با معماری در حال تغییر سریع و اتوماسیون مبتنی بر API، پلتفرمهای ابری چالشها و فرصتهای امنیتی منحصر به فردی را به همراه دارند. در این ویرایش دوم بهروز شده، بهترین شیوههای امنیتی را برای محیطهای ابری چندفروشندهای بررسی خواهید کرد، چه شرکت شما قصد داشته باشد پروژههای قدیمی داخلی را به ابر منتقل کند یا زیرساخت جدیدی را از ابتدا بسازد. توسعهدهندگان، معماران IT و متخصصان امنیت، تکنیکهای خاص ابری را برای ایمنسازی پلتفرمهای ابری محبوب مانند خدمات وب آمازون (Amazon Web Services)، مایکروسافت آژور (Microsoft Azure) و IBM Cloud یاد خواهند گرفت. کریس داتسون، مهندس برجسته IBM، به شما نشان میدهد که چگونه مدیریت دارایی داده، مدیریت هویت و دسترسی (IAM)، مدیریت آسیبپذیری، امنیت شبکه و پاسخ به حوادث را در محیط ابری خود ایجاد کنید. * جدیدترین تهدیدات و چالشها در فضای امنیت ابری را بیاموزید. * ارائهدهندگان ابری که دادهها را ذخیره یا پردازش میکنند یا کنترل مدیریتی را ارائه میدهند، مدیریت کنید. * بیاموزید که چگونه اصول و مفاهیم استاندارد—مانند حداقل امتیاز (Least Privilege) و دفاع عمیق (Defense in Depth)—در ابر اعمال میشوند. * نقش حیاتی IAM را در ابر درک کنید. * بهترین تاکتیکها را برای شناسایی، پاسخ و بازیابی از رایجترین حوادث امنیتی به کار ببرید. * انواع مختلف آسیبپذیریها، به ویژه آنهایی که در معماریهای چندابری (Multicloud) یا ابری ترکیبی (Hybrid Cloud) رایج هستند، مدیریت کنید. * مدیریت دسترسی ممتاز (Privileged Access Management) را در محیطهای ابری بررسی کنید.
اشتراکی

با مرور فصلها، ساختار ، محتوای کتاب را به سرعت بشناسید.
با مرور فصلهای این کتاب میتونی خیلی سریع بفهمی هر بخش چی یاد میده، ساختار کلی چطوره و از کجا باید شروع کنی. هر فصل روی یک مفهوم یا مهارت خاص تمرکز داره و موضوعات اصلیش رو میبینی تا انتخابت آگاهانهتر باشه. چه بخوای کل کتاب رو دنبال کنی، چه فقط یک بخش خاص رو دنبال کنی، این نما کمکت میکنه مسیرت رو پیدا کنی.

اصول و مفاهیم
Least Privilege • Defense in Depth • Zero Trust • Threat Actors, Diagrams, and Trust Boundaries • Cloud Service Delivery Models • The Cloud Shared Responsibility Model • Risk Management • Conclusion • Exercises
درحال تولید...

مدیریت و حفاظت از دارایی داده
Data Identification and Classification • Example Data Classification Levels • Relevant Industry or Regulatory Requirements • Data Asset Management in the Cloud • Tagging Cloud Resources • Protecting Data in the Cloud • Tokenization • Encryption • Conclusion • Exercises
درحال تولید...

مدیریت و حفاظت از دارایی ابری
Differences from Traditional IT • Types of Cloud Assets • Compute Assets • Storage Assets • Network Assets • Asset Management Pipeline • Procurement Leaks • Processing Leaks • Tooling Leaks • Findings Leaks • Tagging Cloud Assets • Conclusion • Exercises
درحال تولید...

مدیریت هویت و دسترسی
Differences from Traditional IT • Life Cycle for Identity and Access • Request • Approve • Create, Delete, Grant, or Revoke • Authentication • Cloud IAM Identities • Business-to-Consumer and Business-to-Employee • Multi-Factor Authentication • Passwords, Passphrases, and API Keys • Shared IDs • Federated Identity • Single Sign-On • Instance Metadata and Identity Documents • Secrets Management • Authorization • Centralized Authorization • Roles • Revalidate • Putting It All Together in the Sample Application • Conclusion • Exercises
درحال تولید...

مدیریت آسیبپذیری
Differences from Traditional IT • Vulnerable Areas • Data Access • Application • Middleware • Operating System • Network • Virtualized Infrastructure • Physical Infrastructure • Finding and Fixing Vulnerabilities • Network Vulnerability Scanners • Agentless Scanners and Configuration Management Systems • Agent-Based Scanners and Configuration Management Systems • Cloud Workload Protection Platforms • Container Scanners • Dynamic Application Scanners (DAST) • Static Application Scanners (SAST) • Software Composition Analysis Tools (SCA) • Interactive Application Scanners (IAST) • Runtime Application Self-Protection Scanners (RASP) • Manual Code Reviews • Penetration Tests • User Reports • Example Tools for Vulnerability and Configuration Management • Risk Management Processes • Vulnerability Management Metrics • Tool Coverage • Mean Time to Remediate • Systems/Applications with Open Vulnerabilities • Percentage of False Positives • Percentage of False Negatives • Vulnerability Recurrence Rate • Change Management • Putting It All Together in the Sample Application • Conclusion • Exercises
درحال تولید...

امنیت شبکه
Differences from Traditional IT • Concepts and Definitions • Zero Trust Networking • Allowlists and Denylists • DMZs • Proxies • Software-Defined Networking • Network Functions Virtualization • Overlay Networks and Encapsulation • Virtual Private Clouds • Network Address Translation • IPv6 • Network Defense in Action in the Sample Application • Encryption in Motion • Firewalls and Network Segmentation • Allowing Administrative Access • Network Defense Tools • Egress Filtering • Data Loss Prevention • Conclusion • Exercises
درحال تولید...

شناسایی، پاسخ و بازیابی از حوادث امنیتی
Differences from Traditional IT • What to Watch • Privileged User Access • Logs from Defensive Tooling • Cloud Service Logs and Metrics • Operating System Logs and Metrics • Middleware Logs • Secrets Server • Your Application • How to Watch • Aggregation and Retention • Parsing Logs • Searching and Correlation • Alerting and Automated Response • Security Information and Event Managers • Threat Hunting • Preparing for an Incident • Team • Plans • Tools • Responding to an Incident • Cyber Kill Chains and MITRE ATT&CK • The OODA Loop • Cloud Forensics • Blocking Unauthorized Access • Stopping Data Exfiltration and Command and Control • Recovery • Redeploying IT Systems • Notifications • Lessons Learned • Example Metrics • Example Tools for Detection, Response, and Recovery • Detection and Response in a Sample Application • Monitoring the Protective Systems • Monitoring the Application • Monitoring the Administrators • Understanding the Auditing Infrastructure • Conclusion • Exercises
درحال تولید...
7 فصل در حال تولید
مدت زمان خوانش
6:47
نوع کتاب
اشتراکی
شرکت کنندگان
0 نفر
تولید کتاب
۳۱ شهریور ۱۴۰۵