Chapter 11. Cloud Security Emerging Trends
Topics covered in this chapter include:
-
Cloud native security
-
Emerging identity and access management
-
Zero trust architecture
-
AI/ML in cloud security
Migrating compute and storage services to cloud providers, effectively outsourcing them, triggered significant changes in the way applications are developed and offered. This was, in part, because of the focus of resources by cloud providers that needed to ensure there would be services to offer their customers. This meant resources developing services that wouldn’t normally be available because most organizations are focused on their own businesses. The same ends up being true for security offerings. Cloud providers must have services to provide their customers, and since application delivery can be different in the cloud than on premises, the way those applications and the data are protected can be different.
While fundamentals remain the same—following the NIST Cybersecurity Framework to ensure you have the right capabilities in place, for instance, and ensuring you have adequate visibility—how you protect and get that visibility may be different. The fact that cloud native services may be ephemeral requires some additional planning to ensure essential information isn’t lost. Security controls for cloud native implementations can be different from on premises, and they are continuing to evolve as more services are offered.
Other changes in protection are based on how our understanding ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access