<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="https://publishpress.com/"
	>

<channel>
	<title>Brandon J Carroll</title>
	<atom:link href="http://brandonjcarroll.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://brandonjcarroll.com/</link>
	<description>Developer Advocate &#124; CCIES #23837 &#124; Security Specialist</description>
	<lastBuildDate>Mon, 21 Oct 2024 17:10:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
<site xmlns="com-wordpress:feed-additions:1">22555084</site>	<item>
		<title>Simplifying Cloud Security for Non-Tech Stakeholders</title>
		<link>https://brandonjcarroll.com/simplifying-cloud-security-for-non-tech-stakeholders/</link>
					<comments>https://brandonjcarroll.com/simplifying-cloud-security-for-non-tech-stakeholders/#respond</comments>
		
		<dc:creator><![CDATA[Brandon Carroll]]></dc:creator>
		<pubDate>Mon, 21 Oct 2024 17:09:57 +0000</pubDate>
				<category><![CDATA[Communication Skills]]></category>
		<category><![CDATA[Career Advice]]></category>
		<category><![CDATA[Professional Development]]></category>
		<category><![CDATA[Cloud Security]]></category>
		<category><![CDATA[SoftSkills]]></category>
		<category><![CDATA[CareerGrowth]]></category>
		<category><![CDATA[TechTranslation]]></category>
		<category><![CDATA[CloudSecurity]]></category>
		<guid isPermaLink="false">https://brandonjcarroll.com/?p=19498</guid>

					<description><![CDATA[<p>In cloud security, we often find ourselves using a lot of technical jargon. This language is important for precise communication among peers. Nonetheless, it can be a significant barrier when ...</p>
<p>The post <a href="https://brandonjcarroll.com/simplifying-cloud-security-for-non-tech-stakeholders/">Simplifying Cloud Security for Non-Tech Stakeholders</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="has-black-color has-text-color has-link-color wp-elements-1f2d9625d8574abc5aadad69fa7a4a64">In cloud security, we often find ourselves using a lot of technical jargon. This language is important for precise communication among peers. Nonetheless, it can be a significant barrier when interacting with non-technical stakeholders. Today, let&#8217;s explore how we can bridge this communication gap and enhance our effectiveness as cloud security professionals.</p>



<h2 class="wp-block-heading">The Challenge of Technical Translation</h2>



<p class="has-black-color has-text-color has-link-color wp-elements-ecd6a78b657b7210196e608019704055">As cloud security experts, we&#8217;re accustomed to discussing concepts like &#8220;IAM policies,&#8221; &#8220;VPC peering,&#8221; and &#8220;zero-trust architecture.&#8221; We often face blank stares or confused nods when we use these terms with executives. The same happens with clients or colleagues from other departments. This disconnect can lead to misunderstandings, misaligned priorities, and even security vulnerabilities.</p>



<h2 class="wp-block-heading">The Power of Simplification</h2>



<p class="has-black-color has-text-color has-link-color wp-elements-32fb4ec32bb3d565a877860dad692670">The key to overcoming this challenge lies in our ability to simplify complex ideas without losing their essence. Here&#8217;s a practical approach:</p>



<ol class="wp-block-list">
<li><strong>Find the core concept:</strong> Before you start explaining, distill the technical idea. Focus on its fundamental purpose. Consider its impact. Now that you have that, incorporate step two.</li>



<li><strong>Use analogies:</strong> Draw parallels between the technical concept that you simplified and everyday experiences. These should be experiences your audience can relate to. As you do this, don&#8217;t lose sight of point number three.</li>



<li><strong>Focus on outcomes:</strong> Okay, for this part, you need to emphasize the business impact. Discuss the risk implications rather than the technical details. The business impact or the risk to the business is the language most non-technical folks are going to connect with. It&#8217;s about how your job and the information you convey relate to their job. This connection impacts what they are focused on.</li>



<li><strong>Avoid acronyms:</strong> Finally, spell out any abbreviations unless you&#8217;re 100% certain your audience is familiar with them. Explain these abbreviations that you would use with your peers. Be sure to clarify their meaning. Sometimes they will nod as if they know what it means, but they don&#8217;t. Just explain it, but do so in a way that isn&#8217;t demeaning to the listener. This is something you need to practice.</li>
</ol>



<h2 class="wp-block-heading">Putting It Into Practice</h2>



<p class="has-black-color has-text-color has-link-color wp-elements-db0793dae439569f9b23b738293a7863">Let&#8217;s take a common cloud security concept: Multi-Factor Authentication (MFA). Here&#8217;s how we explain it to a non-technical executive:</p>



<p class="has-black-color has-text-color has-link-color wp-elements-56d765bd875d4cd0261eddd6983cbe7e">&#8220;Imagine your house has a front door with a standard lock. That&#8217;s like a password &#8211; it&#8217;s good, but if someone get past that lock, and opens the door, they&#8217;re in. Multi-Factor Authentication is like adding an alarm system. Now, even if someone gets past the front door, they must enter the code to disarm the alarm. This prevents triggering other security measures. In our cloud systems, this drastically reduces the risk of unauthorized access, even if a password is compromised.&#8221;</p>



<p class="has-black-color has-text-color has-link-color wp-elements-cc4155480d062d8dca617adacad1eae6">Pretty simple right?</p>



<h2 class="wp-block-heading">The Impact of Clear Communication</h2>



<p class="has-black-color has-text-color has-link-color wp-elements-5801a65c1c4392692abc351069da9f17">By giving some extra focus to the art of translating technical concepts, you can:</p>



<ul class="wp-block-list">
<li style="font-style:normal;font-weight:400">Secure buy-in for critical security initiatives more easily</li>



<li style="font-style:normal;font-weight:400">Improve collaboration with non-technical teams</li>



<li style="font-style:normal;font-weight:400">Enhance our professional reputation and influence</li>
</ul>



<h2 class="wp-block-heading">A Challenge for You</h2>



<p class="has-black-color has-text-color has-link-color wp-elements-a6e00291c13d831ad802bf535c4c1f37">I want to leave you with something that you can try and will help you get better at this.  So, this week, try this exercise: </p>



<p class="has-black-color has-text-color has-link-color wp-elements-18580fc9c2dbb0e5092a4b98ff77600e"><strong>Choose a complex cloud security concept you&#8217;re working with. Explain it to a non-technical friend or family member in under two minutes. Ask them to explain it back to you. If they can grasp and articulate the main idea, you&#8217;re on the right track!</strong></p>



<p class="has-black-color has-text-color has-link-color wp-elements-d99869b409ef87bc21ba43b4fa34bf98">Remember, how we communicate can be just as important as what we know. By honing our ability to translate technical terms into clear, relatable language, we become more effective in our roles. This practice also elevates the overall security posture of our organizations.</p>



<p></p>
<p>The post <a href="https://brandonjcarroll.com/simplifying-cloud-security-for-non-tech-stakeholders/">Simplifying Cloud Security for Non-Tech Stakeholders</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://brandonjcarroll.com/simplifying-cloud-security-for-non-tech-stakeholders/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">19498</post-id>	</item>
		<item>
		<title>Securing the Cloud #32</title>
		<link>https://brandonjcarroll.com/securing-the-cloud-32/</link>
					<comments>https://brandonjcarroll.com/securing-the-cloud-32/#respond</comments>
		
		<dc:creator><![CDATA[Brandon Carroll]]></dc:creator>
		<pubDate>Fri, 05 Jul 2024 14:11:08 +0000</pubDate>
				<category><![CDATA[Securing the Cloud Newsletter]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[community]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[career]]></category>
		<guid isPermaLink="false">https://brandonjcarroll.com/?p=19119</guid>

					<description><![CDATA[<p>Welcome to the 32nd edition of the Securing the Cloud Newsletter! In this issue, we dive into the latest trends and insights in cloud security, explore career development opportunities, and ...</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-32/">Securing the Cloud #32</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Welcome to the 32nd edition of the Securing the Cloud Newsletter! In this issue, we dive into the latest trends and insights in cloud security, explore career development opportunities, and share valuable learning resources. Additionally, we feature insightful perspectives from our community members.</p>



<h2 class="wp-block-heading">Technical Topic</h2>



<ul class="wp-block-list">
<li><a href="https://brandonjcarroll.com/links/9gza1">How to securely transfer files with presigned URLs | AWS Security Blog</a> &#8211; Securely sharing large files and private data is critical in today&#8217;s distributed work environments. This article explores how presigned URLs offer a powerful solution by enabling temporary, controlled access to Amazon S3 objects without exposing long-term credentials. It provides prescriptive guidance on best practices for generating and distributing presigned URLs securely, including implementing safeguards against inadvertent data exposure. The article goes into key technical considerations like using unique nonces, access restrictions, and serverless architectures for generating and validating one-time presigned URL access. It even offers a downloadable code sample illustrating how to implement these secure practices. It also emphasizes the importance of governance, continuous monitoring, and automated revocation procedures to maintain effective oversight and control when sharing presigned URLs broadly. By following the guidance outlined in this article, you can unlock the collaborative benefits of presigned URLs while protecting sensitive data. I encourage you to explore the full post to learn how to strike the right balance between secure data sharing and collaborative efficiency using this powerful architectural pattern.</li>
</ul>



