
Cloud Attack Vectors: Building Effective Cyber-Defense Strategies to Protect Cloud Resources
Morey J. Haber, Brian Chappell, Christopher HillsIntroduction
Chapter 1. Cloud Computing
Software as a Service
Platform as a Service
Infrastructure as a Service
Function as a Service
X as a ServiceDesktop as a Service
Data Center as a Service
Managed Software as a ServiceBackend as a Service
Chapter 2. Cloud Providers
Amazon Web ServicesMicrosoft Azure
Google Cloud Platform
Oracle Cloud
Alibaba
Other Services
Chapter 3. Cloud Definitions
Identities
Accounts
Entitlements
Privileges
Rights
Permissions
Containers
SegmentationMicrosegmentation
Instances
Chapter 4. Asset Management
Discovery
Chapter 5. Attack Vectors
EntitlementsVulnerabilities
Hardening
Configurations
Credentials
S3 Buckets
Identities
Entitlements
API
Authentication
Certificates
PhishingRemote Access
Supply Chain - 3rd Party MSP/MSSP
Chapter 6. Mitigations
Hardening
Patch Management
PAM
CIEM
CIAM
CWPP
Chapter 7. Regulatory Compliance
Security Questionnaires
SOC
Type I
Type II
Type III
Cloud Security Alliance
CCMCAIQ
CIS Controls
PCI DSS
ISO
NIST
FedRamp
Chapter 8. Architectures
Zero Trust
Cloud-Native
HybridEphemeral Implementations
Accounts
Instances
Privileges
Chapter 9. Imposter Syndrome
Chapter 10. Recommendations
Chapter 11. Conclusion
Binding Type: Paperback
Publisher: Apress
Published: 10/31/2022
ISBN: 9781484282359
Pages: 280
Weight: 1.55lbs
Size: 9.21h x 6.14w x 1.02d
