of them that I really enjoy is azure
21:41
them that I really enjoy is azure
21:41
them that I really enjoy is azure Sentinel and uh Def and
21:44
Sentinel and uh Def and
21:44
Sentinel and uh Def and Defender these two combined with Azure
21:47
Defender these two combined with Azure
21:47
Defender these two combined with Azure monitoring and application in size are
21:49
monitoring and application in size are
21:49
monitoring and application in size are great it gives you the ability more or
21:52
great it gives you the ability more or
21:52
great it gives you the ability more or less to be in
21:55
less to be in
21:55
less to be in a let's say
21:58
a let's say
21:58
a let's say event driven monitoring mechanism where
22:02
event driven monitoring mechanism where
22:02
event driven monitoring mechanism where you have events that can trigger
22:04
you have events that can trigger
22:04
you have events that can trigger different
22:05
different
22:05
different alerts and depends what you're doing
22:08
alerts and depends what you're doing
22:08
alerts and depends what you're doing with that alert and why I'm saying this
22:12
with that alert and why I'm saying this
22:12
with that alert and why I'm saying this because I saw I see a lot of solutions
22:15
because I saw I see a lot of solutions
22:15
because I saw I see a lot of solutions where yeah we are putting alerts for a b
22:17
where yeah we are putting alerts for a b
22:18
where yeah we are putting alerts for a b c d and so on and what you're doing when
22:21
c d and so on and what you're doing when
22:21
c d and so on and what you're doing when an alert is trigger oh we're sending an
22:25
an alert is trigger oh we're sending an
22:25
an alert is trigger oh we're sending an email okay and uh uh what does that
22:29
email okay and uh uh what does that
22:30
email okay and uh uh what does that person is doing when he see that alert
22:33
person is doing when he see that alert
22:33
person is doing when he see that alert oh he will go in the console he will
22:35
oh he will go in the console he will
22:35
oh he will go in the console he will verify and so on okay this is great
22:39
verify and so on okay this is great
22:39
verify and so on okay this is great after a few months in
22:42
after a few months in
22:42
after a few months in production we are we are looking what
22:44
production we are we are looking what
22:44
production we are we are looking what happened in the last three months and
22:47
happened in the last three months and
22:47
happened in the last three months and what we found out well we had an
22:49
what we found out well we had an
22:49
what we found out well we had an alert on possible bridge that was
22:53
alert on possible bridge that was
22:53
alert on possible bridge that was triggered for 100 times in the last
22:56
triggered for 100 times in the last
22:56
triggered for 100 times in the last three months okay and what you've done
22:59
three months okay and what you've done
22:59
three months okay and what you've done well for the first four or five times
23:01
well for the first four or five times
23:01
well for the first four or five times we've done an investigation we saw that
23:04
we've done an investigation we saw that
23:04
we've done an investigation we saw that is a false
23:07
positive um trigger and we done done
23:10
positive um trigger and we done done
23:10
positive um trigger and we done done nothing okay
23:12
nothing okay
23:12
nothing okay good and the rest of
23:16
good and the rest of
23:16
good and the rest of 95 was on that were on the same time
23:20
95 was on that were on the same time
23:20
95 was on that were on the same time well we didn't done anything because
23:22
well we didn't done anything because
23:22
well we didn't done anything because there were some Force positive meaning
23:24
there were some Force positive meaning
23:24
there were some Force positive meaning that you need
23:26
that you need
23:26
that you need to uh adjust the system all the time and
23:31
to uh adjust the system all the time and
23:31
to uh adjust the system all the time and also you need to consider to connect to
23:37
also you need to consider to connect to
23:37
also you need to consider to connect to some I say this phas
23:41
some I say this phas
23:41
some I say this phas automatically uh triggers that could for
23:44
automatically uh triggers that could for
23:44
automatically uh triggers that could for example trigger an action that would
23:47
example trigger an action that would
23:47
example trigger an action that would block automatically an IP or limit
23:50
block automatically an IP or limit
23:50
block automatically an IP or limit access to a specific storage or access
23:52
access to a specific storage or access
23:52
access to a specific storage or access of of a a user and so
23:55
of of a a user and so
23:55
of of a a user and so on uh what now appear on the market and
23:59
on uh what now appear on the market and
23:59
on uh what now appear on the market and we need to keep an eye on that because
24:00
we need to keep an eye on that because
24:00
we need to keep an eye on that because there are more and more solutions
24:02
there are more and more solutions
24:02
there are more and more solutions regarding that part is to combine this
24:06
regarding that part is to combine this
24:06
regarding that part is to combine this stream of events that are happening in
24:09
stream of events that are happening in
24:09
stream of events that are happening in the audit in the logs basically more or
24:12
the audit in the logs basically more or
24:12
the audit in the logs basically more or less the monitoring part with AI
24:14
less the monitoring part with AI
24:14
less the monitoring part with AI solution that can react automatically
24:17
solution that can react automatically
24:17
solution that can react automatically and take
24:18
and take
24:18
and take actions meaning that you have a system
24:23
actions meaning that you have a system
24:23
actions meaning that you have a system that can react dynamically
24:28
to what is happening to understand what
24:31
to what is happening to understand what
24:31
to what is happening to understand what is the user be Behavior what is the
24:34
is the user be Behavior what is the
24:34
is the user be Behavior what is the normal user behavior when when a
24:36
normal user behavior when when a
24:36
normal user behavior when when a behavior for user
24:39
behavior for user
24:39
behavior for user change and the action that he would need
24:42
change and the action that he would need
24:42
change and the action that he would need to do what I'm saying by a be behavior
24:45
to do what I'm saying by a be behavior
24:45
to do what I'm saying by a be behavior let's say that you have some
24:48
let's say that you have some
24:48
let's say that you have some U uh systems a third party system that
24:51
U uh systems a third party system that
24:51
U uh systems a third party system that usually access five or six uh apis that
24:56
usually access five or six uh apis that
24:56
usually access five or six uh apis that you are exposing this is happening for
25:00
you are exposing this is happening for
25:00
you are exposing this is happening for one year and after that you notify that
25:03
one year and after that you notify that
25:03
one year and after that you notify that that see the third party is starting
25:05
that see the third party is starting
25:05
that see the third party is starting also to look for other apis trying to
25:08
also to look for other apis trying to
25:08
also to look for other apis trying to access them uh trying to fetch other
25:11
access them uh trying to fetch other
25:11
access them uh trying to fetch other kind of data that he used to uh fetch
25:14
kind of data that he used to uh fetch
25:14
kind of data that he used to uh fetch until now that is a trigger that is
25:16
until now that is a trigger that is
25:16
until now that is a trigger that is changing the
25:18
changing the
25:18
changing the behavior of the third party and maybe
25:21
behavior of the third party and maybe
25:21
behavior of the third party and maybe you need to re maybe you would need to
25:24
you need to re maybe you would need to
25:24
you need to re maybe you would need to shut down access for a temporary Peri
25:27
shut down access for a temporary Peri
25:27
shut down access for a temporary Peri period of time or just
25:30
period of time or just
25:30
period of time or just to notify the support team to validate
25:34
to notify the support team to validate
25:34
to notify the support team to validate if the behavior is the expected one or
25:37
if the behavior is the expected one or
25:37
if the behavior is the expected one or something
25:38
something
25:38
something happen behind the
25:41
happen behind the
25:41
happen behind the scene now going a little bit close to
25:44
scene now going a little bit close to
25:44
scene now going a little bit close to the development side we have so-called
25:46
the development side we have so-called
25:47
the development side we have so-called secure code development where we do
25:48
secure code development where we do
25:48
secure code development where we do performance static code analy we
25:50
performance static code analy we
25:50
performance static code analy we incorporate Security checks in the
25:52
incorporate Security checks in the
25:52
incorporate Security checks in the pipeline and we scan third party
25:54
pipeline and we scan third party
25:54
pipeline and we scan third party dependent for vulnerabilities there a
25:56
dependent for vulnerabilities there a
25:56
dependent for vulnerabilities there a lot of things that we can do in this
25:58
lot of things that we can do in this
25:58
lot of things that we can do in this space and there's a lot of Solutions on
26:01
space and there's a lot of Solutions on
26:01
space and there's a lot of Solutions on the on the market uh it is very common
26:05
the on the market uh it is very common
26:05
the on the market uh it is very common or used to be very common noways is not
26:07
or used to be very common noways is not
26:07
or used to be very common noways is not so common anymore and that's a very good
26:10
so common anymore and that's a very good
26:10
so common anymore and that's a very good thing that people are pushing to the
26:12
thing that people are pushing to the
26:12
thing that people are pushing to the repo to the public repo
26:15
repo to the public repo
26:15
repo to the public repo especially um secrets
26:20
especially um secrets
26:20
especially um secrets from accessing uh the cloud
26:23
from accessing uh the cloud
26:23
from accessing uh the cloud infrastructure like access to storage
26:25
infrastructure like access to storage
26:25
infrastructure like access to storage access to
26:26
access to
26:26
access to database uh and so on there are
26:29
database uh and so on there are
26:29
database uh and so on there are different tools on on the market that
26:31
different tools on on the market that
26:31
different tools on on the market that give you uh give you the ability for
26:33
give you uh give you the ability for
26:33
give you uh give you the ability for example like get Secrets uh to scan
26:35
example like get Secrets uh to scan
26:35
example like get Secrets uh to scan automatically your repo to identify if
26:38
automatically your repo to identify if
26:38
automatically your repo to identify if some casys uh were Ed some secrets and
26:42
some casys uh were Ed some secrets and
26:43
some casys uh were Ed some secrets and then even to
26:45
then even to
26:45
then even to block uh uh to block that uh to block
26:50
block uh uh to block that uh to block
26:50
block uh uh to block that uh to block that push I I I saw some interesting
26:53
that push I I I saw some interesting
26:53
that push I I I saw some interesting Implement implementation that I really
26:55
Implement implementation that I really
26:55
Implement implementation that I really like if for example in the time span of
26:57
like if for example in the time span of
26:57
like if for example in the time span of one week a technical person person is
27:00
one week a technical person person is
27:00
one week a technical person person is doing free push where he has secrets
27:02
doing free push where he has secrets
27:02
doing free push where he has secrets that he's trying to push automatically
27:05
that he's trying to push automatically
27:05
that he's trying to push automatically his account is
27:06
his account is
27:06
his account is suspended and then he needs to go to the
27:08
suspended and then he needs to go to the
27:09
suspended and then he needs to go to the it request to his account to be unlocked
27:12
it request to his account to be unlocked
27:12
it request to his account to be unlocked and so on so we you can play a little
27:15
and so on so we you can play a little
27:15
and so on so we you can play a little bit uh with it secret scanning uh for
27:19
bit uh with it secret scanning uh for
27:19
bit uh with it secret scanning uh for example using
27:24
uh um using G secret is a pretty nice
27:27
uh um using G secret is a pretty nice
27:27
uh um using G secret is a pretty nice tool it's very useful another one I know
27:31
tool it's very useful another one I know
27:31
tool it's very useful another one I know that was retired but I really enjoy it
27:33
that was retired but I really enjoy it
27:33
that was retired but I really enjoy it this why I like to mention is the kit
27:36
this why I like to mention is the kit
27:36
this why I like to mention is the kit scan it for me it was
27:41
scan it for me it was
27:41
scan it for me it was pretty nice how you could integrate it
27:44
pretty nice how you could integrate it
27:44
pretty nice how you could integrate it especially when you had to run a PC or a
27:48
especially when you had to run a PC or a
27:48
especially when you had to run a PC or a demo or things like
27:52
demo or things like
27:52
demo or things like that
27:54
that
27:54
that now from the S point of view if you take
27:57
now from the S point of view if you take
27:57
now from the S point of view if you take a look from the number of secets for a
28:00
a look from the number of secets for a
28:00
a look from the number of secets for a single owner that you have it's pretty
28:02
single owner that you have it's pretty
28:02
single owner that you have it's pretty crazy if you take a look on how many of
28:05
crazy if you take a look on how many of
28:05
crazy if you take a look on how many of them were publish in which type but in
28:09
them were publish in which type but in
28:09
them were publish in which type but in the end a lot of people are publishing
28:11
the end a lot of people are publishing
28:11
the end a lot of people are publishing the keys are using the keys and we need
28:13
the keys are using the keys and we need
28:13
the keys are using the keys and we need all the time to manage them this is why
28:17
all the time to manage them this is why
28:17
all the time to manage them this is why at the beginning I talk about role based
28:19
at the beginning I talk about role based
28:19
at the beginning I talk about role based access control because the there lot of
28:22
access control because the there lot of
28:22
access control because the there lot of situations when you don't need this Keys
