What is Cloud Custodian?

Definition, Key Features, Installation, Version, and Schema

A Cloud Custodian is an open-source from CapitalOne written in python language and comprises many tools and scripts. It is a rule engine where you can write policy definitions in YAML. This enables an organization to manage their public cloud resources by writing policies for cost savings, explore tagging, compliance, security, operations related concerns, and resource inventory.

Open Source, Python, Serverless, Agentless, Policy-as-a-Code, Real-Time Guard Rail, Visibility, Powerful Cloud Security Management Tool

Addresses various domains

Key Features:

  1. Supports AWS, Azure, and GCP Cloud Providers.
  2. Does not require an agent or client to be installed.
  3. Write your own rules in the form of YAML policy.
  4. Enables you to check on your compliance requirements.
  5. Real-Time Guard rails, that take action on the resources to do auto-remediation.
  6. Best in class to filter on certain values and define actions to be taken at certain time intervals. For example- mark now, notify the user, and delete after 1 hour, and then notify again. Hence, allows using a wide variety of combinations to…

--

--

Aakif Shaikh, CISSP, CEH, CHFI, CISA, GWAPT
Aakif Shaikh, CISSP, CEH, CHFI, CISA, GWAPT

Written by Aakif Shaikh, CISSP, CEH, CHFI, CISA, GWAPT

Over 18 years of experience in a wide variety of technical domains within information security including information assurance, compliance, and risk management.

No responses yet