<h2 class="wp-block-heading">Career Corner</h2>



<ul class="wp-block-list">
<li><a href="https://www.nwkings.com/cloud-security-engineer-roadmap">Guide to Becoming a Cloud Security Engineer: Roadmap (2024)</a> &#8211; As businesses adopt cloud computing, the role of cloud security engineers has become more important and more sought after. This guide digs into the exciting world of cloud security, exploring the responsibilities, skills, and career path. In the article you&#8217;ll discover how cloud security engineers safeguard sensitive data and implement robust security measures to prevent breaches and cyber threats. You will also gain insights into the various types of cloud security attacks they combat, such as DDoS, hypervisor attacks, and malicious insiders. The article also explores earning potential, certifications, and has a roadmap. Yes, they are promoting a Cloud Security Master&#8217;s Program that they sell, and I am not recommending you jump into that. But overall for someone that needs an overview and a roadmap, it&#8217;s a start. And yes, I know, some of this you probably already know, but its good review! If you feel good in this area, just skip it!</li>
</ul>



<h2 class="wp-block-heading">Learning and Education</h2>



<p>Want to learn something new? Here you go!</p>



<ul class="wp-block-list">
<li><a href="https://brandonjcarroll.com/links/qp6gk">Community | What is the Get AWS Certified: Data Engineer – Associate Challenge?</a> &#8211; Sometimes you need to be challenged to make progress. If that&#8217;s you, here&#8217;s a challenge you might be interested in.</li>
</ul>



<h2 class="wp-block-heading">Community Voice</h2>



<p>A quick note before I get into this weeks share. The articles I share here are mostly posted by AWS Hero&#8217;s and AWS Community Builders. With that said, I do my best not to do two things: 1\ Share posts from Medium because putting content behind a pay wall is not accessible to everyone and I don&#8217;t want to encourage people to pay for another service. 2\ Drive traffic to LinkedIn. There is a TON of content there and lots of Hero&#8217;s and Community Builders share their stuff there. If you want that content please follow them directly on Linkedin. You can find a directory of Hero&#8217;s and Builders to follow <a href="[https://aws.amazon.com/developer/community/community-builders/](https://aws.amazon.com/developer/community/community-builders/community-builders-directory/?cb-cards.sort-by=item.additionalFields.cbName&amp;cb-cards.sort-order=asc&amp;awsf.builder-category=*all&amp;awsf.location=*all&amp;awsf.year=*all)">here</a> and <a href="https://aws.amazon.com/developer/community/heroes/?community-heroes-all.sort-by=item.additionalFields.sortPosition&amp;community-heroes-all.sort-order=asc&amp;awsf.filter-hero-category=*all&amp;awsf.filter-location=*all&amp;awsf.filter-year=*all&amp;awsf.filter-activity=*all">here</a>. If you&#8217;d like to contribute content to the newsletter, please reach out to me directly!</p>



<p>So, here is a roundup of a few posts from the community this week:</p>



<ol class="wp-block-list">
<li><a href="https://www.fogsecurity.io/blog/encryption-aws-managed-kms-keys">AWS Managed KMS Keys and their Key Policies: Security Implications and Coverage for AWS Services</a> &#8211; Are you curious about the AWS Managed KMS Keys and their potential security implications? This blog post provides an insightful overview and introduces a handy tool from Fog Security that scans and lists all AWS Managed KMS Keys along with their corresponding key policies. With visibility into these keys being a challenge, the post highlights the importance of understanding their usage across various AWS services. It also discusses the pros and cons of using AWS Managed KMS Keys, encouraging readers to make informed decisions. The accompanying GitHub repository offers a comprehensive listing of AWS Managed KMS Keys and their key policies, regularly updated through an automated scanning process. Quick statistics and repository contents are also provided, giving you a glimpse into the valuable information available. If you&#8217;re interested in cloud data security or have feedback on the tool, the author invites you to reach out to Fog Security. Don&#8217;t miss the opportunity to explore this resource and gain insights into AWS Managed KMS Keys and their potential impact on your cloud environment.</li>



<li><a href="https://dev.to/aws-builders/setting-up-aws-iam-identity-center-as-an-identity-provider-for-confluence-2l8">Setting up AWS IAM Identity Center as an identity provider for Confluence &#8211; DEV Community</a> &#8211; This detailed guide walks you through setting up single sign-on (SSO) for the popular collaboration tool Confluence, using AWS IAM Identity Center. By integrating Confluence with AWS IAM Identity Center, you can centrally manage access for your users across multiple AWS accounts and Confluence itself. The step-by-step instructions cover everything from configuring the Confluence application in IAM Identity Center, to verifying domain ownership in Atlassian Admin, creating the identity provider, and enforcing SSO in Confluence&#8217;s authentication policies. While the process involves several steps across AWS and Atlassian&#8217;s interfaces, the guide provides clear directions and troubleshooting tips to ensure a smooth integration. If you&#8217;re looking to streamline authentication and account management between your AWS environment and Confluence, this comprehensive walkthrough could save you a significant amount of time and effort. The ability to leverage AWS IAM Identity Center for SSO with third-party apps like Confluence also highlights its versatility as an identity provider solution.</li>
</ol>



<p>That&#8217;s it for this week. I encourage you to subscribe, share, and leave your comments on this edition of the newsletter.</p>



<p>Also, if you will be attending the AWS Summit New York, please let me know. I will be there as well and I am planning on doing some videos with community members. If videos aren&#8217;t your thing, lets at least have a chat!</p>



<p>That&#8217;s it for now!</p>



<p>Happy Labbing!</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-32/">Securing the Cloud #32</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://brandonjcarroll.com/securing-the-cloud-32/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">19119</post-id>	</item>
		<item>
		<title>Securing the Cloud #31</title>
		<link>https://brandonjcarroll.com/securing-the-cloud-31/</link>
					<comments>https://brandonjcarroll.com/securing-the-cloud-31/#respond</comments>
		
		<dc:creator><![CDATA[Brandon Carroll]]></dc:creator>
		<pubDate>Fri, 14 Jun 2024 21:13:39 +0000</pubDate>
				<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Learning]]></category>
		<guid isPermaLink="false">https://brandonjcarroll.com/?p=19041</guid>

					<description><![CDATA[<p>Welcome to the 31st edition of the Securing the Cloud Newsletter! We&#8217;ve taken two weeks off while travelling for two different conferences. The week of June 3rd we were in ...</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-31/">Securing the Cloud #31</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Welcome to the 31st edition of the Securing the Cloud Newsletter! We&#8217;ve taken two weeks off while travelling for two different conferences. The week of June 3rd we were in Las Vegas for Cisco Live. This week we were in Philadelphia for AWS re:Inforce 2024. Both events were amazing and we were able to spend a lot of time with the community talking networking, cloud, security, and Gen AI. So, in this issue, we dive into the latest trends and insights in cloud security with a bit of what came out of re:Inforce. Plus, we explore career development and share some valuable learning resources. Additionally, we feature insightful perspectives from our community members. Let&#8217;s go!</p>



<h2 class="wp-block-heading">Technical Stuff From CiscoLive and re:Inforce</h2>



<ul class="wp-block-list">
<li><a href="https://www.tiktok.com/@thecloudsecurityguy/video/7380465741331434795">Unleashing Cloud Power with Cisco and AWS</a> &#8211; Du&#8217;An and I presented this 20 minute talk at the AWS booth last week in Las Vegas. We were really excited to help people like us, with a background in Cisco Networking, to bridge that knowledge to the Cloud. Enjoy the video!</li>



<li><a href="https://brandonjcarroll.com/links/9zrhf">Introducing Amazon GuardDuty Malware Protection for Amazon S3 | AWS News Blog</a> &#8211; Amazon GuardDuty Malware Protection for Amazon S3 now detects malicious file uploads, adding to its existing capabilities for Amazon EBS volumes. This was an announcement made at re:Inforce this week in case you missed it. Users can easily enable this service in the GuardDuty console and configure advanced malware protection measures such as object tagging and event-based actions. For more details on how to enhance your organization&#8217;s security with GuardDuty Malware Protection for Amazon S3. Check out the article for the full details.</li>
</ul>