28:26
situations when you don't need this Keys
28:27
situations when you don't need this Keys If you example for example if you for
28:29
If you example for example if you for
28:29
If you example for example if you for example are using only one Cloud vendor
28:32
example are using only one Cloud vendor
28:32
example are using only one Cloud vendor like
28:33
like
28:33
like aure uh except cases when you use third
28:38
aure uh except cases when you use third
28:38
aure uh except cases when you use third parties for for example an uh when I say
28:42
parties for for example an uh when I say
28:42
parties for for example an uh when I say third parties can be another system that
28:45
third parties can be another system that
28:45
third parties can be another system that is not hosted by you in most of the
28:48
is not hosted by you in most of the
28:48
is not hosted by you in most of the cases you can rely on Ro based access
28:50
cases you can rely on Ro based access
28:50
cases you can rely on Ro based access controls and service principles to do
28:53
controls and service principles to do
28:53
controls and service principles to do the authentification to do the ACC
28:58
the authentification to do the ACC
28:58
the authentification to do the ACC control without using any kind of token
29:02
control without using any kind of token
29:02
control without using any kind of token secret even certifications yes sometimes
29:06
secret even certifications yes sometimes
29:06
secret even certifications yes sometimes we need to use certifications sometimes
29:08
we need to use certifications sometimes
29:08
we need to use certifications sometimes we need to to use tokens and that kind
29:11
we need to to use tokens and that kind
29:11
we need to to use tokens and that kind in that kind of situations we need not
29:13
in that kind of situations we need not
29:13
in that kind of situations we need not only to ensure that we have a solution
29:15
only to ensure that we have a solution
29:15
only to ensure that we have a solution like key or any other volt solution but
29:19
like key or any other volt solution but
29:19
like key or any other volt solution but also we need to ensure that we don't
29:22
also we need to ensure that we don't
29:22
also we need to ensure that we don't store the
29:23
store the
29:24
store the secret in configuration in this location
29:27
secret in configuration in this location
29:27
secret in configuration in this location even if the encrypted because you don't
29:29
even if the encrypted because you don't
29:29
even if the encrypted because you don't know exactly who get access to what and
29:33
know exactly who get access to what and
29:33
know exactly who get access to what and which uh machine is compromised because
29:37
which uh machine is compromised because
29:37
which uh machine is compromised because somebody could put a hand on the
29:40
somebody could put a hand on the
29:40
somebody could put a hand on the configuration file would say oh it's not
29:41
configuration file would say oh it's not
29:41
configuration file would say oh it's not a problem we have everything
29:43
a problem we have everything
29:43
a problem we have everything encrypted and also you might end up with
29:46
encrypted and also you might end up with
29:46
encrypted and also you might end up with a node with a let's say with an Azure VM
29:51
a node with a let's say with an Azure VM
29:51
a node with a let's say with an Azure VM that is also compromise or even a
29:54
that is also compromise or even a
29:54
that is also compromise or even a machine from somebody from the technical
29:57
machine from somebody from the technical
29:57
machine from somebody from the technical team that might have the keys that would
30:00
team that might have the keys that would
30:00
team that might have the keys that would allow that person to access that
30:08
Secrets I would like also to talk more
30:10
Secrets I would like also to talk more
30:10
Secrets I would like also to talk more about what other tools we have when we
30:13
about what other tools we have when we
30:13
about what other tools we have when we talk about secret scanning we for
30:15
talk about secret scanning we for
30:15
talk about secret scanning we for example we have Kit leaks spectral Ops
30:17
example we have Kit leaks spectral Ops
30:17
example we have Kit leaks spectral Ops uh scan kol Secrets I I want to
30:22
uh scan kol Secrets I I want to
30:22
uh scan kol Secrets I I want to highlight uh some of them that I really
30:26
highlight uh some of them that I really
30:26
highlight uh some of them that I really find them pretty pretty nice G secrets
30:28
find them pretty pretty nice G secrets
30:28
find them pretty pretty nice G secrets it's very nice to use I would say that
30:31
it's very nice to use I would say that
30:31
it's very nice to use I would say that for a short PC or when somebody's
30:34
for a short PC or when somebody's
30:34
for a short PC or when somebody's learning G secrets it's super super cool
30:38
learning G secrets it's super super cool
30:38
learning G secrets it's super super cool spe spectral Ops is another tool that I
30:41
spe spectral Ops is another tool that I
30:41
spe spectral Ops is another tool that I really like from the UI point of view
30:43
really like from the UI point of view
30:43
really like from the UI point of view because it generat some nice UI
30:46
because it generat some nice UI
30:46
because it generat some nice UI interfaces that can be easily show to
30:49
interfaces that can be easily show to
30:49
interfaces that can be easily show to somebody like a PM or delivery manager
30:52
somebody like a PM or delivery manager
30:52
somebody like a PM or delivery manager or somebody from the board to understand
30:55
or somebody from the board to understand
30:55
or somebody from the board to understand what is happening
30:58
what is happening
30:58
what is happening behind this behind this behind the
31:05
scene uh
31:07
scene uh
31:07
scene uh GTI it's a pretty nice tool for example
31:10
GTI it's a pretty nice tool for example
31:10
GTI it's a pretty nice tool for example for a fast PC so G secrets with GTI goes
31:13
for a fast PC so G secrets with GTI goes
31:13
for a fast PC so G secrets with GTI goes very well very well when you are in the
31:16
very well very well when you are in the
31:16
very well very well when you are in the moment in time when you want to have a
31:18
moment in time when you want to have a
31:18
moment in time when you want to have a PC just to show to the customer just to
31:21
PC just to show to the customer just to
31:21
PC just to show to the customer just to just to show to the to the stakehold uh
31:25
just to show to the to the stakehold uh
31:25
just to show to the to the stakehold uh stakeholder what is uh what is the value
31:28
stakeholder what is uh what is the value
31:28
stakeholder what is uh what is the value what is the the extra value that you can
31:33
what is the the extra value that you can
31:33
what is the the extra value that you can add now a small comparison between some
31:38
add now a small comparison between some
31:38
add now a small comparison between some some of
31:40
some of
31:40
some of them uh if you have if you want to have
31:42
them uh if you have if you want to have
31:42
them uh if you have if you want to have the full control and you don't need too
31:45
the full control and you don't need too
31:45
the full control and you don't need too much UI I would say that git lcks can be
31:50
much UI I would say that git lcks can be
31:50
much UI I would say that git lcks can be a pretty nice way how you could use
31:55
it uh GTO it's nice but it's still it's
32:00
it uh GTO it's nice but it's still it's
32:00
it uh GTO it's nice but it's still it's in MVP
32:02
in MVP
32:02
in MVP stage SP Ops is the one that I really
32:05
stage SP Ops is the one that I really
32:05
stage SP Ops is the one that I really enjoy very very complex but it's not
32:07
enjoy very very complex but it's not
32:07
enjoy very very complex but it's not free and you have an an initial learning
32:12
free and you have an an initial learning
32:12
free and you have an an initial learning curve that you need to
32:16
accept now going forward let's talk
32:19
accept now going forward let's talk
32:19
accept now going forward let's talk about network
32:21
about network
32:21
about network security uh we already know about this
32:25
security uh we already know about this
32:25
security uh we already know about this Three core components vets network
32:29
Three core components vets network
32:29
Three core components vets network security group and application gway that
32:32
security group and application gway that
32:32
security group and application gway that is coming of course with wa with web
32:35
is coming of course with wa with web
32:35
is coming of course with wa with web application
32:37
application
32:37
application firewall I think that with the first two
32:40
firewall I think that with the first two
32:40
firewall I think that with the first two they're pretty easy vet most of the
32:42
they're pretty easy vet most of the
32:42
they're pretty easy vet most of the people nowadays we are using network
32:45
people nowadays we are using network
32:45
people nowadays we are using network security group oh I see a very good
32:48
security group oh I see a very good
32:48
security group oh I see a very good adoption
32:49
adoption
32:49
adoption level on the application Gateway side
32:52
level on the application Gateway side
32:52
level on the application Gateway side there are some challenges especially
32:53
there are some challenges especially
32:53
there are some challenges especially when we're talking talking with w and
32:56
when we're talking talking with w and
32:56
when we're talking talking with w and why because in most of the case is about
32:58
why because in most of the case is about
32:58
why because in most of the case is about the cost and many times people are
33:01
the cost and many times people are
33:01
the cost and many times people are forgetting to consider what are the
33:03
forgetting to consider what are the
33:03
forgetting to consider what are the direct benefits because when for example
33:07
direct benefits because when for example
33:07
direct benefits because when for example you are starting to use an application
33:09
you are starting to use an application
33:09
you are starting to use an application uh Gateway with uh web application
33:12
uh Gateway with uh web application
33:12
uh Gateway with uh web application firewall uh all the API protection layer
33:16
firewall uh all the API protection layer
33:16
firewall uh all the API protection layer that usually you are implementing
33:19
that usually you are implementing
33:19
that usually you are implementing at the API level in your application or
33:22
at the API level in your application or
33:22
at the API level in your application or putting on top your application when
33:24
putting on top your application when
33:24
putting on top your application when you're sponsoring another third party
33:27
you're sponsoring another third party
33:27
you're sponsoring another third party you don't need that
33:29
you don't need that
33:29
you don't need that anymore and it means that it save
33:32
anymore and it means that it save
33:32
anymore and it means that it save you time
33:35
you time
33:35
you time support and monitoring because also
33:38
support and monitoring because also
33:38
support and monitoring because also monitoring is very important because if
33:40
monitoring is very important because if
33:40
monitoring is very important because if you have an outof thee shelf solution
33:42
you have an outof thee shelf solution
33:42
you have an outof thee shelf solution you don't need anymore to monitor to do
33:46
you don't need anymore to monitor to do
33:46
you don't need anymore to monitor to do uh too many security tests on on on that
33:51
uh too many security tests on on on that
33:51
uh too many security tests on on on that part and so on and the most important
33:53
part and so on and the most important
33:53
part and so on and the most important thing here is
33:55
thing here is
33:55
thing here is that if somebody is trying to attack you
33:58
that if somebody is trying to attack you
33:58
that if somebody is trying to attack you not only Bruce Force but
34:00
not only Bruce Force but
34:00
not only Bruce Force but basically trying to gain access because
34:04
basically trying to gain access because
34:04
basically trying to gain access because you because all that
34:07
you because all that
34:07
you because all that load um will be blocked at application
34:12
load um will be blocked at application
34:12
load um will be blocked at application Gateway it means that your back end does
34:16
Gateway it means that your back end does
34:16
Gateway it means that your back end does it is not heated by that payload so you
34:19
it is not heated by that payload so you
34:19
it is not heated by that payload so you don't need to
34:21
don't need to
34:21
don't need to scale your backend system your backend
34:24
scale your backend system your backend
34:24
scale your backend system your backend system is not impacted and can serve
34:26
system is not impacted and can serve
34:26
system is not impacted and can serve without any kind of problem the real
34:29
without any kind of problem the real
34:29
without any kind of problem the real users so the business goes as expected
34:33
users so the business goes as expected
34:33
users so the business goes as expected versus if you put that firewall layer
34:36
versus if you put that firewall layer
34:36
versus if you put that firewall layer for for example top 10 protection and so
34:40
for for example top 10 protection and so
34:40
for for example top 10 protection and so on at the application layer inside your
34:44
on at the application layer inside your
34:44
on at the application layer inside your inside your system even if you have a
34:46
inside your system even if you have a
34:46
inside your system even if you have a third party a li a library but because
34:48
third party a li a library but because
34:48
third party a li a library but because you have that part the payload the CPU
34:51
you have that part the payload the CPU
34:51
you have that part the payload the CPU level that is increased is in your
34:53
level that is increased is in your
34:53
level that is increased is in your backend is it it it is your your
34:56
backend is it it it is your your
34:56
backend is it it it is your your application there meaning that your
34:59
application there meaning that your
34:59
application there meaning that your normal users will be impacted by
35:05
that something that also I would like
35:07
that something that also I would like
35:07
that something that also I would like also to mention is that another layer
35:11
also to mention is that another layer
35:11
also to mention is that another layer that we need to consider is the
35:13
that we need to consider is the
35:13
that we need to consider is the versioning of your
35:15
versioning of your
35:15
versioning of your API and also we have for
35:17
API and also we have for
35:17
API and also we have for example
35:19
example
35:19
example um specific services that need that
