Guest:

Elliott Abraham, Security and Compliance Specialist @ Google Cloud

Topics:

We talk about lift and shift vs cloud native, what are these and are they fair characterizations? Is lift and shift always negative? Does it always harm security? Are security planning needs different between them? What are the fundamentals with security during cloud migration that you have to get right regardless? What’s your advice to a security team to help make a migration work well? How do you account for threat model differences in the cloud? Are cloud threats being more different or more the same to the classic ones?

Resources:

“Google Cloud security foundations guide” "The Phoenix Project" book "Threat Models and Cloud Security" (ep12) "Preparing for Cloud Migrations from a CISO Perspective"  Part 1 (ep5) and Part2 (ep11)