Episode 48: Nobody Gets Rid of Anything, Including Data

Published: Feb. 13, 2019, 6 a.m.

b'Companies can find working in the Cloud quite complicated. However, it\\u2019s a lot easier than it used to be, especially when trying to comply with regulations. That\\u2019s because Cloud providers have evolved and now offer more out-of-the-box services that focus on regulation requirements and compliance.\\nToday, we\\u2019re talking to Elliot Murphy. He\\u2019s the founder of Kindly Ops, which provides consulting advice to companies dealing with regulated workloads in the Cloud.\\nSome of the highlights of the show include:\\n\\nTechnical controls are easier, but requirements are stricter\\nRisk Analysis: Putting locks on things to thinking about risks to customers\\nBuilding governance and controls; making data available and removable \\nSecondary Losses: Scrub services to make scope and magnitude of loss smaller\\nComputing became ubiquitous and affordable; people started collecting data to utilize later - nobody gets rid of anything \\nGeneral Data Protection Regulation (GDPR) set of regulations apply to marketing technology stacks to manage systems\\nEmpathy building exercise and security culture diagnostic help companies understand compliance obligations\\nSecurity Culture: Beliefs and assumptions that drive decisions and actions\\nEvolution of understanding with public Cloud\\u2019s security and availability\\nRaise the bar and shift mindset from pure prevention to early detection/ mitigation; follow FAIR (factor analysis of information risk)\\n\\nLinks:\\n\\nKindly Ops\\nAmazon Web Services (AWS)\\nMicrosoft Azure\\nRelational Database Service (RDS)\\nGoogle Cloud Platform (GCP)\\nNist Cybersecurity Framework\\nGDPR Day\\nPeople-Centric Security by Lance Hayden\\nStripe\\nSociety of Information Risk Analysts (SIRA)\\nDigitalOcean'