35:22
um specific services that need that
35:22
um specific services that need that needs to take this
35:25
needs to take this
35:25
needs to take this uh that can take this uh payload like
35:28
uh that can take this uh payload like
35:28
uh that can take this uh payload like the API management and similar with
35:33
the API management and similar with
35:33
the API management and similar with application gway also API
35:36
application gway also API
35:36
application gway also API management or let's say the challenge
35:38
management or let's say the challenge
35:38
management or let's say the challenge with this is that also with it's come
35:41
with this is that also with it's come
35:41
with this is that also with it's come with additional cost but what is
35:43
with additional cost but what is
35:43
with additional cost but what is providing to you is a layer where you
35:47
providing to you is a layer where you
35:47
providing to you is a layer where you can manage your API manage your your uh
35:51
can manage your API manage your your uh
35:51
can manage your API manage your your uh your versioning and control who has
35:54
your versioning and control who has
35:54
your versioning and control who has access to what meaning that if you're
35:56
access to what meaning that if you're
35:57
access to what meaning that if you're going a combination a with API
35:59
going a combination a with API
35:59
going a combination a with API management and application get uh gway
36:04
management and application get uh gway
36:04
management and application get uh gway you end up in a solution where in the
36:07
you end up in a solution where in the
36:07
you end up in a solution where in the back end you are focusing in only one
36:09
back end you are focusing in only one
36:09
back end you are focusing in only one thing on the
36:12
thing on the
36:12
thing on the business implementing the business flow
36:15
business implementing the business flow
36:15
business implementing the business flow the business rules and focusing how you
36:18
the business rules and focusing how you
36:18
the business rules and focusing how you can bring value to the customer
36:22
can bring value to the customer
36:22
can bring value to the customer versioning part is done inside the API
36:24
versioning part is done inside the API
36:24
versioning part is done inside the API management Access Control identity Tex
36:27
management Access Control identity Tex
36:27
management Access Control identity Tex management part who has access who has
36:30
management part who has access who has
36:30
management part who has access who has uh access to what and so on you are
36:33
uh access to what and so on you are
36:33
uh access to what and so on you are fully implementing inside the API
36:36
fully implementing inside the API
36:36
fully implementing inside the API management you have the application gway
36:38
management you have the application gway
36:38
management you have the application gway that is fully
36:40
that is fully
36:40
that is fully managing uh the security
36:44
managing uh the security
36:44
managing uh the security layer uh if you put on top of that a
36:47
layer uh if you put on top of that a
36:47
layer uh if you put on top of that a loud bananer and uh traffic and uh a
36:52
loud bananer and uh traffic and uh a
36:52
loud bananer and uh traffic and uh a traffic manager like fondor you end up
36:54
traffic manager like fondor you end up
36:54
traffic manager like fondor you end up to
36:55
to
36:55
to have all that security routing Access
36:59
have all that security routing Access
36:59
have all that security routing Access Control outside your system and when you
37:02
Control outside your system and when you
37:02
Control outside your system and when you implement a business flow you you
37:04
implement a business flow you you
37:04
implement a business flow you you already know when you write the code
37:07
already know when you write the code
37:07
already know when you write the code that that person has and has the right
37:11
that that person has and has the right
37:11
that that person has and has the right to be able to access that API you know
37:13
to be able to access that API you know
37:13
to be able to access that API you know exactly who who is that person you you
37:17
exactly who who is that person you you
37:17
exactly who who is that person you you know what kind of role he has and you
37:21
know what kind of role he has and you
37:21
know what kind of role he has and you can focus on serving that uh request
37:25
can focus on serving that uh request
37:25
can focus on serving that uh request giving back some um maybe some data or
37:28
giving back some um maybe some data or
37:28
giving back some um maybe some data or or triggering specific things behind the
37:35
scene secret secret
37:38
scene secret secret
37:38
scene secret secret Secrets I see keyo used
37:42
Secrets I see keyo used
37:42
Secrets I see keyo used everywhere but sometimes except the keyb
37:45
everywhere but sometimes except the keyb
37:45
everywhere but sometimes except the keyb we also need to do some basic things for
37:49
we also need to do some basic things for
37:49
we also need to do some basic things for example if you're using uh let's take a
37:52
example if you're using uh let's take a
37:52
example if you're using uh let's take a very basic example if you're using Azure
37:54
very basic example if you're using Azure
37:54
very basic example if you're using Azure storage in aure storage you have
37:58
storage in aure storage you have
37:58
storage in aure storage you have of key rotation
38:02
capabilities but the question is how
38:05
capabilities but the question is how
38:05
capabilities but the question is how many of you are
38:08
many of you are
38:08
many of you are using and are doing rotation Secrets
38:12
using and are doing rotation Secrets
38:12
using and are doing rotation Secrets every few days few weeks few
38:17
every few days few weeks few
38:17
every few days few weeks few months and all the services and you need
38:20
months and all the services and you need
38:20
months and all the services and you need to be very careful when you build an
38:22
to be very careful when you build an
38:22
to be very careful when you build an application to take a look on the
38:24
application to take a look on the
38:24
application to take a look on the services that have also keys of ailable
38:28
services that have also keys of ailable
38:28
services that have also keys of ailable even if you don't use them you need to
38:31
even if you don't use them you need to
38:31
even if you don't use them you need to ensure that that Keys uh cannot be
38:35
ensure that that Keys uh cannot be
38:35
ensure that that Keys uh cannot be access and also AR rotated every
38:38
access and also AR rotated every
38:38
access and also AR rotated every specific time interval
38:41
specific time interval
38:41
specific time interval because sometimes you could have a
38:43
because sometimes you could have a
38:43
because sometimes you could have a bridge and you don't even know about
38:45
bridge and you don't even know about
38:45
bridge and you don't even know about that when somebody get access to through
38:49
that when somebody get access to through
38:49
that when somebody get access to through a compromise uh
38:53
a compromise uh
38:53
a compromise uh system to aure portal and to a they are
38:58
system to aure portal and to a they are
38:58
system to aure portal and to a they are stealing this access keys and they're
39:00
stealing this access keys and they're
39:00
stealing this access keys and they're staying low for one two 3 months until
39:04
staying low for one two 3 months until
39:04
staying low for one two 3 months until they would try to fet the data or to
39:06
they would try to fet the data or to
39:06
they would try to fet the data or to modify the data and so on and if you
39:09
modify the data and so on and if you
39:09
modify the data and so on and if you have the right policies you can you
39:11
have the right policies you can you
39:11
have the right policies you can you could handle more or less this because
39:14
could handle more or less this because
39:14
could handle more or less this because uh one of for example one of the
39:17
uh one of for example one of the
39:17
uh one of for example one of the disadvantages of
39:19
disadvantages of
39:19
disadvantages of uh uh access keys for example in Azure
39:22
uh uh access keys for example in Azure
39:22
uh uh access keys for example in Azure storage is
39:24
storage is
39:24
storage is that you also the keys themselves also
39:27
that you also the keys themselves also
39:27
that you also the keys themselves also provide access to write delete operation
39:31
provide access to write delete operation
39:31
provide access to write delete operation and so on of course you can have backups
39:33
and so on of course you can have backups
39:33
and so on of course you can have backups you can have other mechanis that a
39:35
you can have other mechanis that a
39:35
you can have other mechanis that a storage is providing but in the end you
39:37
storage is providing but in the end you
39:37
storage is providing but in the end you might be affected for a short period of
39:43
time now when you talk about compliances
39:47
time now when you talk about compliances
39:47
time now when you talk about compliances and uh governance we already heard about
39:50
and uh governance we already heard about
39:50
and uh governance we already heard about Microsoft def Defender if you didn't
39:52
Microsoft def Defender if you didn't
39:52
Microsoft def Defender if you didn't have the opportunity to use it until now
39:54
have the opportunity to use it until now
39:54
have the opportunity to use it until now I would say that is one of the core
39:57
I would say that is one of the core
39:57
I would say that is one of the core Services when you need to do compliancy
40:01
Services when you need to do compliancy
40:01
Services when you need to do compliancy uh checking why because through
40:05
uh checking why because through
40:05
uh checking why because through Microsoft
40:06
Microsoft
40:06
Microsoft Defender you can or Microsoft can fully
40:10
Defender you can or Microsoft can fully
40:10
Defender you can or Microsoft can fully audit all your resources identify how
40:13
audit all your resources identify how
40:14
audit all your resources identify how they are deployed if you are line with
40:16
they are deployed if you are line with
40:16
they are deployed if you are line with different uh uh requirements and if in
40:20
different uh uh requirements and if in
40:20
different uh uh requirements and if in if you have a compliancy regulation that
40:23
if you have a compliancy regulation that
40:23
if you have a compliancy regulation that you need to check that is not part of M
40:26
you need to check that is not part of M
40:26
you need to check that is not part of M Defender
40:28
Defender
40:28
Defender there is a channel and there's a
40:30
there is a channel and there's a
40:30
there is a channel and there's a dedicated team that can support you in
40:33
dedicated team that can support you in
40:33
dedicated team that can support you in defining that
40:35
defining that
40:35
defining that custom uh set of rules that needs to be
40:39
custom uh set of rules that needs to be
40:39
custom uh set of rules that needs to be that needs to be
40:40
that needs to be
40:40
that needs to be checked on top of my M Defender you have
40:44
checked on top of my M Defender you have
40:44
checked on top of my M Defender you have Azure policies and Azure policies from
40:47
Azure policies and Azure policies from
40:47
Azure policies and Azure policies from the governance point of view are is the
40:50
the governance point of view are is the
40:50
the governance point of view are is the most important thing that you need to
40:51
most important thing that you need to
40:52
most important thing that you need to consider and you need to implement from
40:54
consider and you need to implement from
40:54
consider and you need to implement from the beginning because aure policies not
40:56
the beginning because aure policies not
40:56
the beginning because aure policies not only refer to what users can do in that
41:00
only refer to what users can do in that
41:00
only refer to what users can do in that application that's you might manage this
41:02
application that's you might manage this
41:02
application that's you might manage this in different way but also specify
41:04
in different way but also specify
41:04
in different way but also specify exactly the technical team what is able
41:08
exactly the technical team what is able
41:08
exactly the technical team what is able to do and what is not able to do what
41:11
to do and what is not able to do what
41:11
to do and what is not able to do what kind of roles for example can access
41:14
kind of roles for example can access
41:14
kind of roles for example can access different environments where different
41:17
different environments where different
41:17
different environments where different resources can be deployed meaning that
41:20
resources can be deployed meaning that
41:20
resources can be deployed meaning that because of some compliance regulation
41:22
because of some compliance regulation
41:22
because of some compliance regulation maybe you are forced to do the
41:24
maybe you are forced to do the
41:24
maybe you are forced to do the deployment and only in EU EU countries
41:28
deployment and only in EU EU countries
41:28
deployment and only in EU EU countries through Azure policies you can specify
41:30
through Azure policies you can specify
41:30
through Azure policies you can specify exactly that this you might have some
41:33
exactly that this you might have some
41:33
exactly that this you might have some other standards that are intern
41:35
other standards that are intern
41:35
other standards that are intern organization and or enforced by a
41:38
organization and or enforced by a
41:38
organization and or enforced by a regulation that you are not allowed yet
41:41
regulation that you are not allowed yet
41:41
regulation that you are not allowed yet maybe to use let's say aure open AI or
41:45
maybe to use let's say aure open AI or
41:45
maybe to use let's say aure open AI or from the computation point of view you
41:46
from the computation point of view you
41:46
from the computation point of view you can use service a b c and d but not the
41:51
can use service a b c and d but not the
41:51
can use service a b c and d but not the other resps and then through the Azure
41:53
other resps and then through the Azure
41:53
other resps and then through the Azure policies you can enforce that only
41:55
policies you can enforce that only
41:55
policies you can enforce that only specific type of services and and of
41:57
specific type of services and and of
41:57
specific type of services and and of course some specific tiers can be spin
42:00
course some specific tiers can be spin
42:00
course some specific tiers can be spin up so you can Define policies that
42:02
up so you can Define policies that
42:02
up so you can Define policies that specify where the solution can be
42:05
specify where the solution can be
42:05
specify where the solution can be deployed what kind of services and
