Microsoft Security MVP Truls Dahlsveen joins the hosts to discuss Modern Security Strategy. Topics include Zero Trust Commandments as a standard, TLS policy updates for Azure application gateway, firmware analysis in Defender for IoT, prioritizing identity-based logs, industry standard frameworks and controls, ASU control and secure scores.
Zero Trust aims to reinvent security without relying on the network perimeter, challenging the traditional belief in the network perimeter as the primary security defense.
The updated default TLS policy for Azure application gateway (2022 0101) enhances security by enabling TLS 1.3, restricting Cipher suites to modern versions, and removing insecure algorithms like Triple DES.
Deep dives
Importance of Zero Trust and Standards
The podcast discusses the release of the Zero Trust Commandments as a standard and emphasizes the importance of Zero Trust as a rethinking of security strategy. The traditional belief in the network perimeter is challenged, and Zero Trust aims to reinvent security without relying on the network perimeter. The Zero Trust Commandments provide a clear definition and boundaries for implementing Zero Trust.
Updates to TLS Policies
The podcast highlights the updated default TLS policy for Azure application gateway. The new policy, 2022 0101, includes important changes such as enabling TLS 1.3, restricting Cipher suites to more modern versions, and removing insecure algorithms like Triple DES. These updates enhance security for Azure application gateway users.
Firmware Analysis in Defender for IoT
The podcast introduces the new and exciting feature of firmware analysis in Defender for IoT. This feature allows the automated analysis of binary firmware images from IoT devices, identifying potential security vulnerabilities and weaknesses. It is praised as a valuable tool for proactive security monitoring and vulnerability management.
Importance of Security Strategy and Use Cases
The guest speaker, Trools, shares insights on the importance of security strategy and use cases. He emphasizes the need to move away from the traditional mindset of collecting all possible logs and enabling default detections. Instead, organizations should prioritize use case development based on their specific environment, threat actors, and business requirements. Trools also highlights the role of security automation in combating alert fatigue and improving efficiency in security operations.
This week Michael and Mark talk to Microsoft Security MVP Truls Dahlsveen about his thoughts on Modern Security Strategy. It's a fascinating and practical discussion!
We also cover security news about Application Gateway TLS policy, Defender for IoT and some new documentation from the OpenGroup about Zero Trust Commandments.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode