Loading…
In-person + Virtual
18-21 April
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon Europe 2023 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Central European Summer Time (UTC +2). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change and session seating is available on a first-come, first-served basis. 
Wednesday, April 19 • 11:00 - 11:35
Zero Privilege Architectures - Thijs Ebbers & Diana Iordan, ING

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.


In this talk we'll start out with a bit of Dutch folkore (Hey, we're in Amsterdam :-)), we'll explain what is wrong with typical "Least Privilege" & "Zero Trust" implementations and ask the confronting question: "Are we playing for a Draw or are we playing to Win against our IT security adversaries...? Next we'll use some "classical" laws of war/diplomacy, biology/business and engineering to develop a modern IT architecture suitable for todays challenges. This architecture is based on desired state infrastructure, built using CI/CD and Infra/Policy-as-code. It stores its data in Data Services. It uses Events, Observability and IAM to operate securely. (In summary: we cover quite a lot of the CNCF landscape...) We'll explain this architecture and show different views of this architecture for: - Architects/Developers/Engineers - C-level Managers - CISO/Auditors And answer some questions like: - Can it be build ? (spoiler : Yes, ING is running it today, details in previous talks we gave at OpenShift Commons Detroit & San Diego) - My workloads won't fit - We're not a bank, we cannot afford this - Doesn't this collide with current views/implementations of established entities in the security(/compliancy) industry ? To conclude answer any other question the audience asks

Speakers
avatar for Thijs Ebbers

Thijs Ebbers

Cloud Native Architect, ING
Architecting Cloud Native @ING since 2016 (employee since 2001) Architecture Lead for the Runtime Domain (“VM & Container Hosting”), for ING Private & Public Clouds Speaker at OpenShift Commons San Diego & Detroit Interviewed by TheCUBE during KubeCon Detroit Living together with... Read More →
avatar for Diana Iordan

Diana Iordan

Engineer, ING
 I am an engineer in ING's CI/CD squad, building container deployment capabilities for DevOps application deployment pipelines. Working and living in Bucharest.



Wednesday April 19, 2023 11:00 - 11:35 CEST
Auditorium + Balcony | Ground + First Floor | Congress Centre
  Security + Identity