AN OSINT APPROACH TO THIRD PARTY CLOUD SERVICE PROVIDER EVALUATION

By Lokesh Pidawekar on 10 Aug 2018 @ Defcon : Packethacking Village
πŸ“Š Presentation πŸ“Ή Video πŸ”— Link
#third-party-risk-management #supply-chain #vendor-security
Focus Areas: πŸ“¦ Software Supply Chain Security

Presentation Material

AI Generated Summary

Here is a summarized version of the content:

The speaker discussed the challenges faced during a questionnaire-based process to assess cloud providers. To overcome these challenges, they proposed an approach that involves continuous monitoring of cloud providers through automated tools, which can provide valuable insights for making decisions, as well as ensuring consistency in security measures.

Some benefits of this approach include:

  • Ability to make informed decisions about partnerships and acquisitions
  • Consistency in product design and security from an outsider’s perspective

However, there are also some drawbacks, such as:

  • Noise and false positives
  • Limited information that may not satisfy all questions
  • Need for enterprises to invest resources in building a solution or buying one

The speaker is currently working on modeling and prototyping a dashboard to rate individual resources with accurate results. They invited feedback and ideas from the audience to improve this process.

In summary, the proposed solution aims to provide quick results for assessing cloud providers’ security, which can be integrated into current processes to expedite decision-making. The ultimate goal is to have a common platform to share information about various cloud providers and bring most cloud services to an acceptable level of security through sharing this information.

Disclaimer: This summary was auto-generated from the video transcript using AI and may contain inaccuracies. It is intended as a quick overview β€” always refer to the original talk for authoritative content. Learn more about our AI experiments.