Chapter 8: Understanding Common Security Threats to Cloud Services
In Chapters 2-7, we covered the fundamental building blocks of securing cloud services (including services for compute, storage, networking, identity and access management (IAM), auditing, threat management, and incident response), as well as looking at encryption for cloud services.
This chapter will cover the other side of the equation: common security threats to cloud services. We will also consider how to mitigate these threats.
Knowing the threats your organization faces when using cloud services will give you an understanding of what to look for and how to better protect your cloud environments in advance. Getting hacked is more a question of when rather than if, so the knowledge presented in this chapter should help you to be prepared for such an eventuality.
In this chapter, we will cover the following topics:
- The MITRE ATT&CK framework
- Detecting and mitigating data breaches in cloud...