42:07
deployed what kind of services and
42:07
deployed what kind of services and another important thing from the phenos
42:10
another important thing from the phenos
42:10
another important thing from the phenos point of view Azure policies is
42:12
point of view Azure policies is
42:12
point of view Azure policies is providing us the capability to
42:15
providing us the capability to
42:15
providing us the capability to specify even the tier of services that
42:19
specify even the tier of services that
42:19
specify even the tier of services that somebody can spin depending on their
42:22
somebody can spin depending on their
42:22
somebody can spin depending on their role meaning that for example you have
42:25
role meaning that for example you have
42:25
role meaning that for example you have the development team that can spin up
42:28
the development team that can spin up
42:28
the development team that can spin up only small small tiers of different
42:31
only small small tiers of different
42:31
only small small tiers of different resources you can have the data
42:34
resources you can have the data
42:34
resources you can have the data scientist team that can spin up Azure ml
42:39
scientist team that can spin up Azure ml
42:39
scientist team that can spin up Azure ml some microfabric stuff and so on but
42:42
some microfabric stuff and so on but
42:42
some microfabric stuff and so on but only specific location because they are
42:44
only specific location because they are
42:44
only specific location because they are working with data and they canot go
42:46
working with data and they canot go
42:46
working with data and they canot go outside let's say Germany or UK and they
42:50
outside let's say Germany or UK and they
42:50
outside let's say Germany or UK and they cannot spin anything else uh that is uh
42:55
cannot spin anything else uh that is uh
42:55
cannot spin anything else uh that is uh around that side
42:58
around that side
42:58
around that side and also the third thing that I would
42:59
and also the third thing that I would
42:59
and also the third thing that I would like to highlight is the importance of
43:02
like to highlight is the importance of
43:02
like to highlight is the importance of azure Blueprints and now when we talk
43:04
azure Blueprints and now when we talk
43:04
azure Blueprints and now when we talk about blueprints we need to consider
43:07
about blueprints we need to consider
43:07
about blueprints we need to consider that Azure blueprints are in the
43:11
that Azure blueprints are in the
43:11
that Azure blueprints are in the end the high level best practice and
43:15
end the high level best practice and
43:15
end the high level best practice and recommendation that moft is providing
43:17
recommendation that moft is providing
43:17
recommendation that moft is providing for a specific use case use case not
43:20
for a specific use case use case not
43:20
for a specific use case use case not means only a specific type of
43:22
means only a specific type of
43:22
means only a specific type of application but also a use case that
43:25
application but also a use case that
43:25
application but also a use case that would uh align
43:27
would uh align
43:27
would uh align with standard compliance
43:29
with standard compliance
43:29
with standard compliance requirements that you might have for a
43:32
requirements that you might have for a
43:32
requirements that you might have for a specific
43:37
industry excuse
43:40
industry excuse
43:40
industry excuse me and just before closing I would like
43:44
me and just before closing I would like
43:44
me and just before closing I would like to talk more about automated
43:46
to talk more about automated
43:46
to talk more about automated vulnerability
43:47
vulnerability
43:47
vulnerability scanning yes my Defender is also can do
43:51
scanning yes my Defender is also can do
43:51
scanning yes my Defender is also can do this part also can provide
43:52
this part also can provide
43:52
this part also can provide recommendation and automatically fix and
43:55
recommendation and automatically fix and
43:55
recommendation and automatically fix and is doing a great
43:58
is doing a great
43:58
is doing a great job also we have o sub that is doing a
44:02
job also we have o sub that is doing a
44:02
job also we have o sub that is doing a great job for penetration
44:05
testing and let's take a look on some
44:08
testing and let's take a look on some
44:08
testing and let's take a look on some other services and what I would like now
44:10
other services and what I would like now
44:10
other services and what I would like now to go together with you is what is a
44:13
to go together with you is what is a
44:13
to go together with you is what is a service and what does this provide
44:15
service and what does this provide
44:15
service and what does this provide because there's a few of of services and
44:19
because there's a few of of services and
44:19
because there's a few of of services and we need to have a Clear Vision exactly
44:22
we need to have a Clear Vision exactly
44:22
we need to have a Clear Vision exactly what uh what is doing by each of them so
44:26
what uh what is doing by each of them so
44:26
what uh what is doing by each of them so we have my micone Defender for cloud
44:27
we have my micone Defender for cloud
44:28
we have my micone Defender for cloud that we already talked and more or less
44:31
that we already talked and more or less
44:31
that we already talked and more or less it's about assessment doing assessment
44:33
it's about assessment doing assessment
44:33
it's about assessment doing assessment of some Security checks
44:36
of some Security checks
44:36
of some Security checks automatically can do recommendation and
44:40
automatically can do recommendation and
44:40
automatically can do recommendation and can also
44:43
react we have the Z attack
44:47
react we have the Z attack
44:47
react we have the Z attack proxy that can identify vulnerability to
44:51
proxy that can identify vulnerability to
44:51
proxy that can identify vulnerability to penetration Tes are done automatically
44:54
penetration Tes are done automatically
44:54
penetration Tes are done automatically so you can have for example test that
44:57
so you can have for example test that
44:57
so you can have for example test that are done not only before
45:01
are done not only before
45:01
are done not only before each uh launch pre-production
45:04
each uh launch pre-production
45:04
each uh launch pre-production environment but also for example you
45:06
environment but also for example you
45:06
environment but also for example you could run zap every
45:10
could run zap every
45:10
could run zap every night in the de in the development
45:13
night in the de in the development
45:13
night in the de in the development environment or in some other environment
45:16
environment or in some other environment
45:16
environment or in some other environment just to ensure that what was implemented
45:19
just to ensure that what was implemented
45:19
just to ensure that what was implemented what was configured until
45:21
what was configured until
45:21
what was configured until then it's okay the third part the third
45:25
then it's okay the third part the third
45:25
then it's okay the third part the third thing you need web application firewall
45:28
thing you need web application firewall
45:28
thing you need web application firewall that we already
45:30
that we already
45:30
that we already talked and one of the benefits it's top
45:33
talked and one of the benefits it's top
45:33
talked and one of the benefits it's top 10 threads of oaps that are
45:35
10 threads of oaps that are
45:35
10 threads of oaps that are automatically covered and you have
45:40
automatically covered and you have
45:40
automatically covered and you have uh um you are protected automatically by
45:45
uh um you are protected automatically by
45:46
uh um you are protected automatically by by them the fourth one is dependency
45:50
by them the fourth one is dependency
45:50
by them the fourth one is dependency scanning for dependes
45:52
scanning for dependes
45:52
scanning for dependes scanning um and why this is important
45:56
scanning um and why this is important
45:56
scanning um and why this is important because because
45:58
because because
45:58
because because nowadays maybe I'm just saying maybe for
46:02
nowadays maybe I'm just saying maybe for
46:02
nowadays maybe I'm just saying maybe for one component that you're building you
46:04
one component that you're building you
46:04
one component that you're building you are using 100 or 500 libraries that are
46:08
are using 100 or 500 libraries that are
46:08
are using 100 or 500 libraries that are built provided by somebody
46:12
built provided by somebody
46:12
built provided by somebody else and when a vulnerability happens to
46:17
else and when a vulnerability happens to
46:17
else and when a vulnerability happens to that part to that library to that
46:22
that part to that library to that
46:22
that part to that library to that package you need to know you need to be
46:24
package you need to know you need to be
46:24
package you need to know you need to be able to
46:25
able to
46:25
able to react so you need a mechanism that is
46:29
react so you need a mechanism that is
46:29
react so you need a mechanism that is doing dependency scanning a devops
46:32
doing dependency scanning a devops
46:32
doing dependency scanning a devops GitHub depend dependabot can do this
46:36
GitHub depend dependabot can do this
46:36
GitHub depend dependabot can do this very good and you need to consider that
46:39
very good and you need to consider that
46:39
very good and you need to consider that this scan is not done only one time or
46:43
this scan is not done only one time or
46:43
this scan is not done only one time or every time when you want to go in
46:45
every time when you want to go in
46:45
every time when you want to go in production because vulnerabilities can
46:48
production because vulnerabilities can
46:48
production because vulnerabilities can appear for existing libraries and
46:49
appear for existing libraries and
46:49
appear for existing libraries and packages that you are already using
46:52
packages that you are already using
46:52
packages that you are already using meaning that once you go live your job
46:56
meaning that once you go live your job
46:56
meaning that once you go live your job is not finished from dependency scanning
46:58
is not finished from dependency scanning
46:58
is not finished from dependency scanning you still need to scan with the
47:02
you still need to scan with the
47:02
you still need to scan with the new information that appear all the time
47:04
new information that appear all the time
47:04
new information that appear all the time to ensure that what was relasing
47:07
to ensure that what was relasing
47:07
to ensure that what was relasing production doesn't have any kind of
47:10
production doesn't have any kind of
47:10
production doesn't have any kind of dependencies that are vulnerable have a
47:13
dependencies that are vulnerable have a
47:13
dependencies that are vulnerable have a have a day Zero uh uh
47:21
problem we are talking uh about now
47:24
problem we are talking uh about now
47:24
problem we are talking uh about now about continous security uh assessment
47:27
about continous security uh assessment
47:27
about continous security uh assessment where more or less is about continous
47:29
where more or less is about continous
47:29
where more or less is about continous scanning tools like qual and and uh so
47:32
scanning tools like qual and and uh so
47:33
scanning tools like qual and and uh so on and the last one that I would like to
47:36
on and the last one that I would like to
47:36
on and the last one that I would like to highlight is as you for example do
47:38
highlight is as you for example do
47:38
highlight is as you for example do dependency scanning for packages you
47:42
dependency scanning for packages you
47:42
dependency scanning for packages you also need to do dependency scanning for
47:46
also need to do dependency scanning for
47:46
also need to do dependency scanning for containers to scan the images of the
47:49
containers to scan the images of the
47:49
containers to scan the images of the container that you are that that you are
47:52
container that you are that that you are
47:52
container that you are that that you are using how this can be done one option is
47:55
using how this can be done one option is
47:55
using how this can be done one option is maxel Defender that is doing a pretty
47:58
maxel Defender that is doing a pretty
47:58
maxel Defender that is doing a pretty good job for a for APS
48:02
good job for a for APS
48:02
good job for a for APS images also you have the if you are
48:05
images also you have the if you are
48:05
images also you have the if you are using a container reg registry that can
48:08
using a container reg registry that can
48:08
using a container reg registry that can be used to scan Andy any kind of r that
48:11
be used to scan Andy any kind of r that
48:11
be used to scan Andy any kind of r that you have to the images before deployment
48:14
you have to the images before deployment
48:14
you have to the images before deployment them so you have a full set of services
48:18
them so you have a full set of services
48:18
them so you have a full set of services uh that you need to be aware of you need
48:20
uh that you need to be aware of you need
48:20
uh that you need to be aware of you need to know how to integrate them and to be
48:22
to know how to integrate them and to be
48:22
to know how to integrate them and to be able to roll out because each of them
48:25
able to roll out because each of them
48:25
able to roll out because each of them are covering a specific part of your
48:28
are covering a specific part of your
48:28
are covering a specific part of your system uh you will see that I just give
48:31
system uh you will see that I just give
48:31
system uh you will see that I just give give you some example but you will find
48:33
give you some example but you will find
48:33
give you some example but you will find also on the internet other tool that can
48:36
also on the internet other tool that can
48:36
also on the internet other tool that can that are covering the same thing and
48:38
that are covering the same thing and
48:38
that are covering the same thing and they are amazing I tried to stay uh as
48:40
they are amazing I tried to stay uh as
48:40
they are amazing I tried to stay uh as close as possible to Microsoft echos
48:44
close as possible to Microsoft echos
48:44
close as possible to Microsoft echos echosystem but there are a lot of tools
48:47
echosystem but there are a lot of tools
48:47
echosystem but there are a lot of tools on the
48:49
on the
48:49
on the market now before
48:51
market now before
48:51
market now before closing talking about business
48:53
closing talking about business
48:53
closing talking about business continuity and Dr
48:59
sometimes we are forgetting about how
49:02
sometimes we are forgetting about how
49:02
sometimes we are forgetting about how important are the backups how important
49:06
important are the backups how important
