SlideShare una empresa de Scribd logo
1 de 18
AWS Cloud
Governance Overview
                Nathan Beach
                Principle Solution Architect
                AWS Worldwide Public Sector




October 2012
centralized                                                     decentralized


                                 hybrid

              AWS Cloud Governance

                                  data
      infrastructure                                       application

                       A Shared Responsibility Model

                   scalable                  highly available
                                accessible
Governance…

“Governance implies control and oversight over
policies, procedures, and standards for application
development, as well as the
design, implementation, testing, and monitoring of
deployed services.”




Wayne Jansen, Timothy Grace, NIST SP 800-144: Guidelines on Security and Privacy in
Public Cloud Computing, January 2011.
URL: http://csrc.nist.gov/publications/nistpubs/800-144/SP800-144.pdf
…is a Shared Responsibility

 “Cloud Providers and Cloud Consumers collaboratively
 design, build, deploy, and operate cloud-based systems.
 The split of control means both parties now share the
 responsibilities in providing adequate protections to the
 cloud-based systems. Security is a shared
 responsibility.”




Fang Liu, Jin Tong, Jian Mao, Robert Bohn, John Messina, Lee Badger and Dawn
Leaf, NIST SP 500-292: NIST Cloud Computing Reference Architecture, September
2011.
AWS Investments Establish a Trusted
Foundation
Certifications        Physical Security         HW, SW, Network
 SOC 1 Type 2          Datacenters in           Systematic change
 (formerly SAS-70)     nondescript facilities   management
 ISO 27001             Physical access          Phased updates
                       strictly controlled      deployment
 PCI DSS for
 EC2, S3, EBS, VPC,    Must pass two-factor     Safe storage
 RDS, ELB, IAM         authentication at        decommission
                       least twice for floor
                                                Automated
                       access
                                                monitoring and self-
                       Physical access          audit
                       logged and audited
                                                Advanced network
                                                protection
Authorizations and ATOs

 FISMA Moderate

 ITAR Compliant Region (GovCloud)

 DIACAP MAC III/Sensative
Statement on Auditing Standards No. 70
(SAS 70) Type II report.
 Conducted in accordance with the Statement on
 Standards for Attestation Engagements No. 16 (SSAE
 16) and the International Standards for Assurance
 Engagements No. 3402 (ISAE 3402) professional
 standards.
 Attests that AWS’ control objectives are appropriately
 designed and that the individual controls defined to
 safeguard customer data are operating effectively.
 Our commitment to the SOC 1 report is on-going with
 planned periodic audits.
 SOC 1 Type 2 Replaces Statement on Auditing
 Standards No. 70 (SAS 70) Type II report.
ISO 27001 Certification
 AWS achieved ISO 27001 certification of our Information
 Security Management System (ISMS) covering our
 infrastructure, data centers, and services including Amazon
 Elastic Compute Cloud (Amazon EC2), Amazon Simple
 Storage Service (Amazon S3) and Amazon Virtual Private
 Cloud (Amazon VPC).
 Certifies our systematic and ongoing approach to managing
 information security risks that affect the
 confidentiality, integrity, and availability of company and
 customer information.
 AWS’s ISO 27001 certification includes all AWS data centers
 in all regions worldwide and AWS has established a formal
 program to maintain the certification.
 A copy of our ISO certificate, available to AWS
 customers, describes the ISMS services and geographic
 scope.
Payment Card Industry (PCI) Data Security
Standard (DSS) Certification
 PCI-DSS is a standard that specifies best practices
 and various security controls. Certification in the
 standard requires organizations to:
   Build and maintain a secure network
   Protect cardholder data
   Maintain a vulnerability management program
   Implement strong security measures
   Regularly test and monitor networks
   Maintain an information security policy
Shared Responsibility to Implement Controls
AWS Cloud Governance Service Enablers

Governance Area              AWS Technologies
Roles and Responsibilities   • Identity and Access Management: Policies,
                               Roles
Configuration Management     • Cloud Formation Templates
                             • Elastic Beanstalk
                             • Private AMIs
Financial Controls           • Consolidated Billing
                             • Linked Accounts
                             • CloudWatch Billing Alarms
Network Security             •   Virtual Private Cloud
                             •   Network ACLs
                             •   Security Groups
                             •   Virtual Private Gateways
                             •   VPN Connections
                             •   Route Tables and Subnets
AWS Cloud Governance Service Enablers (cont.)

