Comcast's Jearvon Dharrie says, "Automation is a requirement, not a feature." This talk describes his team's journey into public cloud, and how they took control of their infrastructure.
A common solution to cloud security is the gatekeeper model. Old-school security teams think they can prevent breaches by locking down the network and having all requests funnel through a ticket system.
But this model often makes your cloud less secure: Solutions need to be implemented for each service and there is a lack of consistency. It also adds friction, so teams tend to skip it.
In this talk, Dharrie discusses creating a security framework for your enterprise. It takes principles of automation from DevOps and applies it to security. For example:
Automating Multi-Cloud, Multi-Region Vault for Teams and Landing Zones
How Discover Manages 2000+ Terraform Enterprise Workspaces
Architecting Geo-Distributed Mobile Edge Applications with Consul
A Field Guide to Zero Trust Security in the Public Sector