When Drift Detection Fails

ACM.447 Be aware of when Drift Detection helps you, when it doesn’t — and why policy documents should be first class citizens

Teri Radichel
Cloud Security
Published in
7 min readFeb 1, 2024

--

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

⚙️ Part of my series on Automating Cybersecurity Metrics. The Code.

🔒 Related Stories: AWS Security | Application Security

💻 Free Content on Jobs in Cybersecurity | ✉️ Sign up for the Email List

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

In the last post I wrote about a firewall for CloudShell as I’ve been showing how you might use a container to configure your initial AWS account and the risks that come with that approach. Unfortunately it’s a chicken and egg problem when you start up your first AWS account. You have to start somewhere.

In this post I’m going to tell you about a few issues I found with drift detection in a few places.

Drift detection is super helpful. I wrote about here:

--

--

Teri Radichel
Teri Radichel

Written by Teri Radichel

CEO 2nd Sight Lab | Pentesting | Research | AWS Security Hero | Masters of Infosec & Masters Software Engineering | GSE | IANS | SANS Difference Makers Award