Stop Playing Security Whack a Mole: Enforcing Cloud Security with Organizational Controls

Stop Playing Security Whack a Mole: Enforcing Cloud Security with Organizational Controls

Source: YouTube · SANS Cloud Security · published Nov 14, 2025 · 52:24

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

BLUF: The speaker advocates shifting cloud security from reactive detection to proactive prevention by implementing organizational-level controls, which eliminate misconfigurations at scale and significantly improve the signal-to-noise ratio for security teams 0:00.

Key Takeaways:
• The speaker introduces Lucid Truth Technologies, their SANS Technology Institute master's degree, GSE certification, and current teaching roles 0:00.
• Cloud environments enable unprecedented preventive control at the infrastructure level, allowing organizations to "drain the swamp" rather than just detect issues 1:55.
• Organizational controls improve detection by reducing noise; alerts that bypass preventive controls become high-priority indicators of failure 3:30.
• AWS uses Service Control Policies (SCPs) as permission ceilings, while Azure Policy offers flexible effects like audit, modify, and deny for comprehensive governance 5:45.
• Google Cloud utilizes organizational constraints and conditional deny policies, though it lacks the extensive built-in policy library found in Azure 8:15.
• Safe implementation requires a phased lifecycle: design, test via sandbox or audit mode, validate, and gradually enforce, avoiding immediate production deployment 10:30.

The presentation concludes that mature cloud security relies on preventive organizational controls to ensure compliance by design, significantly improving the signal-to-noise ratio for detection teams.

Sources:

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right. Well, welcome everybody. I've been looking forward to this talk for a while now. And a little bit more about me. I'm the owner of Lucid Truth Technologies. We're a digital forensics firm that focuses on cloud forensics as well as forensics of mobile devices, laptops, and so forth. And I use a lot of the cloud technologies to do all this. I got my master's in information security engineering from the SANS technology institute. So I always like to mention when I'm doing a presentation that I'm a proud alumni of STI. Have multiple security certifications including the GK security expert which is the top certification for SANS. I teach a couple classes for SANS. our new SEK502 cloud security tactical defense as well as uh sect 510 the cloud security engineering and controls course. …