- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- CloudMates General
- :
- Azure marketplace images security assurance
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Azure marketplace images security assurance
How can customers check the image before and after deployment and what has been put in place to guarentee that a market place image has not been injected with malicious code?
A downloadable iso file normally has a hash. What about the marketplace templates/images?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Microsoft has a lot of web pages with Azure Security information covering every aspect, so i would start here: https://azure.microsoft.com/en-us/explore/security/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Will that provide an answer to my questions specifically?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why should that not do this ? Microsoft is responsible for the safety of Azure marketplace images, or have you proof that this is regulated differently ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That Azure security page is more about marketing and might make one wonder why any other security solution might be required if Azure has so much resource behind cyber security...
My question is about security checks before and immediately after a deployment of a Check Point VM from the marketplace. It is a valid question that a customer can (and did) ask.
It is a technical question and specifically about the technical options that a Check Point customer may or may not have to validate an image/marketplace template deployment, in the same way as we check downloaded files integrity with a SHA1 or SHA256 checksum.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I understand the "trust but verify" mindset behind this question 🙂
Unfortunately, this is a question that can only truly be answered by the cloud vendor (Microsoft in this case).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
At least in Amazon, AMIs are created from a known good disk image prepared by the vendor.
Once they're published, they cannot be updated without publishing a new AMI.
Unless the image included the malicious content "from the factory" the only way it could be infected would be post-deployment.