bcgov / bcgov/cloud-pathfinder
Onboarding AWS Network Traffic in CloudGuard CSPM
- Dominant language
- Jinja
- Stars
- 2
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
**Describe the issue**
It would be valuable for conversations with partner teams in BC Gov like SecOps (Michael V) where we could show up with or even share access to a live network diagram. This would also be valuable for security investigations and for triaging and prioritizing future security tickets.
**Additional context**
- We may need to onboard some of the core accounts into CSPM in order for log archive
- VPC flow logs are a special case only going to the central log archive S3 bucket
- We need a PIA and STRA for CSPM if we're going to give them access
- This is a lot of data that will be transmitted outside of AWS. AWS costs a lot on egress, so we need to cost modelling. Expected that this could cost tens of thousands per month.
- CSP Native SIEMs are better for this purpose because they avoid the expensive network traffic shipping logs externall.
- We cannot easily control log volume because that's a ministry team setting.
**Definition of done**
- Book a meeting with Check Point Support and bring along one of the tech team to enable Traffic Explorer in CSPM
- Either do it via the available settings or bring back to the team information on what to change in our config/settings so that this is enabled.
- Perform the change in a repeatable manner so that when we create new environments, they come configured correctly
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.