<h2 class="wp-block-heading">Career Corner</h2>



<ul class="wp-block-list">
<li><a href="https://brandonjcarroll.com/links/lslcw">AWS re:Invent 2024 All Builders Welcome | Amazon Web Services</a> &#8211; Ok, this share is in the Career Corner today because I realized many of you may not be familiar with the program. At AWS re:Inforce we had several builders early in their career that were mentored and brought to re:Inforce with the All Builders Welcome program. This is a program where AWS is empowering underrepresented technologists in the early stages of their careers by providing grants to attend certain events. AWS is also doing this for AWS re:Invent in December 2024, offering opportunities to learn, network, and grow in the tech industry. Read the landing page for the re:Invent specific program where it describes the AWS commitment to fostering diversity and inclusion while bridging the gap in the tech space, inviting those interested to apply for the grant and join the next generation of technical leaders. It&#8217;s a pretty cool opportunity that you might want to give a shot.</li>
</ul>



<h2 class="wp-block-heading">Learning and Education</h2>



<ul class="wp-block-list">
<li><a href="https://brandonjcarroll.com/links/jjmzz">Exam Updates, Beta Exams, and New Certifications | Coming Soon to AWS Certification | AWS</a> &#8211; Ok, this normally wouldn&#8217;t be in this section because it&#8217;s not really an article that teaches you something. It&#8217;s here because it shows the two new certifications that AWS announced at re:Inforce and I couldn&#8217;t find an article that went into more details. Anyhow, check them out. They aren&#8217;t availabe yet, but keep them on your radar.
<ul class="wp-block-list">
<li>AWS Certified AI Practitioner beta exam</li>



<li>AWS Certified Machine Learning Engineer &#8211; Associate beta exam</li>
</ul>
</li>
</ul>



<h2 class="wp-block-heading">Community Voice</h2>



<p>Here are a few things going on in the community.</p>



<ol class="wp-block-list">
<li><a href="https://carriagereturn.nl/aws/alb/basic/auth/cognito/2024/05/21/incognito-basic-auth.html">Incognito Authentication | CarriageReturn.Nl</a> &#8211; Learn how to implement a shared password authentication for a web service using ALB and Lambda from this article, which details the challenges faced and solutions adopted in a step-by-step manner. Explore the author&#8217;s journey in setting up secure authentication in the cloud and the insights gained along the way.</li>



<li><a href="https://www.mitigant.io/blog/mitre-att-ck-cloud-matrix-new-techniques-why-you-should-care-part-i">MITRE ATT&amp;CK Cloud Matrix: New Techniques &amp; Why You Should Care. Part I | Mitigant</a> &#8211; The MITRE ATT&amp;CK Framework v.14, released in October 2023, introduces over 18 new techniques crucial for modern cybersecurity defenses, with two notable additions in the IaaS section for enterprises. Exploring these techniques sheds light on how attackers exploit vulnerabilities in cloud systems and emphasizes the importance of staying updated and implementing effective detection strategies. For a deeper dive into cloud threat detection and mitigation strategies, read more at https://www.mitigant.io/sign-up.</li>



<li><a href="https://www.mitigant.io/blog/mitre-att-ck-cloud-matrix-new-techniques-why-you-should-care-part-ii">MITRE ATT&amp;CK Cloud Matrix: New Techniques &amp; Why You Should Care &#8211; Part II | Mitigant</a> &#8211; The MITRE ATT&amp;CK Framework v.14 introduces new techniques like Log Enumeration to address challenges in cloud attack detection. Explore how the framework, along with suggested mitigation strategies, can help defend against evolving threats in cloud environments in the full article.</li>



<li><a href="https://somilgupta.hashnode.dev/learn-to-build-rag-application-using-aws-bedrock-and-langchain">Learn to Build RAG Application using AWS Bedrock and LangChain</a> &#8211; Explore the world of Retrieval-Augmented Generation (RAG) in natural language processing and machine learning. Discover how RAG enhances language models by bridging gaps in data sources, offering accurate responses, and fostering innovation, as demonstrated through a step-by-step guide to building an RAG application in this insightful article.</li>
</ol>



<p>Thanks for reading this weeks edition. We encourage you to subscribe, share, and leave your comments on this edition of the newsletter. Happy Labbing!</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-31/">Securing the Cloud #31</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://brandonjcarroll.com/securing-the-cloud-31/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">19041</post-id>	</item>
		<item>
		<title>Securing the Cloud #30</title>
		<link>https://brandonjcarroll.com/securing-the-cloud-30/</link>
					<comments>https://brandonjcarroll.com/securing-the-cloud-30/#respond</comments>
		
		<dc:creator><![CDATA[Brandon Carroll]]></dc:creator>
		<pubDate>Sat, 25 May 2024 01:44:47 +0000</pubDate>
				<category><![CDATA[Securing the Cloud Newsletter]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[goals]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[generative-ai]]></category>
		<guid isPermaLink="false">https://brandonjcarroll.com/?p=18976</guid>

					<description><![CDATA[<p>Welcome to the 30th edition of the Securing the Cloud Newsletter! In this issue, we dive into the latest trends and insights in cloud security, explore career development opportunities, and ...</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-30/">Securing the Cloud #30</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Welcome to the 30th edition of the Securing the Cloud Newsletter! In this issue, we dive into the latest trends and insights in cloud security, explore career development opportunities, and share valuable learning resources. Additionally, we feature insightful perspectives from our community members.</p>



<h2 class="wp-block-heading">Technical Topic</h2>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="1024" height="1024" data-attachment-id="18977" data-permalink="https://brandonjcarroll.com/securing-the-cloud-30/technical-topic-30/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-30.png" data-orig-size="1024,1024" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="technical-topic-30" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-30.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-30.png" alt="" class="wp-image-18977" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-30.png 1024w, https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-30-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-30-150x150.png 150w, https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-30-768x768.png 768w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list">
<li><a href="https://brandonjcarroll.com/links/hoke0">How to Apply GitOps to Everything Using Amazon Elastic Kubernetes Service (Amazon EKS), Crossplane, and Flux | AWS Open Source Blog</a> &#8211; This post provides a detailed walkthrough on using GitOps, Crossplane, and Flux to provision and manage cloud infrastructure and applications on Amazon Web Services (AWS). It explains how GitOps enables declarative management of cloud-native stacks, while Crossplane allows using Kubernetes APIs to provision and manage resources across different cloud providers. By following this tutorial, you&#8217;ll gain practical experience in leveraging the power of GitOps, Crossplane, and Flux to streamline your cloud infrastructure and application deployments on AWS. You&#8217;ll learn how to version your desired state in Git, automate deployments, and consistently manage resources across environments.</li>
</ul>



<h2 class="wp-block-heading">Career Corner</h2>



<figure class="wp-block-image size-full"><img decoding="async" width="1024" height="1024" data-attachment-id="18978" data-permalink="https://brandonjcarroll.com/securing-the-cloud-30/career-corner-30/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-30.png" data-orig-size="1024,1024" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="career-corner-30" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-30.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-30.png" alt="" class="wp-image-18978" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-30.png 1024w, https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-30-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-30-150x150.png 150w, https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-30-768x768.png 768w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list">
<li><a href="https://www.reddit.com/r/Terraform/comments/13sbl1b/if_you_do_infrastructureascodeare_you_a_developer/">Reddit &#8211; Dive into anything</a> &#8211; Are you someone who works with Infrastructure-as-Code tools like Terraform? If so, this thread goes into an interesting debate &#8211; what exactly do you identify as professionally? Are you a developer since you&#8217;re writing code? An infrastructure engineer since you&#8217;re provisioning infrastructure? Or perhaps both roles blend together in the world of IaC?</li>
</ul>



<h2 class="wp-block-heading">Learning and Education</h2>



<figure class="wp-block-image size-full"><img decoding="async" width="1024" height="1024" data-attachment-id="18979" data-permalink="https://brandonjcarroll.com/securing-the-cloud-30/learning-and-education-30/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-30.png" data-orig-size="1024,1024" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="learning-and-education-30" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-30.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-30.png" alt="" class="wp-image-18979" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-30.png 1024w, https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-30-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-30-150x150.png 150w, https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-30-768x768.png 768w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list">
<li><a href="https://page.gitlab.com/resources-ebook-beginner-guide-gitops.html">A Beginners Guide to GitOps</a> &#8211; GitOps takes the tried-and-true DevOps best practices used for application development, such as version control, collaboration, compliance, and CI/CD, and applies them to infrastructure automation. By leveraging the principles of Git, the widely-adopted version control system, GitOps empowers teams to manage and automate their infrastructure with the same level of rigor and efficiency as they do with their application code. Dive into this beginner&#8217;s guide to GitOps and discover how this powerful framework can transform your infrastructure automation journey.</li>
</ul>



