Cloud 101CircleEventsBlog

Download Publication

Challenges in Securing Application Containers and Microservices
Challenges in Securing Application Containers and Microservices

Challenges in Securing Application Containers and Microservices

Release Date: 07/16/2019

Application containers and a microservices architecture are being used to design, develop and deploy applications leveraging agile software development approaches such as Development Operations. Security must be embedded into these software development approaches. This document serves to identify challenges in securing application containers and microservices in the engineering of trustworthy secure systems through the lens of the Developer, Operator and Architect.


This publication is part of a larger series, you can find all the papers in the series here
Download this Resource

Prefer to access this resource without an account? Download it now.

Microservices Architecture Pattern
Microservices Architecture Pattern
Best Practices for Implementing a Secure Application Container Architecture - Japanese Translation
Best Practices for Implementing a Secure Applic...
Best Practices in Implementing a Secure Microservices Architecture
Best Practices in Implementing a Secure Microse...
Four Ways You Can Lose Your Data
Four Ways You Can Lose Your Data
Published: 04/11/2023
Exploiting CVE-2021-3490 for Container Escapes
Exploiting CVE-2021-3490 for Container Escapes
Published: 04/05/2023
An Introduction to Data Detection and Response (DDR)
An Introduction to Data Detection and Response (DDR)
Published: 03/20/2023
Securing Cloud Workloads in 5 Easy Steps
Securing Cloud Workloads in 5 Easy Steps
Published: 01/30/2023

Acknowledgements

Michael Roza
Michael Roza
Risk, Audit, Control, and Compliance Professional

Michael Roza

Risk, Audit, Control, and Compliance Professional

Since 2012 Michael has contributed to over 85 CSA projects completed by CSA's Internet of Things, Zero Trust/Software-Defined Perimeter, Top Threats, Cloud Control Matrix, Containers/Microservices, DevSecOps, and other working groups. He has also served as co-chair of CSA's Enterprise Architecture, Top Threats, and Security-as-a-Service working groups while also serving as the Standards Liaison Officer for IoT, ICS, EA, SECaaS, and Cloud Ke...

Read more

John Kinsella Headshot Missing
John Kinsella

John Kinsella

This person does not have a biography listed with CSA.

Atul Chaturvedi Headshot Missing
Atul Chaturvedi

Atul Chaturvedi

This person does not have a biography listed with CSA.

Joshua Cuellar Headshot Missing
Joshua Cuellar

Joshua Cuellar

This person does not have a biography listed with CSA.

Shyamkant Dhamke Headshot Missing
Shyamkant Dhamke

Shyamkant Dhamke

This person does not have a biography listed with CSA.

David Wayland Headshot Missing
David Wayland

David Wayland

This person does not have a biography listed with CSA.

John Osborne Headshot Missing
John Osborne

John Osborne

This person does not have a biography listed with CSA.

James Yaple Headshot Missing
James Yaple

James Yaple

This person does not have a biography listed with CSA.

Hillary Baron
Hillary Baron
Senior Technical Director - Research, CSA

Hillary Baron

Senior Technical Director - Research, CSA

This person does not have a biography listed with CSA.

Marina Bregkou
Marina Bregkou
Senior Research Analyst, CSA EMEA

Marina Bregkou

Senior Research Analyst, CSA EMEA

This person does not have a biography listed with CSA.

Anil Karmel
Anil Karmel
Co-founder and CEO, RegScale

Anil Karmel

Co-founder and CEO, RegScale

Anil Karmel is the Co-Founder and CEO of RegScale, which helps organizations start and stay compliant via the world's first real-time GRC platform. Formerly, Anil served as the National Nuclear Security Administration's (NNSA) Deputy Chief Technology Officer. Karmel began his government career as a Technical Staff Member of Los Alamos National Laboratory (LANL) and was responsible for inventing their cloud and collaboration technologies Kar...

Read more

Madhav Chablani Headshot Missing
Madhav Chablani
Consulting CIO, TippingEdge Consulting

Madhav Chablani

Consulting CIO, TippingEdge Consulting

This person does not have a biography listed with CSA.

Alex Rebo Headshot Missing
Alex Rebo

Alex Rebo

This person does not have a biography listed with CSA.

Randall Brooks Headshot Missing
Randall Brooks

Randall Brooks

This person does not have a biography listed with CSA.

