TrustOnCloud

204 posts

TrustOnCloud banner
TrustOnCloud

TrustOnCloud

@trustoncloud

TrustOnCloud provide cloud control catalogs for each Cloud service; based on threat models, audit-ready, and always up-to-date.

Katılım Ocak 2021
40 Takip Edilen247 Takipçiler
TrustOnCloud
TrustOnCloud@trustoncloud·
4/ GCP #BigQuery: 3% covered. 34 of 35 controls missing. Most are medium severity: IAM entity access, row-level security, authorized encryption.
English
1
0
2
30
TrustOnCloud
TrustOnCloud@trustoncloud·
1/ We just open-sourced @wiz_io CCR packages for AWS S3, Azure Storage & GCP BigQuery. Default Wiz coverage: ~34% for these services. Here's what's missing and why it matters for regulated enterprises 🧵
TrustOnCloud tweet media
English
1
1
2
54
TrustOnCloud
TrustOnCloud@trustoncloud·
Before the next re:Invent: ✅ Pull daily during burst weeks ✅ Use the API, not just RSS ✅ Add completeness checks: make "missing updates" an alert, not an accident (4/5)
English
1
0
1
16
TrustOnCloud
TrustOnCloud@trustoncloud·
🚨 Using AWS "What's New" #RSS feed for cloud monitoring? You might be missing critical updates. A few years back, our dashboards stayed green while we went blind to changes. Here's what happened 🧵
TrustOnCloud tweet media
English
1
0
1
33
TrustOnCloud
TrustOnCloud@trustoncloud·
If you rely on release notes alone, you assume a clean transition. Instead, you get a period of hybrid behavior where: • Attack surfaces emerge in the gap between old and new service identities • New functionality may not inherit security controls in the way teams expect
English
1
0
3
21
TrustOnCloud
TrustOnCloud@trustoncloud·
Docs say one thing. The #API does another. This is why we test everything by hand. During a recent deep-dive into Amazon Q in Connect, our researcher Hafsa Hafeez found a discrepancy that most tools miss.
TrustOnCloud tweet media
English
1
1
2
74
TrustOnCloud
TrustOnCloud@trustoncloud·
“We have the AI. We just can’t get GRC to say yes.” Most AI projects don’t stall in development. They stall in security review. Security wants certainty. GRC wants an audit trail. Engineering wants to ship. TrustOnCloud helps align all three by turning control requirements into clear, testable Jira tasks with implementation and validation steps. 🚀 Get AI tech secured and approved: trustoncloud.com/get-ai-tech-se… #CloudSecurity #GRC #AI #DevSecOps #CloudGovernance #CloudSecurity
English
0
0
1
65
TrustOnCloud
TrustOnCloud@trustoncloud·
𝗕𝗿𝗶𝗻𝗴 𝗰𝗼𝗻𝘀𝗶𝘀𝘁𝗲𝗻𝗰𝘆, 𝘀𝗽𝗲𝗲𝗱, 𝗮𝗻𝗱 𝗰𝗹𝗮𝗿𝗶𝘁𝘆 𝘁𝗼 𝗲𝘃𝗲𝗿𝘆 𝗻𝗲𝘄 𝗰𝗹𝗼𝘂𝗱 𝘆𝗼𝘂 𝗼𝗻𝗯𝗼𝗮𝗿𝗱. When you’re asked to support a new cloud provider, the challenges stack up quickly. Each platform has its own controls, compliance rules, and unfamiliar workflows. Without a consistent framework, security work becomes manual, repetitive, and slow. 𝗛𝗶𝗴𝗵-𝗽𝗲𝗿𝗳𝗼𝗿𝗺𝗶𝗻𝗴 𝗰𝗹𝗼𝘂𝗱 𝘁𝗲𝗮𝗺𝘀 𝗳𝗼𝗰𝘂𝘀 𝗼𝗻 𝘁𝗵𝗿𝗲𝗲 𝘁𝗵𝗶𝗻𝗴𝘀: ✔️ Standardizing every cloud with a single control library across AWS, Azure, and Google Cloud. ✔️ Onboarding new services fast with repeatable, audit-ready workflows ✔️ Giving engineers instant clarity with platform-specific guidance Learn more: trustoncloud.com/support-your-c… #CloudSecurity #MultiCloud #Compliance #DevSecOps #TrustOnCloud
TrustOnCloud tweet media
English
0
0
1
32