<h2 class="wp-block-heading">Community Voice</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1024" height="1024" data-attachment-id="18980" data-permalink="https://brandonjcarroll.com/securing-the-cloud-30/community-voice-30/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-30.png" data-orig-size="1024,1024" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="community-voice-30" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-30.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-30.png" alt="" class="wp-image-18980" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-30.png 1024w, https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-30-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-30-150x150.png 150w, https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-30-768x768.png 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<ol class="wp-block-list">
<li><a href="https://dev.to/aws-builders/mastering-the-aws-security-specialty-scs-exam-a-quick-guide-2go0">Mastering the AWS Security Specialty (SCS) Exam &#8211; A Quick Guide &#8211; DEV Community</a> &#8211; Want to ace the challenging AWS Certified Security Specialty exam? This guide shares invaluable tips and top resources that helped Damien pass on their first attempt. Get an inside look at must-use study materials like Stephane Maarek&#8217;s comprehensive Udemy course, Whizlabs&#8217; hands-on labs for practical experience, TutorialsDojo&#8217;s realistic practice exams and cheat sheets, and Becky Weiss&#8217;s session on AWS cloud security fundamentals.</li>



<li><a href="https://slaw.securosis.com/p/enable-guardduty-right-way">Enable GuardDuty the Right Way</a> &#8211; In this article, Rich Mogull takes readers on a journey through the importance of GuardDuty, AWS&#8217;s Intrusion Detection System for the cloud. With his signature storytelling flair, Mogull transports us back to the &#8220;dark days&#8221; of the early cloud era, highlighting the significance of visibility tools like CloudTrail and GuardDuty.</li>



<li><a href="https://dev.to/aws-builders/tactical-cloud-audit-log-analysis-with-duckdb-aws-cloudtrail-2amk">Tactical Cloud Audit Log Analysis with DuckDB &#8211; AWS CloudTrail &#8211; DEV Community</a> &#8211; Have you ever needed to analyze CloudTrail logs but found yourself without a convenient search interface or had to temporarily enable CloudTrail for troubleshooting? This article demonstrates how to leverage the capabilities of DuckDB, a powerful open-source SQL database, to query CloudTrail logs directly from Amazon S3.</li>



<li><a href="https://securosis.com/blog/aws-cloud-incident-analysis-query-cheatsheet/">AWS Cloud Incident Analysis Query Cheatsheet &#8211; Securosis</a> &#8211; This post provides a comprehensive cheatsheet of essential CloudTrail log queries for cloud incident analysis and response.</li>



<li><a href="https://ramimac.me/exposed-docdb">Publicly Exposed AWS Document DB Snapshots – High Signal Security – YAIB</a> &#8211; Security researcher Dylanjacob discovered a massive public exposure of over 3.5TB of sensitive customer data. Here is the story!</li>
</ol>



<h2 class="wp-block-heading">Conclusion</h2>



<p>Thanks for coming along for this weeks journey. I encourage you to subscribe, share, and leave your comments on this edition of the newsletter. Please share with your colleagues and if you have any requests please send them my way. I hope you found this useful. Happy Labbing!</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-30/">Securing the Cloud #30</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://brandonjcarroll.com/securing-the-cloud-30/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18976</post-id>	</item>
		<item>
		<title>Securing the Cloud #29</title>
		<link>https://brandonjcarroll.com/securing-the-cloud-29/</link>
					<comments>https://brandonjcarroll.com/securing-the-cloud-29/#respond</comments>
		
		<dc:creator><![CDATA[Brandon Carroll]]></dc:creator>
		<pubDate>Fri, 17 May 2024 16:53:49 +0000</pubDate>
				<category><![CDATA[Securing the Cloud Newsletter]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Career Advice]]></category>
		<category><![CDATA[Generative AI]]></category>
		<category><![CDATA[Learning and Certification]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[generative-ai]]></category>
		<category><![CDATA[AWS]]></category>
		<guid isPermaLink="false">https://brandonjcarroll.com/?p=18950</guid>

					<description><![CDATA[<p>Welcome to the 29th edition of the Securing the Cloud Newsletter! In this issue, we dive into the latest trends and insights in cloud security, explore career development opportunities, and ...</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-29/">Securing the Cloud #29</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Welcome to the 29th edition of the Securing the Cloud Newsletter! In this issue, we dive into the latest trends and insights in cloud security, explore career development opportunities, and share valuable learning resources. Additionally, we feature insightful perspectives from our community members.</p>



<h2 class="wp-block-heading">Technical Topic</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1024" height="1024" data-attachment-id="18952" data-permalink="https://brandonjcarroll.com/securing-the-cloud-29/technical-topic-29/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-29.png" data-orig-size="1024,1024" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="technical-topic-29" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-29.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-29.png" alt="" class="wp-image-18952" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-29.png 1024w, https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-29-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-29-150x150.png 150w, https://brandonjcarroll.com/wp-content/uploads/2024/05/technical-topic-29-768x768.png 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list">
<li><a href="https://brandonjcarroll.com/links/zvkim">Building a modern application development mindset | AWS Training and Certification Blog</a> &#8211; In today&#8217;s digital landscape, modern applications need to meet demanding requirements &#8211; handling millions of users, managing massive data volumes, and delivering lightning-fast responses. This article outlines how modern application development practices can help businesses rapidly innovate and create robust, secure, and scalable applications that delight customers.</li>
</ul>



<h2 class="wp-block-heading">Career Corner</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1024" height="1024" data-attachment-id="18953" data-permalink="https://brandonjcarroll.com/securing-the-cloud-29/career-corner-29/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-29.png" data-orig-size="1024,1024" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="career-corner-29" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-29.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-29.png" alt="" class="wp-image-18953" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-29.png 1024w, https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-29-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-29-150x150.png 150w, https://brandonjcarroll.com/wp-content/uploads/2024/05/career-corner-29-768x768.png 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list">
<li><a href="https://www.practical-devsecops.com/devsecops-engineer/">How to Become a DevSecOps Engineer-DevSecOps Career Path</a> &#8211; As the demand for skilled DevSecOps engineers skyrockets, this comprehensive guide unveils the exciting career path that awaits those who embrace this innovative field. Delve into the essential skills, tools, and technologies that define a successful DevSecOps engineer, and discover how you can equip yourself with the knowledge and expertise to excel in this rapidly evolving domain. From understanding the roles and responsibilities of a DevSecOps engineer to mastering the art of continuous integration, continuous delivery, and continuous monitoring, this article provides a roadmap to navigating the challenges and opportunities that lie ahead.</li>
</ul>



<h2 class="wp-block-heading">Learning and Education</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1024" height="1024" data-attachment-id="18954" data-permalink="https://brandonjcarroll.com/securing-the-cloud-29/learning-and-education-29/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-29.png" data-orig-size="1024,1024" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="learning-and-education-29" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-29.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-29.png" alt="" class="wp-image-18954" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-29.png 1024w, https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-29-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-29-150x150.png 150w, https://brandonjcarroll.com/wp-content/uploads/2024/05/learning-and-education-29-768x768.png 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<ul class="wp-block-list">
<li><a href="https://aws.amazon.com/blogs/publicsector/episode-3-building-secure-code/">Episode 3: Building Secure Code | AWS Public Sector Blog</a> &#8211; This post provides a comprehensive overview of common application security vulnerabilities and best practices for building, testing, and deploying code securely. It highlights the importance of addressing security concerns throughout the entire application lifecycle, not just during the architecture phase.</li>
</ul>



<h2 class="wp-block-heading">Community Voice</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1024" height="1024" data-attachment-id="18955" data-permalink="https://brandonjcarroll.com/securing-the-cloud-29/community-voice-29/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-29.png" data-orig-size="1024,1024" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="community-voice-29" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-29.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-29.png" alt="" class="wp-image-18955" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-29.png 1024w, https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-29-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-29-150x150.png 150w, https://brandonjcarroll.com/wp-content/uploads/2024/05/community-voice-29-768x768.png 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<ol class="wp-block-list">
<li><a href="https://www.theserverlessterminal.com/p/s3-fixes-billing-for-unauthorised">S3 fixes billing for unauthorised APIs <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f680.png" alt="🚀" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2601.png" alt="☁" class="wp-smiley" style="height: 1em; max-height: 1em;" /> #55</a> &#8211; This comes from AWS Serverless Hero, <a href="https://substack.com/@zachjonesnoel">JONES ZACHARIAH NOEL N</a>. and this issue of Serverless Infrastructure and API provides an insightful look into the latest updates and developments in the world of serverless computing on AWS. Of note, it covers the recent S3 billing issue for unauthorized APIs and how AWS swiftly addressed it within 15 days, showcasing their commitment to customer satisfaction. If you&#8217;re not subscribed already I recommend you have a look!</li>



<li><a href="https://www.meetup.com/lehigh-valley-aws-user-group/events/300860843/">June LVAWSUG Meeting/Party</a> &#8211; Will you be attending AWS Re:Inforce this year? If so, spend some extra time with the AWS Community in Philly!</li>



