Book Image

Mastering Cloud Security Posture Management (CSPM)

By : Qamar Nomani
Book Image

Mastering Cloud Security Posture Management (CSPM)

By: Qamar Nomani

Overview of this book

This book will help you secure your cloud infrastructure confidently with cloud security posture management (CSPM) through expert guidance that’ll enable you to implement CSPM effectively, ensuring an optimal security posture across multi-cloud infrastructures. The book begins by unraveling the fundamentals of cloud security, debunking myths about the shared responsibility model, and introducing key concepts such as defense-in-depth, the Zero Trust model, and compliance. Next, you’ll explore CSPM's core components, tools, selection criteria, deployment strategies, and environment settings, which will be followed by chapters on onboarding cloud accounts, dashboard customization, cloud assets inventory, configuration risks, and cyber threat hunting. As you progress, you’ll get to grips with operational practices, vulnerability and patch management, compliance benchmarks, and security alerts. You’ll also gain insights into cloud workload protection platforms (CWPPs). The concluding chapters focus on Infrastructure as Code (IaC) scanning, DevSecOps, and workflow automation, providing a thorough understanding of securing multi-cloud environments. By the end of this book, you’ll have honed the skills to make informed decisions and contribute effectively at every level, from strategic planning to day-to-day operations.
Table of Contents (26 chapters)
1
Part 1:CSPM Fundamentals
6
Part 2: CSPM Deployment Aspects
11
Part 3: Security Posture Enhancement
19
Part 4: Advanced Topics and Future Trends

Further reading

If you’re interested in diving deeper into DevSecOps and CSPM automation, here is a curated list of books and websites that offer valuable insights and practical guidance:

  • Books:
    • The DevOps Handbook: How to Create World-Class Agility, Reliability, & Security in Technology Organizations, by Gene Kim, Jez Humble, Patrick Debois, and John Willis
    • DevSecOps: Securing Software in the DevOps World, by Shannon Lietz, Daniel Kennedy, and Rugged DevOps, Inc.
    • Site Reliability Engineering: How Google Runs Production Systems, by Niall Richard Murphy, Betsy Beyer, Chris Jones, and Jennifer Petoff
  • Websites and blogs:
    • DevOps.com: A comprehensive resource for DevOps and DevSecOps news, articles, webinars, and best practices (DevOps – The Web’s Largest Collection of DevOps Content)
    • The DevOps Institute: This site offers certifications, articles, and resources on DevOps practices, including DevSecOps (DevOps Certifications — DevOps Institute)
    • National...