Adam Števko - Journey to Securing the Cloud: Detecting and Fixing Misconfigurations at Datadog

Journey to Securing the Cloud: Adam Števko shares best practices for detecting and fixing misconfigurations at Datadog, highlighting the importance of prioritizing tools, integrating security into development, and providing feedback to developers.

Key takeaways
  • Prioritize using a limited number of tools to detect and fix misconfigurations, and consider the context of the findings.
  • Review and analyze the total number of findings, and prioritize remediation based on impact and criticality.
  • Implement automated remediation to reduce manual effort and improve efficiency.
  • Use tools like Terraform to manage cloud resources and reduce the risk of misconfigurations.
  • Engage with developers and stakeholders to ensure that security is integrated into the development process.
  • Provide feedback early and often to developers, and make them part of the solution.
  • Use a standardized format for reporting and remediation, and provide contextual information to aid in decision-making.
  • Implement a systematic approach to response and remediation, and track performance and benchmark remediation and detection.
  • Use modularity and simplicity to improve the security posture, and prioritize capabilities over features.
  • Integrate security teams with development teams to ensure that security best practices are followed.
  • Use open-source solutions, and consider contributing back to the community to improve tooling and remediation.
  • Focus on capabilities rather than features, and prioritize practicality over theoretical complexity.
  • Improve communication and notification between teams, and ensure that stakeholders are engaged and informed.