<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Azure marketplace images security assurance in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184541#M5985</link>
    <description>&lt;P&gt;Will that provide an answer to my questions specifically?&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jun 2023 12:09:37 GMT</pubDate>
    <dc:creator>Don_Paterson</dc:creator>
    <dc:date>2023-06-22T12:09:37Z</dc:date>
    <item>
      <title>Azure marketplace images security assurance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184502#M5983</link>
      <description>&lt;P&gt;&lt;STRONG&gt;How can customers check the image before and after deployment and what has been put in place to guarentee that a market place image has not been injected with malicious code?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;A downloadable iso file normally has a hash. What about the marketplace templates/images?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 07:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184502#M5983</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2023-06-22T07:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Azure marketplace images security assurance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184517#M5984</link>
      <description>&lt;P&gt;Microsoft has a lot of web pages with Azure Security information covering every aspect, so i would start here: &lt;A href="https://azure.microsoft.com/en-us/explore/security/" target="_blank"&gt;https://azure.microsoft.com/en-us/explore/security/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 10:27:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184517#M5984</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-06-22T10:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Azure marketplace images security assurance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184541#M5985</link>
      <description>&lt;P&gt;Will that provide an answer to my questions specifically?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 12:09:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184541#M5985</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2023-06-22T12:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Azure marketplace images security assurance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184554#M5986</link>
      <description>&lt;P&gt;Why should that not do this ? Microsoft is responsible for the safety of Azure marketplace images, or have you proof that this is regulated differently ?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 14:22:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184554#M5986</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-06-22T14:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Azure marketplace images security assurance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184583#M5987</link>
      <description>&lt;P&gt;At least in Amazon, AMIs are created from a known good disk image prepared by the vendor.&amp;nbsp;&lt;BR /&gt;Once they're published, they cannot be updated without publishing a new AMI.&lt;BR /&gt;Unless the image included the malicious content "from the factory" the only way it could be infected would be post-deployment.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 18:08:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184583#M5987</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-22T18:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: Azure marketplace images security assurance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184621#M5988</link>
      <description>&lt;P&gt;That Azure security page is more about marketing and might make one wonder why any other security solution might be required if Azure has so much resource behind cyber security...&lt;/P&gt;&lt;P&gt;My question is about security checks before and immediately after a deployment of a Check Point VM from the marketplace. It is a valid question that a customer can (and did) ask.&lt;/P&gt;&lt;P&gt;It is a technical question and specifically about the technical options that a Check Point customer may or may not have to validate an image/marketplace template deployment, in the same way as we check downloaded files integrity with a SHA1 or SHA256 checksum.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 11:03:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184621#M5988</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2023-06-23T11:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Azure marketplace images security assurance</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184647#M5989</link>
      <description>&lt;P&gt;I understand the "trust but verify" mindset behind this question &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Unfortunately, this is a question that can only truly be answered by the cloud vendor (Microsoft in this case).&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 15:31:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/Azure-marketplace-images-security-assurance/m-p/184647#M5989</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-23T15:31:34Z</dc:date>
    </item>
  </channel>
</rss>