<li><a href="https://streamyard.com/watch/3wykCnJ3iKJg">Getting Your Hands Dirty With RAG: Production Experience With LLM Enhancement</a> &#8211; If you&#8217;re getting into Generative AI and RAG this could prove to be a really good session. It was shared by AWS Hero, Luc van Donkersgoed.</li>



<li><a href="https://www.edx.org/learn/amazon-web-services-aws/pragmatic-ai-labs-authoritative-aws">AI: Authoritative AWS</a> &#8211; AWS Machine Learning Hero, Noah Gift, shared this edX course that covers SIX certifications at the same time in one mega course. I&#8217;m definitely checking it out.</li>



<li><a href="https://brandonjcarroll.com/links/l22lw">The Legend of AWS Warrior: A Free Opensource 3D RPG Adventure Game with Generative AI for learning AWS</a> &#8211; AWS ML Hero, Cyrus Wong, shares an innovative approach to learning AWS through 3D RPG gaming at Hong Kong Institute of Information Technology (HKIIT).</li>
</ol>



<h2 class="wp-block-heading">Conclusion</h2>



<p>As we wrap up this edition of the Securing the Cloud Newsletter, I hope you found the insights, resources, and community highlights both informative and inspiring. Whether you&#8217;re into modern application development, exploring a career in DevSecOps, or enhancing your skills in building secure code, remember that continuous learning and community engagement are key to staying ahead in the ever-evolving world of cloud security.</p>



<p>Keep pushing your boundaries, stay curious, and never hesitate to reach out and share your own experiences and questions with our community. Your journey in cloud and cloud security is as much about collaboration and shared growth as it is about individual progress. Until next time, stay secure and keep experimenting.</p>



<p>I encourage you to subscribe, share, and leave your comments on this edition of the newsletter. Happy Labbing!</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-29/">Securing the Cloud #29</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://brandonjcarroll.com/securing-the-cloud-29/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18950</post-id>	</item>
		<item>
		<title>Securing the Cloud #28</title>
		<link>https://brandonjcarroll.com/securing-the-cloud-28/</link>
					<comments>https://brandonjcarroll.com/securing-the-cloud-28/#respond</comments>
		
		<dc:creator><![CDATA[Brandon Carroll]]></dc:creator>
		<pubDate>Fri, 10 May 2024 18:19:27 +0000</pubDate>
				<category><![CDATA[Securing the Cloud Newsletter]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Career Advice]]></category>
		<category><![CDATA[Learning and Certification]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[goals]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[generative-ai]]></category>
		<category><![CDATA[AWS]]></category>
		<guid isPermaLink="false">https://brandonjcarroll.com/?p=18918</guid>

					<description><![CDATA[<p>Welcome to the 28th edition of the Securing the Cloud Newsletter! In this issue, we dive into the latest trends and insights in cloud security, explore career development opportunities, and ...</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-28/">Securing the Cloud #28</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Welcome to the 28th edition of the Securing the Cloud Newsletter! In this issue, we dive into the latest trends and insights in cloud security, explore career development opportunities, and share valuable learning resources. Additionally, we feature insightful perspectives from our community members.</p>



<h2 class="wp-block-heading">Technical Topics</h2>



<ul class="wp-block-list">
<li><a href="https://brandonjcarroll.com/links/jumfj">Considerations for security operations in the cloud | AWS Security Blog</a> &#8211; Cybersecurity teams consist of different functions like Governance, Risk &amp; Compliance (GRC), Security Architecture, Assurance, and Security Operations (SecOps), each working towards securing the business and its workloads, with SecOps focused on operational oversight and responding to security incidents using various operating models like centralized, decentralized, or hybrid approaches tailored to an organization&#8217;s cloud environment.</li>



<li><a href="https://brandonjcarroll.com/links/dvp3k">Securing generative AI: An introduction to the Generative AI Security Scoping Matrix</a> &#8211; This blog post introduces the Generative AI Security Scoping Matrix, a framework for understanding and prioritizing security controls for generative AI deployments within AWS, emphasizing the importance of aligning security disciplines with different types of AI implementations.</li>



<li><a href="https://brandonjcarroll.com/links/sk24v">Securing generative AI: data, compliance, and privacy considerations</a> &#8211; The second in the series, this blog post provides a detailed exploration of data, compliance, and privacy considerations essential for securing generative AI, offering guidance on navigating the complexities associated with deploying generative AI workloads responsibly.</li>



<li><a href="https://brandonjcarroll.com/links/iclhi">Securing generative AI: Applying relevant security controls</a> &#8211; Finally, the third in the series. this blog post gets into practical strategies for applying security controls to protect generative AI applications, mapping these controls to frameworks like MITRE ATLAS for comprehensive risk management.</li>
</ul>



<h2 class="wp-block-heading">Career Corner</h2>



<ul class="wp-block-list">
<li><a href="https://online.utulsa.edu/blog/soc-analyst-salary-job-description/#:~:text=While%20the%20roles%20and%20responsibilities,strategic%20response%20to%20cybersecurity%20incidents">Security Operations Center (SOC) Analyst Salary and Job Description | The University of Tulsa</a> &#8211; A comprehensive overview of the role, responsibilities, skills, education, and salary expectations for Security Operations Center (SOC) analysts, emphasizing the importance of vigilance against cyber threats and the rewarding nature of this cybersecurity career path.</li>
</ul>



<h2 class="wp-block-heading">Learning and Education</h2>



<ul class="wp-block-list">
<li><a href="https://www.coursera.org/learn/security-operations">Security Operations Course by ISC2 | Coursera</a> &#8211; This course covers security operations, focusing on actively using security controls, mitigating risks, securing data and systems, encouraging secure practices, understanding data security, encryption, controls, asset management, security policies, security awareness training, and reviewing network operations concepts.</li>
</ul>



<h2 class="wp-block-heading">Community Voice</h2>



<p>In this weeks edition we have some more insight from AWS Hero Sena Yakut. Sena shares thoughts on resilience and rec:</p>



<p>My key recommendations for resilience and recovery strategies and overcoming disasters in cloud environments:</p>



<ul class="wp-block-list">
<li><strong>High Available Architectures:</strong> We need to always design our cloud infrastructure with high availability. We always consider using load balancers, auto-scaling, cross-account, or cross-regional architectures when needed.<br>&#8211; <strong>Failover Systems:</strong> We need to implement failover systems that automatically switch to backup resources in the event of an incident, ensuring continuous cloud services availability.</li>



<li><strong>Incident Response Plan and Strong Team:</strong> We need to develop a comprehensive incident response plan that outlines procedures for detecting, responding to, and recovering from cloud security incidents. This plan should include roles and responsibilities, escalation procedures, and communication protocols to facilitate a coordinated response. <a href="https://docs.aws.amazon.com/whitepapers/latest/aws-security-incident-response-guide/develop-and-test-incident-response-plan.html">There is a great resource to develop and test an incident response plan</a>. Also, it’s important to establish an incident response team trained to quickly identify and respond to security incidents or disasters. This team should have clearly defined roles and responsibilities and be ready to execute the plan when needed.</li>



<li><strong>Continuous Improvement and Adaptation:</strong> We should continuously monitor and assess the evolving threat landscape and emerging security risks in our cloud environments. Regularly update and adapt security policies, controls, and practices to address new threats and vulnerabilities and improve overall cloud security posture.</li>



<li><strong>Security Automation and Orchestration:</strong> We need to use automation and orchestration tools to streamline cloud security operations and incident response processes. We automate routine security tasks, such as vulnerability scanning, threat detection, and incident triage, to improve efficiency and reduce response times during security incidents. You can use AWS security-managed services such as AWS Security Hub, AWS Config, Amazon Inspector, and Amazon GuardDuty for all security automation and orchestration.</li>
</ul>



<p>And from around the web here are a few articles written by AWS Community Builders you should check out!</p>



<ol class="wp-block-list">
<li><a href="https://ramimac.me/semgrep-for-terraform">Semgrep for Terraform Security – High Signal Security – YAIB (Yet Another Infosec blog).</a> &#8211; Semgrep is a powerful SAST tool that can be used for detecting security misconfigurations and enforcing secure-by-default patterns in Terraform code, enabling developers to write secure infrastructure as code.</li>



<li><a href="https://dev.to/aws-builders/my-journey-to-passing-the-aws-certified-solutions-architect-associate-exam-de">My Journey to Passing the AWS Certified Solutions Architect Associate Exam &#8211; DEV Community</a> &#8211; A detailed summary of how the author successfully prepared for and passed the AWS Certified Solutions Architect &#8211; Associate (SAA) exam, including the resources used, study plan followed, practice exams taken, and key tips for exam preparation.</li>



