Enhancing Cloud Security with Dominique Dixon at QSC24
Dominique Dixon, associate director of threat and vulnerability management for Humana, explains his role in managing cloud security, addressing vulnerabilities and misconfigurations across public and private cloud services like AWS, GCP, and Azure. The importance of compliance in regulated industries is highlighted, along with the need for collaboration among IT teams.
Transcript
This is Textron tv. Hey everyone. Alan Shiel back here at Qualys QSC in San Diego.
I guess there must be a break going on because there's a lot of people out here behind us in the partner pavilion. Um, thank goodness. I think our mics are pretty good.
So you, they can hear us over. Let me introduce you to our next guest. His name is Dominique Dixon.
Yep. And Dominique is with Humana. That's correct.
That's as far as I can go. Dominique, tell us, well, what do you do at Humana? Yeah, so, um, well ultimately, so in my particular role, um, I do a lot of stuff in the cloud and I handle like a lot of the vulnerabilities and, uh, misconfigurations.
And so I lead a team specifically in the cloud, uh, security space, so CSPM and, uh, container vulnerabilities. And then, um, also policy compliance, so like standardizing baselines and configuration drifts. Um, so that's what I, I basically do at the company.
And so we want to make sure that we, um, identify what's a risky asset. You know, there's a lot of stuff out there and we have a lot of the application teams and dev teams, and we throw so many things at them, but we want to spend the time on what is important, you know, what's at the highest risk, and how can we put everything together like that. So you are dealing, when you say cloud, is it public cloud, private cloud?
Both. Yeah. So we actually work in all three major, uh, public cloud providers, so like AWS and uh, GCP, um, and then also Azure.
Sure. And so we're using that, um, just from like a cloud infrastructure, a cloud platform, but then also, uh, Kubernetes stuff, which is across all three platforms too. So.
Well, when you mentioned containers, I assumed there was Kubernetes in there. Yes. Are you, and again, I don't want discuss anything that's going to get you guys in trouble or give some attackers information.
When you talk about this, I'm assuming you're using like serverless kind of platforms. I mean, all of the kind of latest and greatest Mm-Hmm, yes. You know, that cloud native has to offer.
Um, and that's a job securing all of it, right? Yes. With a lot of different tools.
Well, I, I'm assuming you guys use Qualys for some part of your security. Yes, that's correct. And you're actually speaking here?
Yes. Yeah. So whenever I'm speaking here, so I'm speaking here, uh, tomorrow, it is gonna be tomorrow afternoon.
So I'm strictly going to be focusing on using quas for policy compliance. So we use that. We have a standardized process, um, where we're working with all these different teams because it's a big thing.
It's, uh, you can't put all of this on all the different application teams all at the same time. Um, there's a lot of work involved. You have to create a baseline that's not only specific to your, uh, uh, company, but to ensure that you stay compliant with all the, all the different type of regulations.
Sure. Um, so for us, you know, it's been helpful to be able to utilize Paul, so I'm gonna be speaking about this tomorrow, just the fact that what they have out of box, I mean from, you know, STIG, uh, CIS benchmarks across all the different types of technologies. And then they basically give us the tools to be able to customize for our needs.
There's gonna be certain things that's outside of CIS benchmarks that we have to focus on. Um, and so we have to build our own custom controls, which is great, you know, so we have all that information in there and it's been helping us out a lot. And then also these other teams too.
Got it. You know, look, you're in what we call a heavy, heavily regulated industry, right? Yes.
Healthcare, finance, these kinds of things. So compliance is, is probably more important for you than someone in a different vertical. Um, you know, I, I've been in security a long time myself, Dominique, one of the so constant rubs is should I do compliance or for compliance sake, well, should I really put all my eggs in doing security?
Well, and a byproduct of doing security well is being, is I'm now compliant. 'cause we would like to think anyway that most of our compliance regulations are based on common sense security, uh, you know, procedures, best process, best practices. So do you battle that or you just say, Hey, look, we gotta worry about the compliance and let's get this compliance done.
Well, I think it's kind of a mixture of two things. Yes. I know from a compliance standpoint, a lot of people just see it as like a check box.
