CloudSec Academy

Benvenuto in CloudSec Academy, la tua guida per navigare nella zuppa alfabetica degli acronimi sulla sicurezza del cloud e del gergo del settore. Elimina il rumore con contenuti chiari, concisi e realizzati da esperti che coprono i fondamenti e le best practice.

Data Categorization: Types, strategies, and steps

Team di esperti Wiz

In this article, we'll explore the different types of data categorization, strategies for effective management, and how to avoid common pitfalls that can complicate cloud data governance.

A Comprehensive Guide to Navigating FISMA Compliance

Team di esperti Wiz

FISMA compliance is the set of processes, controls, and protocols an organization must have in place to ensure its information assets satisfy the requirements of the Federal Information Security Management Act (FISMA).

ISO 27001 Controls: Fast Track Guide

Team di esperti Wiz

This article is your cheat sheet for understanding the ISO 27001 controls, implementing them to tackle security risks, and getting ISO 27001 certified—without any hassles.

NIST 800-171: A Fast Track Guide

Team di esperti Wiz

In this article, we’ll explore the ins and outs of NIST 800-171 compliance, including how it fits within the broader NIST standards and who needs to comply. We’ll also discuss some cloud security best practices to help you keep data safe.

HIPAA Cloud Compliance Essentials for Healthcare Providers

Team di esperti Wiz

Although the HIPAA doesn't make any specific reference to the cloud, it is a completely different IT environment from the on-premises data center—with different compliance challenges. Learn some of the key HIPAA considerations when you host your healthcare workloads in the cloud.

NIST Cloud Security Standards

Team di esperti Wiz

In this post, we'll explore NIST's cloud security standards and how they provide a framework of best practices that enhance the safety and reliability of cloud environments.

What is NIST 800-53? A Fast-Track Guide

Team di esperti Wiz

In this post, we’ll explore why NIST 800-53 is an essential part of modern data protection and important to your cloud environment—along with some best practices so you can roll it out smoothly in your organization.

What is NIST Compliance?

Team di esperti Wiz

NIST compliance is adherence to security standards and guidelines developed by the National Institute of Standards and Technology (NIST).

What is Data Risk Management?

Data risk management involves detecting, assessing, and remediating critical risks associated with data. We're talking about risks like exposure, misconfigurations, leakage, and a general lack of visibility.

8 Essential Cloud Governance Best Practices

Team di esperti Wiz

Cloud governance best practices are guidelines and strategies designed to effectively manage and optimize cloud resources, ensure security, and align cloud operations with business objectives. In this post, we'll the discuss the essential best practices that every organization should consider.

What is a Data Risk Assessment?

Team di esperti Wiz

A data risk assessment is a full evaluation of the risks that an organization’s data poses. The process involves identifying, classifying, and triaging threats, vulnerabilities, and risks associated with all your data.

Governance dell'IA: principi, regolamenti e consigli pratici

Team di esperti Wiz

In questa guida, analizzeremo il motivo per cui la governance dell'IA è diventata così cruciale per le organizzazioni, evidenzieremo i principi chiave e le normative che modellano questo spazio e forniremo passaggi attuabili per costruire il proprio framework di governance.

The EU AI Act

Team di esperti Wiz

In questo post, ti aggiorneremo sul motivo per cui l'UE ha messo in atto questa legge, cosa comporta e cosa devi sapere come sviluppatore o fornitore di intelligenza artificiale, comprese le migliori pratiche per semplificare la conformità.

Data Security Compliance Explained

Data security compliance is a critical aspect of data governance that involves adhering to the security-centric rules and regulations set forth by supervisory and regulatory bodies, including federal agencies.

Cosa sono i benchmark CIS?

Team di esperti Wiz

I benchmark CIS sono roadmap di sicurezza disponibili al pubblico che offrono raccomandazioni fondamentali per guidare le organizzazioni nel rafforzamento dei propri sistemi IT contro le minacce informatiche.

The Shared Responsibility Model

Team di esperti Wiz

Il modello di responsabilità condivisa è un framework che stabilisce le responsabilità di sicurezza del cloud tra i provider di servizi cloud (AWS, GCP, Azure) e i clienti.

Che cosa è il CSPM?

Cloud Security Posture Management (CSPM) descrive il processo di rilevamento e correzione continui dei rischi negli ambienti e nei servizi cloud (ad esempio bucket S3 con accesso di lettura pubblico). Gli strumenti CSPM valutano automaticamente le configurazioni cloud rispetto alle best practice del settore, ai requisiti normativi e alle policy di sicurezza per garantire che gli ambienti cloud siano sicuri e gestiti correttamente.