Visibility, Control, and Change Tracking for Public Cloud Policies
Download resourcesAbout this session
Ricky Egge of Tufin demos the company's platform for visibility, control and change tracking over public-cloud network security policies across AWS, Azure and GCP. He frames the need around centralised visibility of many accounts, detecting policy violations, monitoring changes, understanding data-centre-to-cloud connectivity, supporting zero trust by shrinking the blast radius, and letting network, security and DevOps teams collaborate. The platform ingests VPCs, VNets, NSGs, ASGs and cloud firewalls plus tagging metadata. The demo shows a dashboard (risky ports like Telnet and RDP, permissive access, CIS benchmarking, tag usage), and explains that because cloud IPs are ephemeral, tags (environment, application, owner) are how assets should be classified. He builds an organisational policy from tags (Internet only to web tier over HTTPS, block Internet to dev and database tiers), renders a customizable Azure topology graph drilling from account to environment to VNet to tier to servers, and shows effective access and gray-versus-red lines for in- and out-of-policy flows, including a prod web server improperly reaching dev. He demonstrates dynamic tagging, inheritance and policy exceptions. An extended Q&A covers API polling, authentication, throttling, lack of push and serverless coverage, Terraform and CloudFormation compliance checks, Panorama, CIS versus bespoke policies, and multi-cloud complexity.
See topology mapping, network analysis, and troubleshooting N/S and E/W traffic for Azure firewall and AWS security controls support.
Key takeaways
- Classify cloud assets by tags (environment, application, owner), not IP addresses, because cloud IPs are ephemeral while tags travel with the asset.
- Write an organisational network policy in terms of tags: Internet only to the web tier over HTTPS, and block Internet access to dev and to database tiers.
- Use a topology graph and effective-access view to catch out-of-policy flows, such as a production web server able to reach the dev environment.
- When infrastructure was deployed without tags, apply tags dynamically or inherit them from subnets, VNets and security groups without changing the source infrastructure.
- Check proposed changes against policy before deployment through Terraform or CloudFormation integration rather than pushing changes that source automation would later overwrite.
Speakers
Ricky Egge is a seasoned Sales Engineer at Tufin, where he supports and guides clients from a risk, technology, people, process and financial perspective. Aligning products, processes and people, Egge provides clients with the results that align… Read moreRead less
Ricky Egge is a seasoned Sales Engineer at Tufin, where he supports and guides clients from a risk, technology, people, process and financial perspective. Aligning products, processes and people, Egge provides clients with the results that align with their business needs to ensure compliance and minimize risk.