<li><a href="https://devsecopssourav.hashnode.dev/from-metadata-to-mayhem-protecting-aws-account-from-ssrf-attacks-via-imdsv2">From Metadata to Mayhem: Protecting AWS account from SSRF Attacks via IMDSV2</a> &#8211; Server-Side Request Forgery (SSRF) vulnerability allows attackers to manipulate servers into making unintended requests, potentially exposing sensitive data from AWS Instance Metadata Service (IMDS); IMDSv2 mitigates SSRF risks by requiring session tokens, enhancing security for AWS EC2 instances.</li>
</ol>



<h2 class="wp-block-heading">That&#8217;s a wrap!</h2>



<p>Thank you for joining us for the 28th edition of the Securing the Cloud Newsletter. This issue brought you a comprehensive dive into the ever-evolving landscape of cloud security, from detailed discussions on security operations to the intricacies of securing generative AI with AWS&#8217;s Scoping Matrix. We explored significant career opportunities within the realm of cybersecurity and shared educational resources to further your expertise. The insights from our community, especially Sena Yakut&#8217;s robust strategies for resilience in cloud environments, underscore the ongoing need for vigilance and continuous improvement in our security practices. Remember to stay connected, share your thoughts, and engage with the content as we continue to navigate the complexities of cloud security together. Happy Labbing!</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-28/">Securing the Cloud #28</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://brandonjcarroll.com/securing-the-cloud-28/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18918</post-id>	</item>
		<item>
		<title>Securing the Cloud #27</title>
		<link>https://brandonjcarroll.com/securing-the-cloud-27/</link>
					<comments>https://brandonjcarroll.com/securing-the-cloud-27/#respond</comments>
		
		<dc:creator><![CDATA[Brandon Carroll]]></dc:creator>
		<pubDate>Sat, 20 Apr 2024 03:53:33 +0000</pubDate>
				<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[community]]></category>
		<guid isPermaLink="false">https://brandonjcarroll.com/?p=18857</guid>

					<description><![CDATA[<p>Welcome to the 27th edition of the Securing the Cloud Newsletter! In this issue, we dive into the latest trends and insights in cloud security, explore career development opportunities, and ...</p>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-27/">Securing the Cloud #27</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="512" height="512" data-attachment-id="18858" data-permalink="https://brandonjcarroll.com/securing-the-cloud-27/featured-image-27/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/04/featured-image-27.png" data-orig-size="512,512" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="featured-image-27" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/04/featured-image-27.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/04/featured-image-27.png" alt="" class="wp-image-18858" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/04/featured-image-27.png 512w, https://brandonjcarroll.com/wp-content/uploads/2024/04/featured-image-27-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/04/featured-image-27-150x150.png 150w" sizes="auto, (max-width: 512px) 100vw, 512px" /></figure>



<p>Welcome to the 27th edition of the Securing the Cloud Newsletter! In this issue, we dive into the latest trends and insights in cloud security, explore career development opportunities, and share valuable learning resources. Additionally, we feature insightful perspectives from our community members. This weeks edition is focused on Data Security and Cryptography. Is that your area of expertise? If so, join the conversation and share your insights. Here we go!</p>



<h2 class="wp-block-heading">Technical Topic</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="512" height="512" data-attachment-id="18859" data-permalink="https://brandonjcarroll.com/securing-the-cloud-27/technical-topic-27/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/04/technical-topic-27.png" data-orig-size="512,512" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="technical-topic-27" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/04/technical-topic-27.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/04/technical-topic-27.png" alt="" class="wp-image-18859" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/04/technical-topic-27.png 512w, https://brandonjcarroll.com/wp-content/uploads/2024/04/technical-topic-27-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/04/technical-topic-27-150x150.png 150w" sizes="auto, (max-width: 512px) 100vw, 512px" /></figure>



<ul class="wp-block-list">
<li><a href="https://brandonjcarroll.com/links/lvjpc">Community | Data Security and Cryptography on AWS</a> &#8211; This is a round-up article of sorts. In this article I share some terms related to Data Security and Cryptography and point you to useful resources to help you dig deeper into the topics.</li>
</ul>



<h2 class="wp-block-heading">Career Corner</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="512" height="512" data-attachment-id="18860" data-permalink="https://brandonjcarroll.com/securing-the-cloud-27/career-corner-27/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/04/career-corner-27.png" data-orig-size="512,512" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="career-corner-27" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/04/career-corner-27.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/04/career-corner-27.png" alt="" class="wp-image-18860" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/04/career-corner-27.png 512w, https://brandonjcarroll.com/wp-content/uploads/2024/04/career-corner-27-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/04/career-corner-27-150x150.png 150w" sizes="auto, (max-width: 512px) 100vw, 512px" /></figure>



<ul class="wp-block-list">
<li><a href="https://brandonjcarroll.com/specializing-in-a-cryptography-career/">Specializing in a Cryptography Career &#8211; Brandon J Carroll</a> &#8211; In this article, I discuss what it might take to pursue a career specializing in cryptography.</li>
</ul>



<h2 class="wp-block-heading">Learning and Education</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="512" height="512" data-attachment-id="18861" data-permalink="https://brandonjcarroll.com/securing-the-cloud-27/learning-and-education-27/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/04/learning-and-education-27.png" data-orig-size="512,512" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="learning-and-education-27" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/04/learning-and-education-27.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/04/learning-and-education-27.png" alt="" class="wp-image-18861" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/04/learning-and-education-27.png 512w, https://brandonjcarroll.com/wp-content/uploads/2024/04/learning-and-education-27-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/04/learning-and-education-27-150x150.png 150w" sizes="auto, (max-width: 512px) 100vw, 512px" /></figure>



<ul class="wp-block-list">
<li><a href="https://brandonjcarroll.com/questions-from-readers-how-can-i-prepare-for-and-take-certification-exams-if-i-have-dyslexia/">Questions from Readers: How can I prepare for and take certification exams if I have dyslexia? &#8211; Brandon J Carroll</a> &#8211; Inspired by one of my LinkedIn connection&#8217;s query, I share what I have seen over my years of teaching Cisco networking classes.</li>
</ul>



<h2 class="wp-block-heading">Community Voice</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="512" height="512" data-attachment-id="18862" data-permalink="https://brandonjcarroll.com/securing-the-cloud-27/community-voice-27/" data-orig-file="https://brandonjcarroll.com/wp-content/uploads/2024/04/community-voice-27.png" data-orig-size="512,512" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="community-voice-27" data-image-description="" data-image-caption="" data-large-file="https://brandonjcarroll.com/wp-content/uploads/2024/04/community-voice-27.png" src="https://brandonjcarroll.com/wp-content/uploads/2024/04/community-voice-27.png" alt="" class="wp-image-18862" srcset="https://brandonjcarroll.com/wp-content/uploads/2024/04/community-voice-27.png 512w, https://brandonjcarroll.com/wp-content/uploads/2024/04/community-voice-27-300x300.png 300w, https://brandonjcarroll.com/wp-content/uploads/2024/04/community-voice-27-150x150.png 150w" sizes="auto, (max-width: 512px) 100vw, 512px" /></figure>



<ol class="wp-block-list">
<li><a href="https://medium.com/@metal.preacher/ever-changing-cnapp-22d4f66cc809">Ever-changing CNAPP. In this blog, I would like to introduce… | by Shun Yoshie | Mar, 2024 | Medium</a> &#8211; In this article, Shun talks about CNAPP (Cloud Native Application Protection Platforms), emerging as a comprehensive approach to ensuring security in cloud-native environments, integrating various previously siloed security functions like container scanning, CSPM, IaC scanning, CIEM, and CWPP.</li>



<li><a href="https://blog.besharp.it/vpc-lattice-yet-another-connectivity-option-or-a-game-changer/">VPC Lattice: yet another connectivity option or a game-changer? &#8211; Proud2beCloud Blog</a> &#8211; In this article, VPC Lattice, a fairly new AWS service that simplifies secure communication and management of microservices across different AWS accounts and VPCs, is explored through an example deployment highlighting its key components, workflow, benefits, and limitations compared to other connectivity options.</li>



<li><a href="https://dev.to/damienjburks/kickstarting-your-devsecops-career-the-4-essential-certifications-you-need-3el3">Kickstarting Your DevSecOps Career &#8211; The 4 Essential Certifications You Need &#8211; DEV Community</a> &#8211; In this article, my friend <a href="https://dev.to/damienjburks">Damien Burks</a> summarizes four pivotal certifications for launching a DevSecOps career: CompTIA Security+, CompTIA Linux+, AWS Certified Developer &#8211; Associate, and Certified Kubernetes Administrator, highlighting their importance and key focus areas along with emphasizing hands-on experience through projects and lab work. Well that&#8217;s it for this week. I hope you&#8217;ve found this round-up useful. If so, I encourage you to subscribe, share, and leave your comments on this edition of the newsletter. Happy Labbing!</li>
</ol>
<p>The post <a href="https://brandonjcarroll.com/securing-the-cloud-27/">Securing the Cloud #27</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://brandonjcarroll.com/securing-the-cloud-27/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18857</post-id>	</item>
		<item>
		<title>Specializing in a Cryptography Career</title>
		<link>https://brandonjcarroll.com/specializing-in-a-cryptography-career/</link>
					<comments>https://brandonjcarroll.com/specializing-in-a-cryptography-career/#respond</comments>
		