49:06
important are the backups how important are Azure backups how important to have
49:08
are Azure backups how important to have
49:08
are Azure backups how important to have them configured in the right way and
49:12
them configured in the right way and
49:12
them configured in the right way and when I saying the right way it's not
49:13
when I saying the right way it's not
49:13
when I saying the right way it's not only creating the backup I would say
49:15
only creating the backup I would say
49:15
only creating the backup I would say that nowadays uh if you take a if you do
49:18
that nowadays uh if you take a if you do
49:18
that nowadays uh if you take a if you do a backup of a database it's not like 15
49:20
a backup of a database it's not like 15
49:20
a backup of a database it's not like 15 years ago when you had to check if
49:24
years ago when you had to check if
49:24
years ago when you had to check if everything goes well most of the time
49:26
everything goes well most of the time
49:26
everything goes well most of the time things go as as expected by except doing
49:30
things go as as expected by except doing
49:30
things go as as expected by except doing the backup you need to ensure that the
49:32
the backup you need to ensure that the
49:32
the backup you need to ensure that the backup is stored in a safe
49:36
backup is stored in a safe
49:36
backup is stored in a safe place because if somebody put the hands
49:39
place because if somebody put the hands
49:39
place because if somebody put the hands on the backup even if it's encrypted
49:42
on the backup even if it's encrypted
49:42
on the backup even if it's encrypted even if
49:43
even if
49:43
even if it's uh even if you're using a a very
49:48
it's uh even if you're using a a very
49:48
it's uh even if you're using a a very complex password you don't know exactly
49:52
how how it can be compromised I I
49:55
how how it can be compromised I I
49:55
how how it can be compromised I I remember a long long time ago I think in
49:59
remember a long long time ago I think in
49:59
remember a long long time ago I think in uh at the last
50:02
uh at the last
50:02
uh at the last uh
50:03
uh
50:04
uh decade before they were calling in night
50:06
decade before they were calling in night
50:06
decade before they were calling in night I don't know maybe it was in
50:08
I don't know maybe it was in
50:08
I don't know maybe it was in Chicago I
50:10
Chicago I
50:10
Chicago I saw um I saw U Paula in a 90minut
50:16
saw um I saw U Paula in a 90minut
50:16
saw um I saw U Paula in a 90minut session and she
50:18
session and she
50:18
session and she broke an a SQL backup and show exactly
50:23
broke an a SQL backup and show exactly
50:23
broke an a SQL backup and show exactly what are the tool that you need to use
50:25
what are the tool that you need to use
50:25
what are the tool that you need to use to go in the binaries of the
50:28
to go in the binaries of the
50:28
to go in the binaries of the backup and
50:31
backup and
50:31
backup and replace the predefined token for the
50:33
replace the predefined token for the
50:33
replace the predefined token for the password with the predefined one that
50:35
password with the predefined one that
50:35
password with the predefined one that you have and then voila you had access
50:38
you have and then voila you had access
50:38
you have and then voila you had access to it and they just and that's just one
50:41
to it and they just and that's just one
50:41
to it and they just and that's just one example there are many other things that
50:44
example there are many other things that
50:44
example there are many other things that you can do also there are some times
50:46
you can do also there are some times
50:46
you can do also there are some times when people are doing backups and they
50:47
when people are doing backups and they
50:47
when people are doing backups and they don't enry them and if you take a look
50:49
don't enry them and if you take a look
50:49
don't enry them and if you take a look on Google you will see that a lot of
50:51
on Google you will see that a lot of
50:52
on Google you will see that a lot of breaches happen just because not of the
50:55
breaches happen just because not of the
50:55
breaches happen just because not of the main data or storage but because of the
50:57
main data or storage but because of the
50:57
main data or storage but because of the backup somebody put a hand on the backup
50:59
backup somebody put a hand on the backup
50:59
backup somebody put a hand on the backup and they were able to access
51:02
it the last thing is azure sight
51:06
it the last thing is azure sight
51:06
it the last thing is azure sight recovery now for developers that are
51:08
recovery now for developers that are
51:08
recovery now for developers that are building application you might not be
51:10
building application you might not be
51:10
building application you might not be very close to it but Azure sight
51:12
very close to it but Azure sight
51:12
very close to it but Azure sight recovery is giving you the ability to be
51:15
recovery is giving you the ability to be
51:15
recovery is giving you the ability to be able to back up and restore your
51:19
able to back up and restore your
51:19
able to back up and restore your workloads in case of something happen to
51:23
workloads in case of something happen to
51:23
workloads in case of something happen to be able to restore them in another V
51:25
be able to restore them in another V
51:25
be able to restore them in another V Zone to be able to restore them in
51:27
Zone to be able to restore them in
51:27
Zone to be able to restore them in another aure region on your own Prem
51:29
another aure region on your own Prem
51:29
another aure region on your own Prem solution in another Cloud vendor and so
51:31
solution in another Cloud vendor and so
51:31
solution in another Cloud vendor and so on and this component is very important
51:36
on and this component is very important
51:36
on and this component is very important because this part give you the ability
51:38
because this part give you the ability
51:38
because this part give you the ability to have an end to end automatically
51:40
to have an end to end automatically
51:41
to have an end to end automatically system that take the back up take the
51:43
system that take the back up take the
51:43
system that take the back up take the payload and kick it off in another
51:46
payload and kick it off in another
51:46
payload and kick it off in another location and just before closing this
51:49
location and just before closing this
51:49
location and just before closing this topic something that we should also keep
51:52
topic something that we should also keep
51:52
topic something that we should also keep in mind is
51:54
in mind is
51:54
in mind is that even if I said and even if we know
51:58
that even if I said and even if we know
51:58
that even if I said and even if we know that for example a backup
52:00
that for example a backup
52:00
that for example a backup of
52:02
of
52:02
of SQL goes all the time as
52:05
SQL goes all the time as
52:05
SQL goes all the time as expected you should have a written
52:09
expected you should have a written
52:09
expected you should have a written procedure what are the recovery what are
52:12
procedure what are the recovery what are
52:12
procedure what are the recovery what are the Dr that that needs to be done and
52:15
the Dr that that needs to be done and
52:15
the Dr that that needs to be done and why it's not about that the SQL backup
52:18
why it's not about that the SQL backup
52:18
why it's not about that the SQL backup will not be able to be restored but
52:21
will not be able to be restored but
52:21
will not be able to be restored but except that restore there are other
52:23
except that restore there are other
52:23
except that restore there are other activities that needs to be run before
52:26
activities that needs to be run before
52:26
activities that needs to be run before and
52:27
and
52:27
and after some of them can be fully
52:30
after some of them can be fully
52:30
after some of them can be fully automatically
52:32
automatically
52:32
automatically but sometimes you have some Manor steps
52:35
but sometimes you have some Manor steps
52:35
but sometimes you have some Manor steps and when you put pressure on people man
52:37
and when you put pressure on people man
52:37
and when you put pressure on people man man man your
52:39
man man your
52:39
man man your um uh your bank solution is down you
52:42
um uh your bank solution is down you
52:42
um uh your bank solution is down you need to recover as fast as possible that
52:44
need to recover as fast as possible that
52:44
need to recover as fast as possible that people might do mistakes or might forget
52:48
people might do mistakes or might forget
52:48
people might do mistakes or might forget about what is the value of that flag
52:50
about what is the value of that flag
52:50
about what is the value of that flag that need to be configured to make the
52:52
that need to be configured to make the
52:52
that need to be configured to make the system to work as
52:53
system to work as
52:53
system to work as expected so you need a full r procedure
52:57
expected so you need a full r procedure
52:57
expected so you need a full r procedure with all the step that needs to be done
52:59
with all the step that needs to be done
52:59
with all the step that needs to be done how you need to handle them and so on
53:01
how you need to handle them and so on
53:02
how you need to handle them and so on and this one should
53:04
and this one should
53:04
and this one should be um should be checked you should have
53:08
be um should be checked you should have
53:08
be um should be checked you should have a simulation every maybe 3 months six
53:11
a simulation every maybe 3 months six
53:11
a simulation every maybe 3 months six months and also consider the component
53:14
months and also consider the component
53:14
months and also consider the component that you assume that will never go down
53:18
that you assume that will never go down
53:18
that you assume that will never go down talking about aure for
53:21
example what you would do if for example
53:25
example what you would do if for example
53:25
example what you would do if for example the end
53:26
the end
53:26
the end enter ID T that you're using goes
53:31
enter ID T that you're using goes
53:31
enter ID T that you're using goes down are you waiting to do a restoration
53:34
down are you waiting to do a restoration
53:34
down are you waiting to do a restoration what if they're losing your data okay in
53:37
what if they're losing your data okay in
53:37
what if they're losing your data okay in that case what are the all the
53:40
that case what are the all the
53:40
that case what are the all the configuration that were done previously
53:42
configuration that were done previously
53:42
configuration that were done previously and that would need to be documented or
53:45
and that would need to be documented or
53:45
and that would need to be documented or written in a paral or some something
53:48
written in a paral or some something
53:48
written in a paral or some something else that would be a that would give the
53:50
else that would be a that would give the
53:50
else that would be a that would give the ability to rebuild that tenant to
53:54
ability to rebuild that tenant to
53:54
ability to rebuild that tenant to rebuild all the roles group and so so on
53:57
rebuild all the roles group and so so on
53:57
rebuild all the roles group and so so on because in many cases best case what you
54:00
because in many cases best case what you
54:00
because in many cases best case what you can find is a conference
54:02
can find is a conference
54:02
can find is a conference page with some of them listed but with
54:06
page with some of them listed but with
54:06
page with some of them listed but with not full but with not full uh but not
54:09
not full but with not full uh but not
54:09
not full but with not full uh but not with the full information and if you
54:11
with the full information and if you
54:11
with the full information and if you need to restore them there are big
54:13
need to restore them there are big
54:13
need to restore them there are big chances that you might forget some steps
54:15
chances that you might forget some steps
54:15
chances that you might forget some steps to do even if we take let's say three
54:17
to do even if we take let's say three
54:17
to do even if we take let's say three days as long as you have the full
54:19
days as long as you have the full
54:19
days as long as you have the full procedure and steps this might be fine
54:21
procedure and steps this might be fine
54:21
procedure and steps this might be fine because it might be the only solution
54:24
because it might be the only solution
54:24
because it might be the only solution that you have available
54:33
the complexity of the system that we
54:35
the complexity of the system that we
54:35
the complexity of the system that we need to manage is pretty high except the
54:38
need to manage is pretty high except the
54:38
need to manage is pretty high except the application layer we need to ensure that
54:41
application layer we need to ensure that
54:41
application layer we need to ensure that we are integrating and we are using the
54:43
we are integrating and we are using the
54:43
we are integrating and we are using the right tools inside our application are
54:46
right tools inside our application are
54:46
right tools inside our application are running inside eror and we are doing the
54:49
running inside eror and we are doing the
54:49
running inside eror and we are doing the right integration
54:51
right integration
54:51
right integration using uh services that give us the
54:58
using uh services that give us the
54:58
using uh services that give us the layer that we that the customer expect
55:02
layer that we that the customer expect
55:02
layer that we that the customer expect from us there are many tools there are
55:05
from us there are many tools there are
55:05
from us there are many tools there are many ways how you can solve different
55:07
many ways how you can solve different
55:07
many ways how you can solve different problem but what we need to ensure
55:11
problem but what we need to ensure
55:11
problem but what we need to ensure that each
55:14
component uh that needs to be handled
55:17
component uh that needs to be handled
55:17
component uh that needs to be handled from the security point of view
55:20
from the security point of view
55:20
from the security point of view has um mitigation and the and the
55:23
has um mitigation and the and the
55:23
has um mitigation and the and the solution
55:24
solution
55:24
solution plan um thank you thank you for being
55:27
plan um thank you thank you for being
55:27
plan um thank you thank you for being with uh me today I hope that you found
55:31
with uh me today I hope that you found
55:31
with uh me today I hope that you found the session useful we have a few minutes
55:34
the session useful we have a few minutes
55:34
the session useful we have a few minutes now for Q&A or we can meet in zoom in a
55:38
now for Q&A or we can meet in zoom in a
55:38
now for Q&A or we can meet in zoom in a in a few
