CSA HKM Knowledge Sharing Event – March 2021

Another great event is happening at the Cloud Security Alliance Hong Kong & Macau Chapter in March. Last month, we talked about securing cloud environment using SASE and Zero Trust. This month, we switched to secure the cloud environment from a Cloud Service Provider (CSP) perspective. This round, we invited Ken Zhang, Practice Manager of Amazon Web Services (AWS) to tell us the Top Ten AWS Security Tips.

In this session, you will hear fundamental recommendations for simple to implement, low or no cost AWS security solutions that offer potentially high impact. AWS services, including Amazon GuardDuty, AWS Security Hub and AWS CloudTrail enable better detection and response capabilities – making intrusion detection and incident response simpler and less costly than typical on-premises IT environments. It time allows, there would potentially be some AWS Console demo too. This will definitely be a resourceful session for you.

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants will claim 1 CPE.

DATE: 25 March, 2021 (Thursday)

TIME: 12:30 – 01:30 pm

VENUE: Webinar (in English)

SPEAKER: Ken Zhang, Practice Manager, Amazon Web Services (AWS)

TOPIC: Top Ten AWS Security Tips

THE SPEAKER:

Ken Zhang, Practice Manager of Amazon Web Services (AWS). Ken specializes in cloud, strategy, security, transformation, architecture and change management. He has experience helping organizations with their transformation journeys in banking, insurance, retail, health service and manufacturing. He also holds a variety of widely-recognized tech certificates and an MBA from a global top 30 business school. He is passionate about helping organizations to capture value and provide better experience to their customers.

View the Presentation: https://youtu.be/WyZv99TG5Dg

Upcoming Events in February and March 2021

After Chinese New Year, many exciting activities and events are coming.

Firstly, on this coming Thursday (25 Feb 2021), we will have our knowledge sharing session by Zscaler on SASE and Zero Trust Model. Remember to register and join. More details can be found here.

Secondly, Information Security Summit – one of the most attractive, non-vendor driven, local Cybersecurity event will be held on March 9 – 10, 2021. This year, the Conference will be organised quite different from previous years due to the New Norm after Covid-19 virus. All the events will be organised online. Events and talks will be more interesting. Speakers from other countries will be conducting from other time zone to support us this year. For interactive panel discussion, some of the panelist will be discussing through the webinar from their home town on the topic – Challenge of Securing the New Norm – the Remote, Mobile, Decentralised and Virtual Business. Do register the conference and workshops. Do visit the link about the IS Summit 2021.

Periodically, CSA will have new publications. Recently CSA published the new report on Blockchains – Blockchains in the Quantum Era and report on IoT – CSA IoT Security Controls Framework v2. Stay tune with research from CSA.

Finally, Certificate of Cloud Auditing Knowledge (CCAK) is coming. More information about the joint certification program with ISACA will be clarified soon. At this stage, 400+ pages study guide are available in ISACA store. Stay tune with CCAK site from CSA.

CSA HKM Knowledge Sharing Event – February 2021

The Chinese New Year is coming. The Cloud Security Alliance Hong Kong & Macau Chapter wishes you Happy Chinese New Year.

We will continue our Knowledge Sharing Event after the Chinese New Year and the topic will be “How to leverage cloud platform to transform traditional security infrastructure to Secure Access Service Edge (SASE) and Zero Trust model to facilitate digital transformation”, which will be presented by Jones Leung of Zscaler.

In the “New Normal” situation, more company has to move away from existing design and implementation of securing corporate network through VPN to SASE. How to deploy and implement SASE is a hot topic.

Thanks for the success of cloud in the past few years, now there are far more innovative ways to operate our IT platform to support business growth and increase business agility, and the same can apply to securing a new digital enterprise. Secure Access Service Edge (SASE) is one of the most popular approaches to provide different business data access experience and coverage to new threats. This session is to share common approaches to deliver SASE, their fundamental differences, pros and cons for different approaches, and also how SASE can bring you closer to adopting zero trust access model.

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants will claim 1 CPE.

