with-agents

Cloud Security Basics

Top 3 access risks in Cloud Security

Google Cloud Tech 2 of 10
In this collection Browse 10 summaries 2 of 10

This episode frames access security as admitting the right identity, from an acceptable device and context, to the right resource through overlapping controls.

Key Points Covered

  • Access risk is broader than stolen passwords: The examples include phishing, man-in-the-middle interception, denial-of-service attacks, and accidental or malicious use of excessive permissions [00:01:04]-[00:02:10].
  • Network controls form one layer: The 2020 architecture account describes encryption, TLS termination, load balancing, and centralized traffic signals as defenses against interception and denial-of-service traffic [00:02:10]-[00:03:13].
  • Authentication should resist phishing: Risk-aware sign-in and hardware security keys provide evidence beyond a password alone [00:03:13]-[00:04:15].
  • Authorization also needs context: Identity-Aware Proxy and endpoint management are presented as ways to include application policy, group or domain membership, and device state in access decisions [00:04:15]-[00:05:20].
  • Treat this as dated guidance: This is a 2020 product and security explanation; verify current Google Cloud documentation, IAM behavior, defaults, products, UI, pricing, endpoint controls, and incident-response guidance before use.

Full video: https://www.youtube.com/watch?v=IHBoUADMrHc(opens in a new tab)