Amir Jerbi Headshot Missing
Amir Jerbi

Amir Jerbi

This person does not have a biography listed with CSA.

Cem Gurkok Headshot Missing
Cem Gurkok

Cem Gurkok

This person does not have a biography listed with CSA.

James McCloskey Headshot Missing
James McCloskey

James McCloskey

This person does not have a biography listed with CSA.

Ki-Hong Min Headshot Missing
Ki-Hong Min

Ki-Hong Min

This person does not have a biography listed with CSA.

Ken Stavinoha Headshot Missing
Ken Stavinoha

Ken Stavinoha

This person does not have a biography listed with CSA.

Shanthi Thomas Headshot Missing
Shanthi Thomas

Shanthi Thomas

This person does not have a biography listed with CSA.

Juanita Koilpillai
Juanita Koilpillai
Founder & CEO, Waverly Labs

Juanita Koilpillai

Founder & CEO, Waverly Labs

Juanita Koilpillai is Founder and CEO of Waverley Labs, a pioneer in software defined perimeters (SDP) and digital risk reduction solutions. She has 30 years’ experience researching and developing systems in computer security, network management and real-time distributed software. She leads the open source software-defined perimeter (SDP) effort for ‘black’ apps in the cloud with the Cloud Security Alliance and is an active contributor to N...

Read more

Mark Yanalitis Headshot Missing
Mark Yanalitis

Mark Yanalitis

This person does not have a biography listed with CSA.

Michele Drgon Headshot Missing
Michele Drgon

Michele Drgon

This person does not have a biography listed with CSA.

John Wrobel Headshot Missing
John Wrobel

John Wrobel

This person does not have a biography listed with CSA.

Ramaswamy Chandramouli Headshot Missing
Ramaswamy Chandramouli

Ramaswamy Chandramouli

This person does not have a biography listed with CSA.

Yin Lee Headshot Missing
Yin Lee

Yin Lee

This person does not have a biography listed with CSA.

Mark Potter Headshot Missing
Mark Potter

Mark Potter

This person does not have a biography listed with CSA.

Ed Santiago Headshot Missing
Ed Santiago

Ed Santiago

This person does not have a biography listed with CSA.

Shawn Wells Headshot Missing
Shawn Wells

Shawn Wells

This person does not have a biography listed with CSA.

Vishwas Manral
Vishwas Manral
Chief Technologist at McAfee Enterprise, Head of Cloud Native Security

Vishwas Manral

Chief Technologist at McAfee Enterprise, Head of Cloud Native Security

Vishwas is the co-chair of CSA’s Serverless working group and a contributor to theApplication Containers and Microservices working group. He has served as a presenter at the CSA Virtual EU Summit 2020, and as chair of the Silicon Valley chapter. He is the head of Cl...

Read more

Jeff Barnes Headshot Missing
Jeff Barnes

Jeff Barnes

This person does not have a biography listed with CSA.

Aaron Lippold Headshot Missing
Aaron Lippold

Aaron Lippold

This person does not have a biography listed with CSA.

Kina Shah Headshot Missing
Kina Shah

Kina Shah

This person does not have a biography listed with CSA.

Shankar Chebrolu Headshot Missing
Shankar Chebrolu

Shankar Chebrolu

This person does not have a biography listed with CSA.

Ashish Kurmi Headshot Missing
Ashish Kurmi

Ashish Kurmi

This person does not have a biography listed with CSA.

Michaela Iorga
Michaela Iorga
Senior Security Technical Lead for Cloud Computing at National Institute of Standards and Technology (NIST/ITL)

Michaela Iorga

Senior Security Technical Lead for Cloud Computing at National Institute of Standards and Technology (NIST/ITL)

This person does not have a biography listed with CSA.

Lloyd Osafo Headshot Missing
Lloyd Osafo

Lloyd Osafo

This person does not have a biography listed with CSA.

Andrew Wild
Andrew Wild

Andrew Wild

This person does not have a biography listed with CSA.

Michael Green Headshot Missing
Michael Green

Michael Green

This person does not have a biography listed with CSA.

Frank Geck Headshot Missing
Frank Geck

Frank Geck

This person does not have a biography listed with CSA.

Joshua Daniel Headshot Missing
Joshua Daniel

Joshua Daniel

This person does not have a biography listed with CSA.

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?