Skip to main content
Page header background image

Other Events

2023 CISOExecNet Breakfast Roundtable – Securing The Cloud, SaaS, and DevOps

CISO Executive Network

Any series where we discuss cloud, data protection, or third-party risk members bring up their concerns with ‘Shadow IT’ - SaaS solutions that business units purchase or users buy to get their jobs done without going through the traditional IT org. Do we just need to admit that Shadow IT is IT and learn to secure it? In this series we will talk about how to gain visibility into SaaS and secure it.

How are we ensuring that our assets are secure when they are not in our data centers? How do we secure both apps we build and the SaaS applications we are utilizing?

Security Controls Covered: CASB, AppSec, DevOps, Third-Party Risk Management, IAM, Cloud DLP, Cloud Config Management, Container Security, API Security

The cloud is our reality and nearly every application our firms use today either SaaS or third-party hosted. Almost none of our data resources is on a device we can touch. Most of the apps being developed for us or our third-party providers are being done with DevOps processes. Thus, re-architecting our security portfolio to have better visibility and control over the data and apps that we no longer host has become a top priority. In this series, we will look at better ways to manage the risk to our resources in the cloud, third-party providers, and devops processes.

Topics likely to be part of this discussion include:

  • Cloud security frameworks and standards
  • Third-party risk management models
  • Cloud security posture management tools
  • DevOps security models
  • Open source risks
  • API security]
  • Container security
  • Role of IAM in cloud and DevOps security
  • Data protection as more of our data moves to the cloud and third parties
  • Challenges of IaaS

Sponsored by Wiz & Varonis

Services