		<dc:creator><![CDATA[Brandon Carroll]]></dc:creator>
		<pubDate>Fri, 19 Apr 2024 18:59:15 +0000</pubDate>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Career Advice]]></category>
		<category><![CDATA[goals]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[career]]></category>
		<guid isPermaLink="false">https://brandonjcarroll.com/?p=18851</guid>

					<description><![CDATA[<p>I talk a lot about working in networking, cybersecurity, and IT. But I don&#8217;t really get into the more niche areas. But at the same time I&#8217;ve always advocated for ...</p>
<p>The post <a href="https://brandonjcarroll.com/specializing-in-a-cryptography-career/">Specializing in a Cryptography Career</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>I talk a lot about working in networking, cybersecurity, and IT.  But I don&#8217;t really get into the more niche areas.  But at the same time I&#8217;ve always advocated for specializing.  It&#8217;s what made my career what it is today.  So, this week I&#8217;ve been focused on Cryptography and Data Security, and I thought, if you aspire to pursue a career in cryptography, what would one need to focus on.  Turns out there are several areas of study that can provide a strong foundation, and they include mathematics, computer science, and information security. Here are some thigns to consider in each of these areas.</p>



<h2 class="wp-block-heading">Mathematics:</h2>



<p>Cryptography heavily relies on abstract algebraic concepts such as groups, rings, and fields. For this you would need to learn Abstract Algebra.  Also, understanding the properties of integers, prime numbers, and modular arithmetic (Number Theory) is important in cryptography. And cryptanalysis often involves statistical analysis and probability theory. Personally, this is why I&#8217;m not specialized in cryptography.  I know it.  I understand things like Diffie-Hellman and IPsec and so on.  But too much math hurts my little brain, so I leave this to the smart people!</p>



<h2 class="wp-block-heading">Computer Science:</h2>



<p>Efficient algorithms and data structures are essential for implementing cryptographic systems.  You would pick this knowledge up in most computer science programs.  You would likely also pick up a programming language.  Python is common.  Others are as well, but I like Python.  You would need some programming skills if you are planning to develop cryptographic software.  ANd I think last, but not least in this area is having an understanding low-level hardware and software principles.  This is beneficial for optimizing cryptographic implementations (something else I cannot do).</p>



<h2 class="wp-block-heading">Information Security:</h2>



<p>Now we&#8217;re talking!  Cryptography is a core area of information security, covering symmetric and asymmetric cryptography, hash functions, digital signatures, and cryptanalysis techniques.  This is the stuff I&#8217;ve gotten just good enough at to be dangerous.  My favorite books on the topic are <a href="https://www.amazon.com/IPSec-2nd-Naganand-Doraswamy/dp/013046189X/ref=sr_1_4?crid=157DZGFV5FDHJ&amp;dib=eyJ2IjoiMSJ9.kkbQJnWk3jMzSHSozb9J3J7xhh2rCMmGXIsz6iw1zsTv9I5zZg4iwRjaWKL906MAeebK0SI5ksbbScBuYW5fGuRNNeQzhpVjcQvCE0pJwT6oMIM4cdD9IeFS-LgER-PPWbcLskEGVkiNl96LtzwRqtgaIYHF5zYzzZxugy12lBxg2e8QesaCu7eJs7SXCu4N7MctMsblvjUwKU27GwinWqQ4rat9Nt-GEOLqG6uWp5OnkCHD0Xis0LB3PtbluwVsG8L0rZyb6QBpXLVMf2mTMkwb-l4NFI6Sqo3Lv0-WczI.NL3bTpJi2XHwLRJeI4J5oEkYv9d6pz1Fg5wWX8zhkAA&amp;dib_tag=se&amp;keywords=IPSec&amp;qid=1713552169&amp;sprefix=ipsec%2Caps%2C180&amp;sr=8-4"><em>IPSec, Second Edition</em> </a>and <a href="https://www.amazon.com/Applied-Cryptography-Protocols-Algorithms-Source/dp/1119096723/ref=sr_1_2?crid=V2ZI3GP46ME7&amp;dib=eyJ2IjoiMSJ9.u4S1OZuqfcjj2IZapD4z3iV5n_4e46w8N1s_Nv9FpBPMdNlhzK86IE_dmU3N5BdY1nXQcDpTr7xs1K9I0e9TsV13cpXMFB1nGvLpOUSmlfSiR-yqe7z95tN3dqCNxByKsIGZbYyGadUHA9ncjHF6GNWcnmz4Nyhe4cTb2R9ukdIGH-ouoIeT-Tvv9jFwxfad22UbxG_mn5qF1-ykiyu2AGT77NmHwOGN5UkDfCfAFCfeM3gCMKUadLw0b7tBqku894Zo5wnWt6godd0nW7P3GbvtuYbZYt4CYePARKqe7EY.Vrq5oUdUiLfpyFX1JKXxwjApD8cAmJmLHbP67quHlTk&amp;dib_tag=se&amp;keywords=Bruce+Schneier&amp;qid=1713552313&amp;sprefix=bruce+schneier%2Caps%2C301&amp;sr=8-2">Applied Cryptography: Protocols, Algorithms and Source Code in C</a>.</p>



<p>Along a similar vein, you need to have knowledge of areas like access control, authentication, and intrusion detection are relevant for designing secure systems that incorporate cryptography.</p>



<p>So what does a typical career path for someone in Cryptography look like?</p>



<h2 class="wp-block-heading">A typical career path in cryptography </h2>



<p>A typical career path in cryptography might look like this:</p>



<ol class="wp-block-list">
<li>Get your education.  This might include a bachelor&#8217;s degree in computer science, mathematics, or a related field, with a focus on cryptography-related courses. Some universities offer specialized programs or concentrations in cryptography and information security, but math is also an option.</li>



<li>Get an Internships </li>



<li>Graduate Studies: You might consider pursuing a master&#8217;s or doctoral degree in cryptography, computer science, or applied mathematics, depending on your interests and career goals. Personally, this was not for me, however for a focus in this space graduate studies provide opportunities for advanced research and specialization.</li>



<li>Get an Entry-Level Position.  And this part kinda stinks.  You may have the degree and some practical experience if you&#8217;ve interned, but not everyone comes out of college and starts a new tech company or joins one of the big cloud companies.  You can seek entry-level positions as a cryptographer, security analyst, or software engineer in various industries, such as technology companies, financial institutions, government agencies, or research organizations and this will give you real-world experience and start building your <a href="https://80000hours.org/key-ideas-2023/career-capital/#:~:text=A%20key%20strategic%20consideration%20is,more%20productive%20over%20their%20career.">career capital.</a></li>



<li>Keep seeking professional development opportunities and certifications.  You need to do this to update your knowledge.  Attend conferences, workshops, and training programs whenver you can. Obtaining industry-recognized certifications, such as the Certified Encryption Specialist (EC-Council) or the Certified Information Systems Security Professional (CISSP), can enhance your credibility and career prospects.</li>



<li>Keep looking for advancement opportunities.  This will come with time.  And as you gain experience and begin to stand out in your specialty, you can progress to roles such as lead cryptographer, cryptography researcher, security architect, or cybersecurity consultant. Some cryptographers also transition into academia, teaching and conducting research at universities or research institutions if that&#8217;s your thing.</li>
</ol>



<p>Whatever you decide, it&#8217;s important to recognize that cryptography is a highly specialized field, and career paths may vary a lot depending on the industry, organization, and your interests and goals. In fact, you may head down this path and decide it&#8217;s not for you.  Still the knowledge you gain will invariably help you in adjacent areas.  That being said, I think that continuous learning, staying updated with the latest developments in cryptography, and maintaining a strong understanding of evolving security threats and countermeasures will be your key to a successful career in this field. I hope you found this useful.  Happy Careering!</p>
<p>The post <a href="https://brandonjcarroll.com/specializing-in-a-cryptography-career/">Specializing in a Cryptography Career</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://brandonjcarroll.com/specializing-in-a-cryptography-career/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18851</post-id>	</item>
		<item>
		<title>Data Security and Cryptography on AWS</title>
		<link>https://brandonjcarroll.com/data-security-and-cryptography-on-aws/</link>
					<comments>https://brandonjcarroll.com/data-security-and-cryptography-on-aws/#respond</comments>
		