55:40
in a few
55:40
in a few minutes yeah so thank you so much this
55:43
minutes yeah so thank you so much this
55:43
minutes yeah so thank you so much this has been really really great you know
55:46
has been really really great you know
55:46
has been really really great you know security is a v v topic but I think you
55:49
security is a v v topic but I think you
55:50
security is a v v topic but I think you managed to give us a very great overview
55:53
managed to give us a very great overview
55:53
managed to give us a very great overview in just you know 45 50 minutes so thank
55:56
in just you know 45 50 minutes so thank
55:56
in just you know 45 50 minutes so thank thank you so much for
55:58
thank you so much for
55:58
thank you so much for that and now we're going to have a Q&A
56:01
that and now we're going to have a Q&A
56:01
that and now we're going to have a Q&A session but before we go into that uh I
56:03
session but before we go into that uh I
56:03
session but before we go into that uh I will just uh would just like to
56:06
will just uh would just like to
56:06
will just uh would just like to advertise here that after we finish our
56:09
advertise here that after we finish our
56:09
advertise here that after we finish our session we would like to welcome
56:11
session we would like to welcome
56:11
session we would like to welcome everyone of you for a short digitala
56:14
everyone of you for a short digitala
56:14
everyone of you for a short digitala which is a zoom meeting where you will
56:16
which is a zoom meeting where you will
56:16
which is a zoom meeting where you will be able to talk directly to Ru and
56:19
be able to talk directly to Ru and
56:19
be able to talk directly to Ru and discuss things and a bit more here in
56:21
discuss things and a bit more here in
56:21
discuss things and a bit more here in detail so let me also share that uh link
56:26
detail so let me also share that uh link
56:26
detail so let me also share that uh link here in the chat uh one H small moment
56:30
here in the chat uh one H small moment
56:30
here in the chat uh one H small moment [Music]
56:32
[Music]
56:32
[Music] here so so either you can scan the QR
56:36
here so so either you can scan the QR
56:36
here so so either you can scan the QR code or you can use this link here
56:40
code or you can use this link here
56:40
code or you can use this link here in in the
56:44
chat
56:47
so
56:50
so
56:50
so um so then we can uh go through here the
56:54
um so then we can uh go through here the
56:54
um so then we can uh go through here the Q questions answered here during the
56:58
Q questions answered here during the
56:58
Q questions answered here during the stream so one question here
57:02
stream so one question here
57:02
stream so one question here in which was asked very early on in the
57:05
in which was asked very early on in the
57:05
in which was asked very early on in the Stream was from Kate so she was asking
57:08
Stream was from Kate so she was asking
57:08
Stream was from Kate so she was asking about some real world example of
57:10
about some real world example of
57:10
about some real world example of security breaches and how they could
57:12
security breaches and how they could
57:12
security breaches and how they could have been prevented using Asher tools so
57:16
have been prevented using Asher tools so
57:16
have been prevented using Asher tools so I think you've given lot of examples
57:19
I think you've given lot of examples
57:19
I think you've given lot of examples here throughout the stream R but is
57:21
here throughout the stream R but is
57:21
here throughout the stream R but is there any anything in particular you
57:24
there any anything in particular you
57:24
there any anything in particular you would like to add
57:27
would like to add
57:27
would like to add I will say
57:29
I will say
57:29
I will say that one of the tools that you would
57:32
that one of the tools that you would
57:32
that one of the tools that you would that I highly recommend to use is mro
57:34
that I highly recommend to use is mro
57:34
that I highly recommend to use is mro the fender especially the premium tier
57:37
the fender especially the premium tier
57:37
the fender especially the premium tier not the free one uh why because it
57:42
not the free one uh why because it
57:42
not the free one uh why because it giving you the oversee the overview of
57:45
giving you the oversee the overview of
57:46
giving you the oversee the overview of the features and configurations that you
57:48
the features and configurations that you
57:48
the features and configurations that you might miss on top of that we you have
57:51
might miss on top of that we you have
57:51
might miss on top of that we you have all the other part but that is one of
57:54
all the other part but that is one of
57:54
all the other part but that is one of the starting point and there are lot
57:56
the starting point and there are lot
57:56
the starting point and there are lot breaches that you could avoid just
57:58
breaches that you could avoid just
57:58
breaches that you could avoid just having it and just give a very simple
58:01
having it and just give a very simple
58:01
having it and just give a very simple simple example if you don't have
58:03
simple example if you don't have
58:03
simple example if you don't have rotation of your keys access keys he
58:07
rotation of your keys access keys he
58:07
rotation of your keys access keys he will let you know if you have by mistake
58:10
will let you know if you have by mistake
58:10
will let you know if you have by mistake somehow configured that also you have
58:13
somehow configured that also you have
58:13
somehow configured that also you have you accept HTTP request not only SEC uh
58:16
you accept HTTP request not only SEC uh
58:16
you accept HTTP request not only SEC uh secure access he will let you know and
58:20
secure access he will let you know and
58:20
secure access he will let you know and also he will most of the cases he will
58:23
also he will most of the cases he will
58:23
also he will most of the cases he will give you
58:25
give you
58:25
give you uh a script that can run automatically
58:28
uh a script that can run automatically
58:28
uh a script that can run automatically to fix that problem it's very basic it's
58:30
to fix that problem it's very basic it's
58:30
to fix that problem it's very basic it's very simple but in the end most of the
58:34
very simple but in the end most of the
58:34
very simple but in the end most of the breaches I would say that are happening
58:35
breaches I would say that are happening
58:35
breaches I would say that are happening because of these small things that you
58:37
because of these small things that you
58:37
because of these small things that you just forget to do or to
58:42
cover okay thank you then we have a
58:47
cover okay thank you then we have a
58:47
cover okay thank you then we have a question here from Jona she asked what
58:50
question here from Jona she asked what
58:50
question here from Jona she asked what are your recommended security tools for
58:53
are your recommended security tools for
58:53
are your recommended security tools for selfhosted Asher devops agent
58:56
selfhosted Asher devops agent
58:56
selfhosted Asher devops agent through aser VMS or aser VM scale
59:02
sets
59:13
uh what are the what are Rec security
59:16
uh what are the what are Rec security
59:16
uh what are the what are Rec security tools for selfhosted aure devop agent
59:18
tools for selfhosted aure devop agent
59:18
tools for selfhosted aure devop agent through aure
59:20
through aure
59:20
through aure avms um that's a very good question I
59:23
avms um that's a very good question I
59:23
avms um that's a very good question I was just thinking
59:26
was just thinking
59:26
was just thinking from the tools are so if you talk about
59:28
from the tools are so if you talk about
59:28
from the tools are so if you talk about the tools for example you can also have
59:32
the tools for example you can also have
59:32
the tools for example you can also have Defender that could
59:34
Defender that could
59:34
Defender that could run but also
59:38
run but also
59:38
run but also um by the tomb tool themselves I think
59:42
um by the tomb tool themselves I think
59:42
um by the tomb tool themselves I think or what I what I would recommend just
59:45
or what I what I would recommend just
59:45
or what I what I would recommend just one time I want go back to the slides
1:00:22
uh I think that for uh for example
1:00:27
uh I think that for uh for example
1:00:27
uh I think that for uh for example and I'm just thinking if for example
1:00:29
and I'm just thinking if for example
1:00:29
and I'm just thinking if for example take uh secret
1:00:32
take uh secret
1:00:32
take uh secret management something
1:00:36
maybe like
1:00:38
maybe like
1:00:38
maybe like [Music]
1:00:40
[Music]
1:00:40
[Music] uh HOV could be used for it and the
1:00:46
uh HOV could be used for it and the
1:00:46
uh HOV could be used for it and the Vault for the configuration so this one
1:00:51
Vault for the configuration so this one
1:00:51
Vault for the configuration so this one I'm thinking for for example you have
1:00:53
I'm thinking for for example you have
1:00:53
I'm thinking for for example you have for example U
1:00:56
for example U
1:00:56
for example U you have different play uh Play books
1:00:59
you have different play uh Play books
1:00:59
you have different play uh Play books for hardening the
1:01:00
for hardening the
1:01:00
for hardening the security or if you take for example
1:01:04
security or if you take for example
1:01:04
security or if you take for example anchor as an example for custom runtime
1:01:09
anchor as an example for custom runtime
1:01:09
anchor as an example for custom runtime security that would be able to run
1:01:11
security that would be able to run
1:01:12
security that would be able to run inside the agent and dig inside any kind
1:01:16
inside the agent and dig inside any kind
1:01:16
inside the agent and dig inside any kind of threads and to be able to react to
1:01:21
of threads and to be able to react to
1:01:21
of threads and to be able to react to it for identity access management issue
1:01:24
it for identity access management issue
1:01:24
it for identity access management issue for example let's assume that you don't
1:01:25
for example let's assume that you don't
1:01:25
for example let's assume that you don't use is uh or you're trying to find out
1:01:28
use is uh or you're trying to find out
1:01:28
use is uh or you're trying to find out if your custom Ro Bas control and you
1:01:32
if your custom Ro Bas control and you
1:01:32
if your custom Ro Bas control and you what kind of configuration you've done
1:01:35
what kind of configuration you've done
1:01:35
what kind of configuration you've done you could use something like teleport I
1:01:39
you could use something like teleport I
1:01:39
you could use something like teleport I think that is used to be called this
1:01:40
think that is used to be called this
1:01:40
think that is used to be called this kind of ser of ser of of of
1:01:44
kind of ser of ser of of of
1:01:44
kind of ser of ser of of of service H what else we could we could
1:01:49
service H what else we could we could
1:01:49
service H what else we could we could have uh for treat for treat detection if
1:01:53
have uh for treat for treat detection if
1:01:54
have uh for treat for treat detection if for example you have you want want to
1:01:56
for example you have you want want to
1:01:56
for example you have you want want to have something different than U micro
1:01:59
have something different than U micro
1:01:59
have something different than U micro Defender there is there was an open
1:02:03
Defender there is there was an open
1:02:03
Defender there is there was an open source monitoring
1:02:05
source monitoring
1:02:05
source monitoring solution I think that was called
1:02:09
solution I think that was called
1:02:09
solution I think that was called wazo but one of the appro that I I would
1:02:13
wazo but one of the appro that I I would
1:02:13
wazo but one of the appro that I I would recommend to do is to
1:02:15
recommend to do is to
1:02:15
recommend to do is to take each kind of layer that you like to
1:02:19
take each kind of layer that you like to
1:02:19
take each kind of layer that you like to cover and look exactly what what are the
1:02:21
cover and look exactly what what are the
1:02:21
cover and look exactly what what are the tools what I mean what I mean by that
1:02:23
tools what I mean what I mean by that
1:02:24
tools what I mean what I mean by that I'm not aware for example of a
1:02:26
I'm not aware for example of a
1:02:26
I'm not aware for example of a that is handling uh that is handling
1:02:30
that is handling uh that is handling
1:02:30
that is handling uh that is handling everything this is why for example in
1:02:33
everything this is why for example in
1:02:33
everything this is why for example in the pipeline you have the ability and in
1:02:35
the pipeline you have the ability and in
1:02:35
the pipeline you have the ability and in the end you
1:02:37
the end you
1:02:37
the end you are you're allowed to run different
1:02:40
are you're allowed to run different
1:02:40
are you're allowed to run different steps and different custom activities
1:02:42
steps and different custom activities
1:02:42
steps and different custom activities and system that would do scanning of
1:02:45
and system that would do scanning of
1:02:45
and system that would do scanning of different of different
1:02:54
layers right
1:02:56
layers right
1:02:56
layers right okay we have another question here also
1:02:59
okay we have another question here also
1:02:59
okay we have another question here also uh another question here also from Jonah
1:03:02
uh another question here also from Jonah
1:03:02
uh another question here also from Jonah she asks what is the best way to secure
1:03:06
she asks what is the best way to secure
1:03:06
she asks what is the best way to secure and protect aure front door instances or
1:03:09
and protect aure front door instances or
1:03:09
and protect aure front door instances or end points is f for front door the best
1:03:12
end points is f for front door the best
1:03:12
end points is f for front door the best option or is there any other better
1:03:15
option or is there any other better
1:03:15
option or is there any other better security tools or
1:03:18
practice uh something that aure front
1:03:22
practice uh something that aure front
1:03:22
practice uh something that aure front door now has it is the W part so
1:03:27
door now has it is the W part so
1:03:27
door now has it is the W part so basically the web application fire
1:03:29
basically the web application fire
1:03:29
basically the web application fire firewall that also is part of azure
1:03:32
firewall that also is part of azure
1:03:32
firewall that also is part of azure front the same way we had for
1:03:34
front the same way we had for
1:03:34
front the same way we had for application Gateway for app Gateway we
1:03:36
application Gateway for app Gateway we
1:03:36
application Gateway for app Gateway we have also for a front door this would
1:03:38
have also for a front door this would
1:03:38
