bcgov / bcgov/cloud-pathfinder

Onboarding AWS Network Traffic in CloudGuard CSPM

Open
#1,979 0 comments 0 reactions 0 assignees View on GitHub
Security Technology
Dominant language
Jinja
Stars
2
Forks
7
PR merge metrics
No merged PRs in 30d

Description

**Describe the issue**
It would be valuable for conversations with partner teams in BC Gov like SecOps (Michael V) where we could show up with or even share access to a live network diagram. This would also be valuable for security investigations and for triaging and prioritizing future security tickets.

**Additional context**
- We may need to onboard some of the core accounts into CSPM in order for log archive
- VPC flow logs are a special case only going to the central log archive S3 bucket
- We need a PIA and STRA for CSPM if we're going to give them access
- This is a lot of data that will be transmitted outside of AWS. AWS costs a lot on egress, so we need to cost modelling. Expected that this could cost tens of thousands per month.
- CSP Native SIEMs are better for this purpose because they avoid the expensive network traffic shipping logs externall.
- We cannot easily control log volume because that's a ministry team setting.

**Definition of done**
- Book a meeting with Check Point Support and bring along one of the tech team to enable Traffic Explorer in CSPM
- Either do it via the available settings or bring back to the team information on what to change in our config/settings so that this is enabled.
- Perform the change in a repeatable manner so that when we create new environments, they come configured correctly

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.