DATE: 25 February, 2021 (Thursday)

TIME: 12:30 – 01:30 pm

VENUE: Webinar (in Cantonese)

SPEAKER: Mr. Jones Leung, Systems Engineering Manager, ASEAN and Greater China, Zscaler, Inc

TOPIC: How to leverage cloud platform to transform traditional security infrastructure to Secure Access Service Edge (SASE) and zero trust model to facilitate digital transformation

THE SPEAKER:

Mr. Jones Leung has been with Zscaler for more than 7 years, promoting cloud transformation to enterprises and the industry. Over the past 20 years, Jones worked for many different top IT companies, such as Palo Alto Networks, Cisco and Blue Coat, and is a very well-recognized and knowledgeable technology evangelist in the region.

REGISTRATION: https://csakse2102.eventbrite.hk

Cloud Controls Matrix v4 part 1 published in Q1 2021

Cloud Control Matrix is the core component used in providing the cloud security compliance check.

CCM v3.0.1 was initially released 6 years ago. CSA determined that it is time to revise and provide the community with vendor-neutral security and privacy control framework.

More controls are added and more guidelines will be extended from the CCM v4.

CCM v4 can be downloaded from https://cloudsecurityalliance.org/research/cloud-controls-matrix/

CCM Implementation Guidelines will be published Q2, 2021

CCM Auditing Guidelines will be published Q3, 2021

Refer to the blog in CSA, https://cloudsecurityalliance.org/blog/2021/01/21/the-csa-cloud-controls-matrix-ccm-v4-raising-the-cloud-security-bar-to-the-next-level/

CSA HKM Knowledge Sharing Event – January 2021

Year 2020 is over. Welcome 2021.

In this year Cloud Security Alliance Hong Kong & Macau Chapter will continue to adopt the “New Normal” arrangement for our activities. In fact, with all your support in the last few months, it seems that with the new method, communication channel and sharing session time, more members and participants can enjoy the power of cloud computing. This year we will arrange more sharing both from cloud customers, cloud service providers and other experts.

“Start Big is always better to start with Big CSP player”. As you all know, Azure Cloud is one of the largest Cloud Service Providers, we have arranged the first sharing event with Microsoft Cloud Solution Architect in Hong Kong to cover DevOps Security Best Practices in Microsoft Azure.

Ms. Wai Man HUI, cloud solution architect will lead us through Azure’s DevOps Security Best Practices. During the talk, Wai Man will tell us more about DevOps with GitHub and Azure, how to protect secrets properly in Azure cloud environment. She will also tell us how to enhance security in Azure environment through demonstration in real life too.

The topics include :

– DevOps with GitHub And Azure
– Best practices for strong secret management
– How Key Vault can be used to enhance the security of your Azure environment

Please do not miss this opportunity to learn from the expert and get connected with your peers.

This is just the beginning of our cloud security journey in 2021. More sharing and event will be coming.

Participants will claim 1 CPE.

DATE: 28 January, 2021 (Thursday)

TIME: 12:30 – 01:30 pm

VENUE: Webinar (in Cantonese)

SPEAKER: Wai Man HUI, Cloud Solution Architect, Microsoft, Hong Kong

TOPIC: DevOps Security Best Practices with Microsoft Azure 

THE SPEAKER:

Wai Man HUI is a Cloud Solution Architect in Microsoft (Hong Kong) team that specialised in DevOps area. She worked on development and implementing business solution for company size from 50+ employees to 50,000+ employees. She also helps company in transforming their development and development workflow from traditional environment to cloud platform.

PRESENTATION FILE

CSA HKM Knowledge Sharing Event – December 2020

Christmas is coming and we all wish Covid-19 will be over soon. Cloud Security Alliance Hong Kong & Macau Chapter is arranging another Knowledge Sharing Event on December 17, 2020, a week before Christmas.

As a continuation of the last two Knowledge Sharing Event, we continue to focus on hot cloud security topic – PaaS and Microservices Security topics.

Security microservices provide security functionality, such as encryption and authentication, to calling applications. As microservices (e.g. ‘serverless’ RESTful JSON APIs) become more common in both the cloud and internal architectures, there is a trend towards including hardware security module (HSM) based services, making strong security functionality readily available to applications. In this session, you will learn:

* Why microservices are becoming fashionable
* How security microservices make security easier
* Examples of security microservices

This talk will be delivered by Ian Christofis, Principal Managing Consultant, nCipher Security (an Entrust company).

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants can claim 1 CPE.

DATE: December 17, 2020 (Thursday)

TIME: 12:30 – 01:30 pm

VENUE: Webinar

SPEAKER: Ian Christofis, Principal Managing Consultant, nCipher Security (an Entrust company)

TOPIC: Security Microservices – A New Trend

THE SPEAKER:

Ian Christofis is a specialist in information security, including cryptographic security, Public Key Infrastructure (PKI) and identity & access management. He combines a strong understanding of the commercial and strategic business issues with a detailed knowledge of the technology.

He is a Certified Information System Security Professional (CISSP), a Founding Board Member of the Cloud Security Alliance (CSA) Hong Kong & Macau Chapter, sits on the Editorial Board of the Professional Information Security Association (PISA) Journal, and a member of the International Association for Cryptologic Research (IACR).

WATCH PRESENTATION: https://youtu.be/dga_gxwfftQ

PRESENTATION FILE: https://bit.ly/2KvbKM2

CSA HKM Knowledge Sharing Event – November 2020

In last month’s knowledge sharing event, we focused in the methodology to develop and secure our PaaS environment. Do we still need to secure the cloud stem? Do we still need to secure the cloud architecture? How to secure that environment?

The common security challenges faced in the cloud stem from misconfiguration, compliance, and an exploding set of cloud infrastructure services. This session will cover how to combat these challenges and gain visibility into security, compliance, and governance vulnerabilities on your public cloud infrastructure.

We will go over the latest security offering that helps teams build a better cloud architecture. You can also look forward to hundreds of out-of-the-box, step-by-step remediation guides, enabling DevSecOps teams and cloud architects to quickly resolve vulnerabilities.

This upcoming knowledge sharing event, we invited Tony Lee, Head of Consulting of Trend Micro will lead us to the “Cloud operational excellence – Guardrails to build exceptional architecture & avoid misconfigurations“.

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants can claim 1 CPE.

DATE: November 05, 2020 (Thursday)

TIME: 12:30 – 01:30 pm

VENUE: Webinar

SPEAKER: Tony Lee, Head of Consulting of Trend Micro

TOPIC: Cloud operational excellence – Guardrails to build exceptional architecture & avoid misconfigurations

THE SPEAKER:

Tony Lee is the Head of Consulting at Trend Micro – a global leader in cyber security solutions. He is responsible for the provision of security advice and solution consultation for large scale IT users and key channel partners in Hong Kong.

Tony has more than 13 years experiences in strategic planning and requirements analysis, with special focus on cloud security deployment, cyber threats response and emerging technologies analysis. As a technology evangelist for Trend Micro, he has been acting as a high profile speaker for major industry events in the region, specialized in evolving cyber threats such as ransomware and APT attacks.

Tony is a graduate of the Hong Kong Baptist University, where he received a Bachelor of Science degree in computer science.

REGISTATION: https://csakse2011.eventbrite.hk

CSA大中華區發佈《軟體定義邊界(SDP)和零信任》白皮書

CSA大中華區已發佈《軟體定義邊界(SDP)和零信任》白皮書,對如何使用SDP來實現零信任網絡(ZTN),為什麼將SDP應用於網絡連接,以及甚麼是最先進的ZTN實現等問題進行了分析解答。

軟體定義邊界(Software Defined Perimeter, SDP)是一個能夠為OSI七層協定棧提供安全防護的網絡安全架構,實現資產隱藏,並在允許連接到隱藏資產之前使用單個數據包通過單獨的控制和數據平面建立信任連接。 使用SDP實現的零信任網絡使組織能夠更好防禦新變種攻擊方法,以及改善企業所面臨攻擊面日益複雜和擴大的安全困境。

從本質上講,零信任是一種網絡安全概念,其核心思想是組織不應自動信任傳統邊界內外的任何事物,並旨在捍衛企業資產。 實施零信任需要在授予訪問許可權之前驗證所有嘗試連接到資產的事物,並在整個連接期間對會話進行持續評估。

軟體定義邊界(SDP)是零信任策略的最高級實現方案。 CSA已採用並宣導將以下結構應用於網絡連接:

  • 將建立信任的控制平面與傳輸實際數據的數據平面分開。
  • 使用動態全部拒絕(deny-all)防火牆(不是完全deny-all,而是允許例外)來隱藏基礎架構(例如,使伺服器變”黑”,不可見)
  • 丟棄所有未經授權的數據包並將它們用於記錄和分析流量。
  • 訪問受保護的服務之前,通過單包授權(SPA)協定來認證和授權使用者以及驗證設備。
  • 最小授權在此協定中是自帶的。