have also for a front door this would for example give you protection
1:03:41
for example give you protection
1:03:41
for example give you protection for um some preconfigured rules like top
1:03:46
for um some preconfigured rules like top
1:03:46
for um some preconfigured rules like top 10 OAS but more this is the level lay
1:03:49
10 OAS but more this is the level lay
1:03:49
10 OAS but more this is the level lay layer seven what you don't have is uh
1:03:52
layer seven what you don't have is uh
1:03:52
layer seven what you don't have is uh the do protection and then on top of
1:03:54
the do protection and then on top of
1:03:54
the do protection and then on top of front door you'll need on on dos
1:03:57
front door you'll need on on dos
1:03:57
front door you'll need on on dos protection system just to ensure that if
1:04:00
protection system just to ensure that if
1:04:00
protection system just to ensure that if somebody hits your end point you'll be
1:04:03
somebody hits your end point you'll be
1:04:03
somebody hits your end point you'll be able
1:04:05
able
1:04:05
able to uh you'll be able to protect for this
1:04:08
to uh you'll be able to protect for this
1:04:08
to uh you'll be able to protect for this and the last thing that you could do
1:04:11
and the last thing that you could do
1:04:11
and the last thing that you could do here and you need to ensure is that all
1:04:14
here and you need to ensure is that all
1:04:14
here and you need to ensure is that all that apis that you are protecting
1:04:17
that apis that you are protecting
1:04:17
that apis that you are protecting through front door to application uh
1:04:21
through front door to application uh
1:04:21
through front door to application uh Gateway are not public available over
1:04:24
Gateway are not public available over
1:04:24
Gateway are not public available over the internet meaning that they are they
1:04:27
the internet meaning that they are they
1:04:27
the internet meaning that they are they are they are protected inside uh vnet
1:04:31
are they are protected inside uh vnet
1:04:31
are they are protected inside uh vnet maybe you use for example as private
1:04:34
maybe you use for example as private
1:04:34
maybe you use for example as private link just to uh provide access through
1:04:37
link just to uh provide access through
1:04:37
link just to uh provide access through different system through different vnet
1:04:39
different system through different vnet
1:04:39
different system through different vnet and subsystem but otherwise from the
1:04:41
and subsystem but otherwise from the
1:04:41
and subsystem but otherwise from the public internet or for the users they
1:04:44
public internet or for the users they
1:04:44
public internet or for the users they all the time go to the front door and to
1:04:47
all the time go to the front door and to
1:04:47
all the time go to the front door and to the application uh uh
1:04:50
the application uh uh
1:04:50
the application uh uh gway and some other protection for
1:04:52
gway and some other protection for
1:04:52
gway and some other protection for example can
1:04:53
example can
1:04:53
example can be like defining some custom rules in
1:04:56
be like defining some custom rules in
1:04:56
be like defining some custom rules in aure fror if you talk
1:04:59
aure fror if you talk
1:04:59
aure fror if you talk about that if you know for example the
1:05:01
about that if you know for example the
1:05:01
about that if you know for example the users usually are only from Europe and
1:05:03
users usually are only from Europe and
1:05:04
users usually are only from Europe and you can do some Jo Jo blocking part but
1:05:07
you can do some Jo Jo blocking part but
1:05:07
you can do some Jo Jo blocking part but this this comes with Pro and cons
1:05:09
this this comes with Pro and cons
1:05:09
this this comes with Pro and cons because you don't know exactly for
1:05:11
because you don't know exactly for
1:05:11
because you don't know exactly for example just give you an an
1:05:13
example just give you an an
1:05:13
example just give you an an example uh I have out of the Shelf vpm
1:05:17
example uh I have out of the Shelf vpm
1:05:17
example uh I have out of the Shelf vpm connection that is uh that is uh
1:05:20
connection that is uh that is uh
1:05:20
connection that is uh that is uh established I notify that sometimes I'm
1:05:23
established I notify that sometimes I'm
1:05:23
established I notify that sometimes I'm I'm based in Romania I'm based in K but
1:05:25
I'm based in Romania I'm based in K but
1:05:25
I'm based in Romania I'm based in K but some times I go through out through
1:05:28
some times I go through out through
1:05:28
some times I go through out through buchar but sometimes I'm going through
1:05:31
buchar but sometimes I'm going through
1:05:31
buchar but sometimes I'm going through Amsterdam out so even with jaw blocking
1:05:35
Amsterdam out so even with jaw blocking
1:05:35
Amsterdam out so even with jaw blocking there might be sometimes um some false
1:05:41
alarms okay thank you and then we have a
1:05:45
alarms okay thank you and then we have a
1:05:45
alarms okay thank you and then we have a question here from Vladimir who says how
1:05:48
question here from Vladimir who says how
1:05:48
question here from Vladimir who says how can I configure assure API management to
1:05:51
can I configure assure API management to
1:05:51
can I configure assure API management to prevent Doos attacks and secure against
1:05:55
prevent Doos attacks and secure against
1:05:55
prevent Doos attacks and secure against other common API Gateway threats does
1:05:58
other common API Gateway threats does
1:05:58
other common API Gateway threats does API API management have security tools
1:06:01
API API management have security tools
1:06:01
API API management have security tools turned on by
1:06:03
turned on by
1:06:03
turned on by default so by default if you're talking
1:06:06
default so by default if you're talking
1:06:06
default so by default if you're talking about API
1:06:08
about API
1:06:08
about API management that Microsoft is providing
1:06:10
management that Microsoft is providing
1:06:11
management that Microsoft is providing you don't have the do
1:06:13
you don't have the do
1:06:13
you don't have the do protection you have some uh you can
1:06:16
protection you have some uh you can
1:06:16
protection you have some uh you can Define inside API
1:06:18
Define inside API
1:06:18
Define inside API management
1:06:20
management
1:06:20
management some rate limit meaning more or less the
1:06:25
some rate limit meaning more or less the
1:06:25
some rate limit meaning more or less the number of that are accepted in a
1:06:27
number of that are accepted in a
1:06:27
number of that are accepted in a specific time interval in a specific uh
1:06:30
specific time interval in a specific uh
1:06:30
specific time interval in a specific uh time time window but uh nothing more
1:06:34
time time window but uh nothing more
1:06:34
time time window but uh nothing more than that if you want to protect you you
1:06:36
than that if you want to protect you you
1:06:36
than that if you want to protect you you can have an approach like as I I I said
1:06:39
can have an approach like as I I I said
1:06:39
can have an approach like as I I I said in the previous question like
1:06:41
in the previous question like
1:06:41
in the previous question like blacklisting or wh listing dice that
1:06:44
blacklisting or wh listing dice that
1:06:44
blacklisting or wh listing dice that sometimes might be a solution depend if
1:06:46
sometimes might be a solution depend if
1:06:46
sometimes might be a solution depend if it's a B2B or b2c if it's a B2B IP white
1:06:50
it's a B2B or b2c if it's a B2B IP white
1:06:50
it's a B2B or b2c if it's a B2B IP white listing usually works pretty well but if
1:06:54
listing usually works pretty well but if
1:06:54
listing usually works pretty well but if you really need that d
1:06:56
you really need that d
1:06:56
you really need that d protection then you would need to enable
1:06:59
protection then you would need to enable
1:06:59
protection then you would need to enable Azure D do protection Ser service that
1:07:03
Azure D do protection Ser service that
1:07:03
Azure D do protection Ser service that it's and why because API Gateway it's
1:07:07
it's and why because API Gateway it's
1:07:07
it's and why because API Gateway it's about layer seven but it's not DS
1:07:10
about layer seven but it's not DS
1:07:10
about layer seven but it's not DS protection Azure DS protection comes
1:07:12
protection Azure DS protection comes
1:07:12
protection Azure DS protection comes with layer three protection level four
1:07:16
with layer three protection level four
1:07:16
with layer three protection level four and level seven so you already have
1:07:18
and level seven so you already have
1:07:18
and level seven so you already have protection for Doos attacks on layer
1:07:20
protection for Doos attacks on layer
1:07:20
protection for Doos attacks on layer three on at the packaging you have a
1:07:23
three on at the packaging you have a
1:07:23
three on at the packaging you have a layer four at the at the transport and
1:07:25
layer four at the at the transport and
1:07:25
layer four at the at the transport and layer seven so I would say the best way
1:07:28
layer seven so I would say the best way
1:07:28
layer seven so I would say the best way is to go with Azure do
1:07:32
protection okay okay and then I think we
1:07:36
protection okay okay and then I think we
1:07:36
protection okay okay and then I think we have the last question here for today
1:07:39
have the last question here for today
1:07:39
have the last question here for today which comes from Michael who says uh
1:07:42
which comes from Michael who says uh
1:07:42
which comes from Michael who says uh when creating virtual networks how would
1:07:44
when creating virtual networks how would
1:07:44
when creating virtual networks how would you segment them into resource
1:07:52
groups okay creating of your how would
1:07:56
groups okay creating of your how would
1:07:56
groups okay creating of your how would you segment them
1:07:58
you segment them
1:07:58
you segment them [Music]
1:07:59
[Music]
1:07:59
[Music] into uh resour group now depends it's
1:08:03
into uh resour group now depends it's
1:08:03
into uh resour group now depends it's not clear from exactly at at what
1:08:05
not clear from exactly at at what
1:08:05
not clear from exactly at at what Michael is referring to uh if you would
1:08:08
Michael is referring to uh if you would
1:08:08
Michael is referring to uh if you would like to segment them for
1:08:11
like to segment them for
1:08:11
like to segment them for example to per environment or per subnet
1:08:17
example to per environment or per subnet
1:08:17
example to per environment or per subnet per sub
1:08:21
per sub
1:08:21
per sub component uh but uh
1:08:27
more or less you should have virtual
1:08:30
more or less you should have virtual
1:08:30
more or less you should have virtual networks for each environment so you
1:08:33
networks for each environment so you
1:08:33
networks for each environment so you shouldn't share uh uh V uh virtual uh
1:08:37
shouldn't share uh uh V uh virtual uh
1:08:37
shouldn't share uh uh V uh virtual uh Network for the same uh
1:08:40
Network for the same uh
1:08:40
Network for the same uh environment uh there's sometimes depends
1:08:43
environment uh there's sometimes depends
1:08:43
environment uh there's sometimes depends on the size and I will say about
1:08:45
on the size and I will say about
1:08:45
on the size and I will say about policies if you should have subnets or
1:08:48
policies if you should have subnets or
1:08:48
policies if you should have subnets or different v-ets for each applications
1:08:51
different v-ets for each applications
1:08:51
different v-ets for each applications it's something that you might uh discuss
1:08:56
it's something that you might uh discuss
1:08:56
it's something that you might uh discuss but the standard approach is to have a
1:08:58
but the standard approach is to have a
1:08:58
but the standard approach is to have a vnet per each
1:09:01
vnet per each
1:09:01
vnet per each application um something that needs to
1:09:03
application um something that needs to
1:09:03
application um something that needs to be considered here more
1:09:05
be considered here more
1:09:05
be considered here more important is to take a look on hubs
1:09:09
important is to take a look on hubs
1:09:09
important is to take a look on hubs spoke top topology and I think the hubs
1:09:12
spoke top topology and I think the hubs
1:09:12
spoke top topology and I think the hubs spoke topology uh and what is referring
1:09:14
spoke topology uh and what is referring
1:09:14
spoke topology uh and what is referring The Hub hubs spoke topology is
1:09:19
The Hub hubs spoke topology is
1:09:19
The Hub hubs spoke topology is uh ensuring that you have only one Hub
1:09:22
uh ensuring that you have only one Hub
1:09:22
uh ensuring that you have only one Hub where all the communication from the
1:09:24
where all the communication from the
1:09:24
where all the communication from the internet your application goes through
1:09:26
internet your application goes through
1:09:26
internet your application goes through that Hub ensuring you that you can audit
1:09:29
that Hub ensuring you that you can audit
1:09:29
that Hub ensuring you that you can audit you can control you have some security V
1:09:31
you can control you have some security V
1:09:31
you can control you have some security V Appliance in only one location and also
1:09:34
Appliance in only one location and also
1:09:34
Appliance in only one location and also each spoke you can imagine that is a
1:09:35
each spoke you can imagine that is a
1:09:35
each spoke you can imagine that is a different application and the
1:09:37
different application and the
1:09:37
different application and the communication between two between two
1:09:39
communication between two between two
1:09:40
communication between two between two application between two spokes all the
1:09:42
application between two spokes all the
1:09:42
application between two spokes all the timers will go through this Hub to be
1:09:44
timers will go through this Hub to be
1:09:44
timers will go through this Hub to be able to monitor control and so on if you
1:09:47
able to monitor control and so on if you
1:09:47
able to monitor control and so on if you apply Hub spoke topology that you
1:09:50
apply Hub spoke topology that you
1:09:50
apply Hub spoke topology that you usually is used in large Enterprise
1:09:52
usually is used in large Enterprise
1:09:52
usually is used in large Enterprise solution then you end up with a
1:09:55
solution then you end up with a
1:09:55
solution then you end up with a conclusion and this is I this is how I
1:09:57
conclusion and this is I this is how I
1:09:57
conclusion and this is I this is how I would recommend that each application
1:09:59
would recommend that each application
1:09:59
would recommend that each application should have a different virtual
1:10:04
Network I think that in around 95% of
1:10:09
Network I think that in around 95% of
1:10:09
Network I think that in around 95% of the cases this would not affect the
1:10:15
performance there might be some narrow