I'm doing it, you know, I'm good to go. Right? All the auditors that come through, okay, you have your documentation, that's fine, but are you doing, are you protecting your company?
Are you doing things how you're supposed to be doing it? Is everything going well? Um, are you actually That's exactly it.
The Risk Yep. Is being found. And so like, I think that, you know, as you're doing that and as you're building out all your different, all all your different processes and all the documentation, it brings it, it brings it, uh, together.
So you're a checking the box. Yes, I am compliant, but you're, you're also starting to mitigate all the, all the other risks that you have at your company. You're moving In as security.
'cause to me it's sort of, I'm moving beyond what I call least common denominator security, which is compliance into actually doing security. Yes. Right.
And, and I think that's an important piece of the security professionals and security teams working. You mentioned a few times about how your team works with developers and ops and you know, different other folks within the IT world. Yes.
com too. That's one of the sites. And so DevSecOps is obviously a very big thing to us.
One of the, like my, on my own personal journey is we can't expect developers to be security pros. Yep. We can ask their help, right.
And tell 'em to be security mindful, but they're not security people. They're not. Yes.
And so how do you now, and you mentioned you got a lot of stuff going on in your manner all over the place, uhhuh, how do you navigate the boundaries? The, you know, where these things intersect, developer operations, SREs, platform engineering, you know, all of the accoutrements of the modern IT infrastructure. Well, I mean, one of the big things is just starting off.
We need to communicate well, you know? Yeah. Having, um, you know, really good, uh, communication across all the different teams.
And essentially we have to all work together. You know, a lot of these teams, they're doing their job. They're trying to build applications and push this out.
You have a platform team, they're doing their job as well. But whenever, what we are, what we are doing as well is, is, is a, is a changing the view we're, and, and then we're tying everyone all together. We're bringing these teams, Hey, yes, I worked with you on the application side, but I work with the platform team.
Let's come together and let's figure this out. You know, so like if you go into the actual, the actual technicalities or everything, um, you know, let's shift left, let's, you know, build this inside their pipelines. And they don't have to do anything.
It just, they are a, they're starting to build their application. A a scan can occur. Here's your findings.
Instead of being reactive. And like a lot of the vulnerability space in the past has been all, there's all these things out there that's hurry up and fix, fix, fix. Let's be proactive and identify these things early on in inside their pipelines.
And so then we start to mitigate that at the first stage where at the beginning, all the way, all the way, all the way into the end as well. So we're seeing this in the DevOps DevSecOps space where sort of AI copilots, if you will. Mm-Hmm.
I mean, they're making their way into the IDE. So as these people are actually coding, if there's a known vulnerability they brought down that, you know, they're using an old version of a open source component or something like that, you know, it's getting a spotlight and hopefully remediated right there before, you know, it makes its way down the pipeline. Human matter, doing stuff like that or looking at it.
Yeah, there's some things that we're actually looking at. Um, I really can't say a whole lot about it, but, you know, um, nowadays, especially with all these different types of, uh, security tools, so we have our AI stuff that we're actually building out, but then that's also on top of like, Qualys is starting to use ai, these other security products, they're, they're, they're All guys though. So yes, at the same time, we wanna make sure that, you know, like everything is being developed in a, a secure fashion and then we, we are able to, to, uh, protect those assets at the beginning.
But yeah, there's, there's a lot of things that's all going on in that space. Um, um, but yeah, like, just like what you said, you know, catching it at the, at the very beginning on the left side, I mean, that will help, Makes it a lot easier if you can. Yes, Yes you Can.
And that's the key to it. Anyway. Hey man, I want to thank you.
I appreciate it. Good luck tomorrow. Yeah.
With your presentation. I'm sure it'll be great and good luck in, you know, doing what you do at Humana. Right?
It's not a, it's not a friendly world out there sometimes, right? It's pretty loud. Alright.
Donique Dixon from Humana here live at, uh, Qualys QSC. He's presenting tomorrow. Um, check it out.
We're live all day here. We've got some more content gonna play until our next guest. This is Alan Hummel for Textron.
We're out.