		<dc:creator><![CDATA[Brandon Carroll]]></dc:creator>
		<pubDate>Fri, 19 Apr 2024 18:18:23 +0000</pubDate>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[AWS]]></category>
		<guid isPermaLink="false">https://brandonjcarroll.com/?p=18848</guid>

					<description><![CDATA[<p>As organizations increasingly rely on cloud services to store and process sensitive data, cryptography and data security become evident areas that a security professional needs to be familiar with. It&#8217;s ...</p>
<p>The post <a href="https://brandonjcarroll.com/data-security-and-cryptography-on-aws/">Data Security and Cryptography on AWS</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>As organizations increasingly rely on cloud services to store and process sensitive data, cryptography and data security become evident areas that a security professional needs to be familiar with. It&#8217;s true, cloud environments present unique security challenges and risks, so being ready to address them means you need to understand the concepts and the tools available. This article is intended to be a quick explanation of these concepts with some direction on more detailed articles, user guides, and developer guides, that will prepare you to take on the task. Let&#8217;s dig in.</p>



<h2 class="wp-block-heading">Encryption at Rest</h2>



<p>Encryption at rest refers to encrypting data when it is stored, as opposed to when it is being transmitted (encryption in transit). There are three main approaches for encryption at rest:</p>



<ol class="wp-block-list">
<li>Server-side encryption: The service storing the data (e.g. Amazon S3) encrypts the data when it is received and decrypts it when requested by an authorized user. This is seamless for developers but allows any role with appropriate permissions to decrypt the data.</li>



<li>Client-side encryption: The application encrypts the data before sending it to the storage service, so the service never has access to the unencrypted data. This provides more control over who can decrypt the data.</li>



<li>Client-side in-browser encryption: Sensitive data is encrypted in the user&#8217;s browser before being sent to the application, protecting it even if it is accidentally exposed by intermediary services.</li>
</ol>



<p>&nbsp;Encryption at rest helps protect sensitive data from unauthorized access if it is lost, stolen, or accidentally exposed. It is an important technique for preserving user privacy and preventing disclosure of sensitive business data throughout the data lifecycle, from collection to storage to processing and sharing.</p>



<p>Check out the <a href="https://brandonjcarroll.com/links/cnn9i">Protecting data at rest</a>section of the Well architected framework for more details.</p>



<h2 class="wp-block-heading">Encryption in Transit</h2>



<p>Encryption in transit (opposite of encryption at rest) refers to the encryption of data while it is being transmitted over a network from one point to another, typically between a client and a server. The data is encrypted before being sent and decrypted after being received, but it may be stored in plaintext at the source and destination systems</p>



<p>Check out the <a href="https://brandonjcarroll.com/links/lhmnw">Protecting data in transit</a>section of the Well architected framework for more details.</p>



<h2 class="wp-block-heading">Key Management</h2>



<p>Key management is an important aspect of encryption solutions. It involves protecting encryption keys at rest so that the keys can never be used outside the authorized system, and ensuring that the authorization to use encryption keys is independent from how access to the underlying data is controlled. This separation of key access from data access helps prevent issues like overly permissive data access policies from compromising encrypted data.</p>



<p>The AWS Service that handles key management is called KMS and you can learn KMS concepts<a href="https://brandonjcarroll.com/links/xrwqk">in this developer guide</a>.</p>



<h2 class="wp-block-heading">Cryptographic Services</h2>



<p>Cryptographic services refer to the application of cryptography techniques and protocols to secure data, communications, and systems. These services include encryption, digital signatures, key management, and authentication mechanisms, enabling confidentiality, integrity, and non-repudiation of information exchanged over insecure networks or stored in vulnerable environments.</p>



<p>AWS offers a few services specific to Cryptographic Services. You can <a href="https://brandonjcarroll.com/links/uyray">learn about them her</a>e.</p>



<h2 class="wp-block-heading">Compliance and Regulations</h2>



<p>Compliance and regulations refer to the set of rules, guidelines, and standards that organizations must adhere to, ensuring data security and privacy. These standards, such as HIPAA for healthcare organizations and PCI DSS for companies handling payment card data, mandate specific data security and encryption requirements to protect sensitive information and prevent data breaches.</p>



<p>You can learn how AWS services and tools can help <a href="https://brandonjcarroll.com/links/7sy3t">achieve compliance here</a>.</p>



<h2 class="wp-block-heading">Best Practices and Recommendations</h2>



<p>When it comes to data security and cryptography on AWS, some key best practices include: Implementing encryption at rest and in transit using AWS services like AWS Key Management Service (KMS) and AWS Certificate Manager. Regularly rotating encryption keys and following the principle of least privilege for access to encrypted data and key material. Leveraging AWS services like Amazon Macie and AWS CloudTrail to monitor and audit data access and encryption activities for compliance purposes.</p>



<p>I encourage you to become familiar with these best practices on AWS. You can <a href="https://brandonjcarroll.com/links/6jtm3">read more here</a>.</p>
<p>The post <a href="https://brandonjcarroll.com/data-security-and-cryptography-on-aws/">Data Security and Cryptography on AWS</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://brandonjcarroll.com/data-security-and-cryptography-on-aws/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18848</post-id>	</item>
		<item>
		<title>Questions from Readers: How can I prepare for and take certification exams if I have dyslexia?</title>
		<link>https://brandonjcarroll.com/questions-from-readers-how-can-i-prepare-for-and-take-certification-exams-if-i-have-dyslexia/</link>
					<comments>https://brandonjcarroll.com/questions-from-readers-how-can-i-prepare-for-and-take-certification-exams-if-i-have-dyslexia/#comments</comments>
		
		<dc:creator><![CDATA[Brandon Carroll]]></dc:creator>
		<pubDate>Thu, 18 Apr 2024 17:00:00 +0000</pubDate>
				<category><![CDATA[Learning and Certification]]></category>
		<category><![CDATA[goals]]></category>
		<category><![CDATA[Learning]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[career]]></category>
		<guid isPermaLink="false">https://brandonjcarroll.com/?p=18840</guid>

					<description><![CDATA[<p>I&#8217;ve been in Networking and Cloud Infrastructure Security for a long time. I was a Cisco Trainer from January 2001 up to around 2018. I understand the challenges that individuals ...</p>
<p>The post <a href="https://brandonjcarroll.com/questions-from-readers-how-can-i-prepare-for-and-take-certification-exams-if-i-have-dyslexia/">Questions from Readers: How can I prepare for and take certification exams if I have dyslexia?</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>I&#8217;ve been in Networking and Cloud Infrastructure Security for a long time.  I was a Cisco Trainer from January 2001 up to around 2018. I understand the challenges that individuals with dyslexia may face when working on certifications because I have taught them, I&#8217;ve talked with them, I&#8217;ve seen them struggle and I&#8217;ve seen them overcome and succeed. </p>



<p>I can&#8217;t say I have done it myself. I only know what I&#8217;ve seen others do and what they have told me. I know what I have witnessed. I also know that Dyslexia does not reflect an individual&#8217;s intelligence or potential. </p>



<p>I am posting this because a connection on LinkedIn told me that studying for and taking certification exams are challenging, because they have to keep re-reading to comprehend technical topics.  They asked my point of view.  Here are the questions I asked. </p>



<h2 class="wp-block-heading">Questions</h2>



<ol class="wp-block-list">
<li>Is there assistive technology like text-to-speech software or applications that can help by reading study materials to you that could help?. </li>



<li>Do you break down study materials instead of trying to tackle an entire chapter or section at once? If so, does that help with retention?</li>



<li>I know Dyslexia can affect visual processing, so would creating visual aids like mind maps or diagrams help you better understand and remember more technical concepts?</li>



<li>Some certification providers offer accommodations for individuals with learning disabilities, such as extended time or the ability to use assistive technology during the exam. <a href="https://aws.amazon.com/certification/policies/before-testing/#Requesting_Accommodations">AWS does this</a>. So does <a href="https://www.pearsonvue.com/accommodations/pv_review.asp?clientName=Cisco%20Systems">Cisco</a> and Microsoft. Are you asking for these?</li>
</ol>



<h2 class="wp-block-heading">Wrap Up</h2>



<p>I can&#8217;t begin to say I know what it&#8217;s like, but it is inspiring to see someone that is faced with a challenge like Dyslexia be successful in their career and certification aspirations. If you have other thoughts or want to share your experience, I really want to hear it.  Please post them in the comments. </p>
<p>The post <a href="https://brandonjcarroll.com/questions-from-readers-how-can-i-prepare-for-and-take-certification-exams-if-i-have-dyslexia/">Questions from Readers: How can I prepare for and take certification exams if I have dyslexia?</a> appeared first on <a href="https://brandonjcarroll.com">Brandon J Carroll</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://brandonjcarroll.com/questions-from-readers-how-can-i-prepare-for-and-take-certification-exams-if-i-have-dyslexia/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">18840</post-id>	</item>
	</channel>
</rss>