1:10:17
performance there might be some narrow
1:10:17
performance there might be some narrow cases where you have very very very
1:10:20
cases where you have very very very
1:10:20
cases where you have very very very Chetty systems but there might be some
1:10:23
Chetty systems but there might be some
1:10:23
Chetty systems but there might be some exception where you want to applications
1:10:26
exception where you want to applications
1:10:26
exception where you want to applications or multiplayer application to stay in
1:10:28
or multiplayer application to stay in
1:10:28
or multiplayer application to stay in the same V I'm just thinking about uh
1:10:32
the same V I'm just thinking about uh
1:10:32
the same V I'm just thinking about uh stock market
1:10:33
stock market
1:10:33
stock market applications that might be that that
1:10:37
applications that might be that that
1:10:37
applications that might be that that narrow case but in general vnet per
1:10:40
narrow case but in general vnet per
1:10:40
narrow case but in general vnet per application and all the time have don't
1:10:44
application and all the time have don't
1:10:44
application and all the time have don't mix the environments under the same
1:10:50
vet yes I think maybe that goes into his
1:10:52
vet yes I think maybe that goes into his
1:10:53
vet yes I think maybe that goes into his followup question he said that instead
1:10:55
followup question he said that instead
1:10:55
followup question he said that instead of creating a v Network into a separate
1:10:57
of creating a v Network into a separate
1:10:57
of creating a v Network into a separate Resource Group but instead having the
1:10:59
Resource Group but instead having the
1:11:00
Resource Group but instead having the vet inside the dev test and prod
1:11:02
vet inside the dev test and prod
1:11:02
vet inside the dev test and prod resource
1:11:15
[Music]
1:11:20
groups uh
1:11:25
as for vnet I personally I consider that
1:11:29
as for vnet I personally I consider that
1:11:29
as for vnet I personally I consider that that you should have different res group
1:11:30
that you should have different res group
1:11:31
that you should have different res group for each
1:11:32
for each
1:11:32
for each uh uh for each environment but uh vet
1:11:37
uh uh for each environment but uh vet
1:11:37
uh uh for each environment but uh vet and Resource Group even if allow you so
1:11:41
and Resource Group even if allow you so
1:11:41
and Resource Group even if allow you so Resource Group are more virtual grouping
1:11:44
Resource Group are more virtual grouping
1:11:44
Resource Group are more virtual grouping of resources that give you the virtual
1:11:47
of resources that give you the virtual
1:11:47
of resources that give you the virtual view of uh of
1:11:50
view of uh of
1:11:50
view of uh of grouping when you talk about vnet is
1:11:53
grouping when you talk about vnet is
1:11:53
grouping when you talk about vnet is more close to physical because you're
1:11:55
more close to physical because you're
1:11:55
more close to physical because you're connecting some aure services to uh to
1:12:01
connecting some aure services to uh to
1:12:01
connecting some aure services to uh to vet and also the resour group themselves
1:12:04
vet and also the resour group themselves
1:12:04
vet and also the resour group themselves should be separately and yes you could
1:12:07
should be separately and yes you could
1:12:07
should be separately and yes you could have multiple resour group under the
1:12:09
have multiple resour group under the
1:12:09
have multiple resour group under the same
1:12:10
same
1:12:10
same vet this can this can be done you could
1:12:14
vet this can this can be done you could
1:12:14
vet this can this can be done you could in this way you could say that under a
1:12:16
in this way you could say that under a
1:12:16
in this way you could say that under a vnet you can you can have different
1:12:18
vnet you can you can have different
1:12:18
vnet you can you can have different resour group for each
1:12:20
resour group for each
1:12:20
resour group for each environment uh initially might be easily
1:12:22
environment uh initially might be easily
1:12:22
environment uh initially might be easily to implement
1:12:25
to implement
1:12:25
to implement but I would keep them as different V so
1:12:29
but I would keep them as different V so
1:12:29
but I would keep them as different V so I I wouldn't go on that approach
1:12:35
sorry excuse me to have um to mix the
1:12:40
sorry excuse me to have um to mix the
1:12:40
sorry excuse me to have um to mix the same v-net under multiple RIS group
1:12:43
same v-net under multiple RIS group
1:12:43
same v-net under multiple RIS group especially
1:12:45
especially
1:12:45
especially because I'm uh thinking and uh consider
1:12:50
because I'm uh thinking and uh consider
1:12:50
because I'm uh thinking and uh consider how also you manage the access
1:12:52
how also you manage the access
1:12:52
how also you manage the access control and if something goes
1:12:56
control and if something goes
1:12:56
control and if something goes uh not as expected in Access Control
1:12:58
uh not as expected in Access Control
1:12:59
uh not as expected in Access Control Management of the technical people you
1:13:00
Management of the technical people you
1:13:00
Management of the technical people you can end up without knowing that somebody
1:13:03
can end up without knowing that somebody
1:13:03
can end up without knowing that somebody would have access to prod prod
1:13:06
would have access to prod prod
1:13:06
would have access to prod prod environment or some some data from the
1:13:08
environment or some some data from the
1:13:08
environment or some some data from the prod
1:13:12
environment okay thank you thank you so
1:13:16
environment okay thank you thank you so
1:13:16
environment okay thank you thank you so much we also have some uh messages Kate
1:13:20
much we also have some uh messages Kate
1:13:20
much we also have some uh messages Kate says thank you for answering her
1:13:23
says thank you for answering her
1:13:23
says thank you for answering her question Vladimir thank you so much for
1:13:25
question Vladimir thank you so much for
1:13:25
question Vladimir thank you so much for your
1:13:26
your
1:13:26
your answer and also from Jonah
1:13:30
answer and also from Jonah
1:13:30
answer and also from Jonah here and uh um but before we close this
1:13:34
here and uh um but before we close this
1:13:34
here and uh um but before we close this stream I would also like to share some
1:13:37
stream I would also like to share some
1:13:37
stream I would also like to share some resources that I think can be uh very
1:13:40
resources that I think can be uh very
1:13:40
resources that I think can be uh very valuable for uh for everyone so the
1:13:44
valuable for uh for everyone so the
1:13:44
valuable for uh for everyone so the First Resource that I would like to
1:13:45
First Resource that I would like to
1:13:45
First Resource that I would like to share is um is an article here that that
1:13:51
share is um is an article here that that
1:13:51
share is um is an article here that that you gave us here Ru which is this one
1:14:01
uh so this is an article that gives you
1:14:03
uh so this is an article that gives you
1:14:03
uh so this is an article that gives you a very good overview on what you should
1:14:05
a very good overview on what you should
1:14:05
a very good overview on what you should think about when you develop secure
1:14:07
think about when you develop secure
1:14:08
think about when you develop secure applications here on on Asher but we
1:14:11
applications here on on Asher but we
1:14:11
applications here on on Asher but we also have some other free some other uh
1:14:13
also have some other free some other uh
1:14:13
also have some other free some other uh resources here so one of the things that
1:14:16
resources here so one of the things that
1:14:16
resources here so one of the things that I would like to emphasize here is that
1:14:18
I would like to emphasize here is that
1:14:18
I would like to emphasize here is that there's a lot of training material for
1:14:20
there's a lot of training material for
1:14:20
there's a lot of training material for free on Microsoft laar so one of them is
1:14:24
free on Microsoft laar so one of them is
1:14:24
free on Microsoft laar so one of them is this re
1:14:28
Source Just sh
1:14:34
this so this is um this is actually a
1:14:38
this so this is um this is actually a
1:14:38
this so this is um this is actually a training resource here for
1:14:41
training resource here for
1:14:41
training resource here for um this uh security fundamentals exam
1:14:46
um this uh security fundamentals exam
1:14:46
um this uh security fundamentals exam and uh there is an
1:14:49
and uh there is an
1:14:49
and uh there is an Associated uh learning path which is for
1:14:52
Associated uh learning path which is for
1:14:52
Associated uh learning path which is for free so the certification is not for
1:14:54
free so the certification is not for
1:14:54
free so the certification is not for free but the training the train for it
1:14:56
free but the training the train for it
1:14:56
free but the training the train for it that's for free so I encourage everyone
1:14:59
that's for free so I encourage everyone
1:14:59
that's for free so I encourage everyone who's interested to look into into
1:15:03
who's interested to look into into
1:15:03
who's interested to look into into that um and in the same way we also have
1:15:06
that um and in the same way we also have
1:15:06
that um and in the same way we also have another resource here
1:15:09
another resource here
1:15:09
another resource here for let me just
1:15:21
copy so this is the same um same setup
1:15:24
copy so this is the same um same setup
1:15:24
copy so this is the same um same setup here but this is for the aser security
1:15:27
here but this is for the aser security
1:15:27
here but this is for the aser security engineer
1:15:29
engineer
1:15:30
engineer certification and we also have a third
1:15:32
certification and we also have a third
1:15:32
certification and we also have a third one here for the cyber security
1:15:35
one here for the cyber security
1:15:35
one here for the cyber security architecture expert
1:15:46
exam uh which is this
1:15:50
one but in in addition to that uh
1:15:54
one but in in addition to that uh
1:15:54
one but in in addition to that uh Microsoft has also something they called
1:15:56
Microsoft has also something they called
1:15:56
Microsoft has also something they called apply uh skills so the applied skills
1:15:59
apply uh skills so the applied skills
1:15:59
apply uh skills so the applied skills they are an exam which is for free but
1:16:02
they are an exam which is for free but
1:16:02
they are an exam which is for free but they also have a training training
1:16:04
they also have a training training
1:16:04
they also have a training training learning path which is also for free so
1:16:08
learning path which is also for free so
1:16:08
learning path which is also for free so um so I'm going to share two links here
1:16:12
um so I'm going to share two links here
1:16:12
um so I'm going to share two links here um the first one
1:16:14
um the first one
1:16:14
um the first one is for using the uh um Microsoft uh
1:16:23
Sentinel which is this
1:16:26
Sentinel which is this
1:16:27
Sentinel which is this one and then the last one is how you can
1:16:32
one and then the last one is how you can
1:16:32
one and then the last one is how you can how you can secure your services and
1:16:34
how you can secure your services and
1:16:34
how you can secure your services and work dos with Microsoft
1:16:38
Defender and that's this link
1:16:47
here yeah yeah so security is a very
1:16:50
here yeah yeah so security is a very
1:16:50
here yeah yeah so security is a very important topic so I think I hope you
1:16:52
important topic so I think I hope you
1:16:52
important topic so I think I hope you will find these links valuable here
1:16:55
will find these links valuable here
1:16:55
will find these links valuable here um so with that said uh I would like to
1:16:59
um so with that said uh I would like to
1:16:59
um so with that said uh I would like to thank all of you and please join our F
1:17:02
thank all of you and please join our F
1:17:02
thank all of you and please join our F now that we will start as soon as we
1:17:04
now that we will start as soon as we
1:17:04
now that we will start as soon as we finish uh this stream here so you can
1:17:07
finish uh this stream here so you can
1:17:07
finish uh this stream here so you can just scan this QR code to join me and Ru
1:17:10
just scan this QR code to join me and Ru
1:17:10
just scan this QR code to join me and Ru here so do you have any finally final um
1:17:15
here so do you have any finally final um
1:17:15
here so do you have any finally final um comments um
1:17:19
Ru before we
1:17:22
Ru before we
1:17:22
Ru before we finish um no just just one more time
1:17:25
finish um no just just one more time
1:17:25
finish um no just just one more time thank you thank you for joining the
1:17:27
thank you thank you for joining the
1:17:27
thank you thank you for joining the session feel free to reach me on
1:17:29
session feel free to reach me on
1:17:29
session feel free to reach me on LinkedIn if you would like to have a
1:17:30
LinkedIn if you would like to have a
1:17:30
LinkedIn if you would like to have a chat or to
1:17:33
chat or to
1:17:33
chat or to change
1:17:35
change
1:17:35
change uh different ideas and aspects because
1:17:38
uh different ideas and aspects because
1:17:38
uh different ideas and aspects because as we saw in the question there are
1:17:40
as we saw in the question there are
1:17:40
as we saw in the question there are multiple ways how you can solve a
1:17:42
multiple ways how you can solve a
1:17:42
multiple ways how you can solve a problem they're not wrong or wrong
1:17:45
problem they're not wrong or wrong
1:17:45
problem they're not wrong or wrong approaches it's a lot about about the
1:17:47
approaches it's a lot about about the
1:17:47
approaches it's a lot about about the context on what kind of skills you have
1:17:50
context on what kind of skills you have
1:17:50
context on what kind of skills you have available and time and time and budget
1:17:54
available and time and time and budget
1:17:54
available and time and time and budget and I would like to to learn more from
1:17:55
and I would like to to learn more from
1:17:55
and I would like to to learn more from you and from what are the other ways how
1:17:59
you and from what are the other ways how
1:17:59
you and from what are the other ways how you solve your day-to-day security
1:18:03
you solve your day-to-day security
1:18:03
you solve your day-to-day security problems from
1:18:05
problems from
1:18:05
problems from Asia y yeah so thank you so much and and
1:18:10
Asia y yeah so thank you so much and and
1:18:10
Asia y yeah so thank you so much and and see you in our next uh session here have
1:18:13
see you in our next uh session here have
1:18:13
see you in our next uh session here have a good weekend
1:18:16
a good weekend
1:18:16
a good weekend [Music]
1:18:28
[Music]
1:18:28
[Music] so
1:18:32
[Music]


