AN OSINT APPROACH TO THIRD PARTY CLOUD SERVICE PROVIDER EVALUATION

By Lokesh Pidawekar on 10 Aug 2018 @ Defcon : Packethacking Village
📊 Presentation 📹 Video 🔗 Link
third-party-risk-management cloud-security vulnerability-management supply-chain vendor-security
Focus Areas: Software Supply Chain Security , Vulnerability Management

Presentation Material

AI Generated Summary (may contain errors)

Here is a summarized version of the content:

The speaker discussed the challenges faced during a questionnaire-based process to assess cloud providers. To overcome these challenges, they proposed an approach that involves continuous monitoring of cloud providers through automated tools, which can provide valuable insights for making decisions, as well as ensuring consistency in security measures.

Some benefits of this approach include:

However, there are also some drawbacks, such as:

The speaker is currently working on modeling and prototyping a dashboard to rate individual resources with accurate results. They invited feedback and ideas from the audience to improve this process.

In summary, the proposed solution aims to provide quick results for assessing cloud providers’ security, which can be integrated into current processes to expedite decision-making. The ultimate goal is to have a common platform to share information about various cloud providers and bring most cloud services to an acceptable level of security through sharing this information.