The clouds can be a scary place. All these machines that simply aren't yours. So, how can you make sure you continuously keep your cloud infrastructure secure? OWASP Cumulus is the easy way to bring security into the cloud and your DevOps teams. Play it at
copi.owasp.org, thanks to Christoph Niehoff and OWASP Cumulus! Read more at:
https://dev.to/owasp/no-need-to-fear-the-clouds-play-owasp-cumulus-d6g
While we at OWASP Cornucopia have been focusing on creating games focused on web- and mobile application security, we have felt that the specific needs of the DevOps team working in cloud environments have been missing. OWASP Cumulus seeks to fill this gap and provides a custom card deck with threats to cloud systems.
We have recently started adding more EoP-based games to
copi.owasp.org (e.g., we recently added Elevation of MLSec for threat modeling AI and ML.
https://dev.to/owasp/threat-modeling-your-ai-models-using-ai-29e1). These games follow the same game rules as OWASP Cornucopia and help promote application security and threat modeling. We will not hesitate to add more games. Ideas and support from the community are, therefore, always welcome!
On behalf of Colin Watson, Grant Ongers, and me, I wish you all a wonderful day.
Cheers
OWASP Cornucopia co-leader
Johan Sydseter