from Hacker News

On Establishing a Cloud Security Program

by aburan28 on 5/19/21, 7:49 PM with 3 comments

  • by uzakov on 5/20/21, 9:11 AM

    In many ways this reminds me of OWASP SAMM, which is a framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. For anyone interested in having data driven, defined way to measure and scale security I am strongly advising to have a look at this project https://owasp.org/www-project-samm/
  • by tpmx on 5/19/21, 10:35 PM

    Maybe lead with defining the whats and the whys of a "cloud security program", to begin with?