在該白皮書中,CSA全球SDP工作組和CSA大中華區SDP工作組的多位專家們對SDP如何實現零信任的戰略、價值、實施等內容做了原創和翻譯,相信對廣大的安全專家、CIO、CISO和公司業務高管在考慮企業的零信任落地時會有啟示和説明。

下載《軟體定義邊界(SDP)和零信任》白皮書

CSA HKM Knowledge Sharing Event – October 2020

Container environment is a hot topic in cloud environment especially cloud security area. So after previous two rounds of cloud usage and SaaS cloud security talk, we now start another interesting series of cloud security talk – Cloud Container security talk. We will start our talk from OpenShift and DevSecOps. That are two hot topics in Cloud Computing and Cloud Security Area.

This month we invited William Lok, CTO and Co-founder of TechNet HK to lead us through “Transforming DevOps to DevSecOps with Redhat OpenShift“.

Today, DevOps is an inevitable way to transform the enterprise into digital era and innovate into software company. William will prepare a demo on how a container application governed by series of tool chains and deploy on RedHat OpenShift.

On top of tool chains, William will share how the security perspectives can be fulfilled by transforming DevOps to DevSecOps Journey.

Please do not miss this opportunity to learn from the expert and get connected with your peers.

Participants can claim 1 CPE.

DATE: October 08, 2020 (Thursday)

TIME: 12:30 – 01:30 pm

VENUE: Webinar

SPEAKER: William Lok, CTO and Co-founder of TechNet HK

TOPIC: Transforming DevOps to DevSecOps with Redhat OpenShift

THE SPEAKER:

William Lok, CTO and co-founder of TechNet HK (http://www.technet-asia.com). He leads the company technology visions and directions. He is a frequent speaker on DevOps seminars. He plays an active role in evangelizing opensource, multi-cloud and DevSecOps adoption for Hong Kong, Macau and Taiwan enterprises.

WATCH NOW: https://vimeo.com/466411506

雲安全聯盟大中華區發佈 《雲計算的 11 類頂級威脅》

越來越多的企業正在將數據和應用程式遷移到雲中,這帶來了獨特的資訊安全挑戰。 保護企業在雲中數據的主要責任並不完全在於服務提供者,而主要在於客戶本身。 為了使組織對雲安全問題有新的瞭解,以便他們可以就雲採用策略做出有根據的決策,CSA 大中華區發佈了新版本的《雲計算的11類頂級威脅》(中文版),本報告主要關注11個與雲計算的共用、按需特性相關的問題。 以下是本報告關注的11個主要威脅:

1.資料洩漏。
2.配置錯誤與變更控制不足。
3.缺乏雲端安全架構與策略。
4.身份,憑證,存取和金鑰管理不足。
5.帳戶劫持。
6.內部威脅。
7.不安全的介面和 API 。
8.控制平面薄弱。
9.元結構與應用程式結構失效。
10.有限的雲使用可見度。
11.濫用及違法使用雲服務。

拒絕服務共享技術漏洞以及雲服務提供者數據丟失和系統漏洞之類的問題已不在本報告之列。 這表明由雲服務提供者負責的傳統安全問題似乎已經有效的緩解。 相反我們看到更多的是需要解決那些位於技術棧更高層次的安全問題這些問題是高級管理層決策的結果。

在調查中評分最高的新專案更加細微表明消費者對雲的理解日益成熟。 這些問題本質上是雲計算的固有特性表明消費者正在積極考慮向雲遷移的技術環境。 這些主題涉及潛在的控制平面缺陷元結構和應用結構故障以及有限的雲可見性。 這些新的重點與以前的《 關鍵威脅Top Threats》報告中更為突出的通用威脅風險和漏洞(即數據丟失拒絕服務)明顯不同。

CSA大中華區希望本報告能夠提高組織對最重要的安全問題及其應對措施的認識並在為雲遷移和安全性制定預算時將其考慮在內。 該報告提供了控制建議和參考示例旨在供合規風險和技術人員使用管理層也能夠從本報告的技術趨勢和概述中受益。

下載報告:雲計算的 11 類頂級威脅