<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Research on Securosis</title><link>/tags/research/</link><description>Recent content in Research on Securosis</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 09 Jan 2025 17:00:00 +0000</lastBuildDate><atom:link href="/tags/research/index.xml" rel="self" type="application/rss+xml"/><item><title>Defining Security Invariants</title><link>/research/howto/security-invariants/</link><pubDate>Thu, 09 Jan 2025 17:00:00 +0000</pubDate><guid>/research/howto/security-invariants/</guid><description>&lt;p&gt;&lt;em&gt;&lt;strong&gt;Note:&lt;/strong&gt; This post has been revised to include the new capabilities released by AWS prior to re:Invent 2024.&lt;br&gt;
You can also check out the re:Invent presentation we did with Securosis: &amp;ldquo;Security invariants: From enterprise chaos to cloud order&amp;rdquo; &lt;a href="DEV401_Security-invariants-From-enterprise-chaos-to-cloud-order.pdf"&gt;slides&lt;/a&gt; - &lt;a href="https://www.youtube.com/watch?v=aljwG4N5a-0"&gt;video&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</description></item><item><title>The Universal Cloud Threat Model</title><link>/research/papers/the-universal-cloud-threat-model-for-cloud-native-security/</link><pubDate>Tue, 23 Apr 2024 00:00:00 +0000</pubDate><guid>/research/papers/the-universal-cloud-threat-model-for-cloud-native-security/</guid><description>&lt;p&gt;The Universal Cloud Threat Model is a collaboration between &lt;a href="https://www.primeharbor.com"&gt;PrimeHarbor Technologies&lt;/a&gt; and Securosis. It is a &lt;em&gt;cloud-centric&lt;/em&gt; threat model to help organizations focus security efforts on the most-common attacks most organizations will experience. The UCTM is designed as an adjunct to other threat models. From the introduction:&lt;/p&gt;</description></item><item><title>Modernizing SecOps for Cloud</title><link>/research/papers/modernizing-secops-for-cloud/</link><pubDate>Fri, 23 Feb 2024 00:00:00 +0000</pubDate><guid>/research/papers/modernizing-secops-for-cloud/</guid><description>&lt;p&gt;Security Operations, SecOps for short, has been one of the more difficult security domains to modernize for cloud. It requires a combination of new subject matter expertise, new technologies, process updates, and even a slightly different mindset. Cloud impacts SecOps in ways both obvious and subtle, and because most organizations still have datacenters and offices, teams need to add new skills and update operations while still supporting everything already on their plates. It’s a daunting challenge, but one that can be made much easier to tackle by distilling down, into the core of how cloud changes things, and taking lessons from the successes of early adopters.&lt;/p&gt;</description></item></channel></rss>