Governance Area         AWS Technologies
Information Assurance   • Corporate “Gold” Operating System Images
Processing              • VPC Workload Isolation
                        • Dedicated EC2 Instances
Information Assurance   • S3 AES 256 bit Encryption
Storage                 • Partner Extensions offer Boot Volume and EBS
                          Volume Encryption
Information Assurance   • HW/SW VPN Connections
Transmission            • DirectConnect

Network Security        •   Virtual Private Cloud
                        •   Network ACLs
                        •   Security Groups
                        •   Virtual Private Gateways
                        •   VPN Connections
AWS Cloud Governance Service Enablers (cont.)

Governance Area      AWS Technologies
Access Controls      •   Identity and Access Management Policies
                     •   Bucket Policies
                     •   EC2 Instance Roles
                     •   Query String Authentication
                     •   Access Control Lists



Identification and   •   Identity and Access Management
Authentication       •   Multi-Factor Authentication
                     •   Group Policies and Roles
                     •   Federated Identity Management API
AWS Cloud Governance Service Enablers (cont.)

Governance Area            AWS Technologies
Disaster Recovery and      Data
Continuity of Operations   • EBS Snapshots
                           • S3 Near-Line Storage
                           • Glacier Near-Offline Storage
                           • Storage Gateway
                           • Bulk Data Import/Export
                           • Managed AWS No-SQL/SQL Database
                             Services
                           • Extensive 3rd Party Solutions

                           Workload
                           • Elastic load Balancers
                           • EC2 Auto Scaling
                           • Route 53 – Latency Based Routing
                           • Cloud Front – Content Delivery Network
                           • Multi-AZ, Multi-Region Workload Deployment
AWS Cloud Governance Service Enablers (cont.)

Governance Area            AWS Technologies
Monitoring and Reporting   • Cloud Watch
                           • Cloud Watch Alarms
                           • Simple Notification Service
References and Further Reading
 Wayne Jansen, Timothy Grace, NIST SP 800-144: Guidelines on Security and Privacy
 in Public Cloud Computing, January 2011. URL:
 http://csrc.nist.gov/publications/nistpubs/800-144/SP800-144.pdf

 Fang Liu, Jin Tong, Jian Mao, Robert Bohn, John Messina, Lee Badger and Dawn
 Leaf, NIST SP 500-292: NIST Cloud Computing Reference Architecture, September
 2011.URL: http://www.nist.gov/customcf/get_pdf.cfm?pub_id=909505

 NIST SP 800-53 R3: Recommended Security Controls for Federal Information
 Systems and Organizations, August 2009. URL:
 http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-
 final_updated-errata_05-01-2010.pdf

 Amazon Web Services: Security and Accreditation Center: Certifications
 URL: http://aws.amazon.com/security/#certifications
AWS Cloud Governance
      Overview

     Nathan Beach
     Principle Solution Architect
     AWS Worldwide Public Sector

     E-Mail: nsbeach@amazon.com

Más contenido relacionado

La actualidad más candente

AWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best Practices
Amazon Web Services
 
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Amazon Web Services
 
Data Center Migration to the AWS Cloud
Data Center Migration to the AWS CloudData Center Migration to the AWS Cloud
Data Center Migration to the AWS Cloud
Tom Laszewski
 

La actualidad más candente (20)

AWS 101
AWS 101AWS 101
AWS 101
 
Cloud Migration Workshop
Cloud Migration WorkshopCloud Migration Workshop
Cloud Migration Workshop
 
AWS Technical Essentials Day
AWS Technical Essentials DayAWS Technical Essentials Day
AWS Technical Essentials Day
 
AWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best PracticesAWS Multi-Account Architecture and Best Practices
AWS Multi-Account Architecture and Best Practices
 
AWS Control Tower를 통한 클라우드 보안 및 거버넌스 설계 - 김학민 :: AWS 클라우드 마이그레이션 온라인
AWS Control Tower를 통한 클라우드 보안 및 거버넌스 설계 - 김학민 :: AWS 클라우드 마이그레이션 온라인AWS Control Tower를 통한 클라우드 보안 및 거버넌스 설계 - 김학민 :: AWS 클라우드 마이그레이션 온라인
AWS Control Tower를 통한 클라우드 보안 및 거버넌스 설계 - 김학민 :: AWS 클라우드 마이그레이션 온라인
 
Executing a Large-Scale Migration to AWS
Executing a Large-Scale Migration to AWSExecuting a Large-Scale Migration to AWS
Executing a Large-Scale Migration to AWS
 
AWS Security Hub
AWS Security HubAWS Security Hub
AWS Security Hub
 
Fundamentals of AWS Security
Fundamentals of AWS SecurityFundamentals of AWS Security
Fundamentals of AWS Security
 
Running Active Directory in the AWS Cloud
Running Active Directory in the AWS Cloud Running Active Directory in the AWS Cloud
Running Active Directory in the AWS Cloud
 
Deploy and Govern at Scale with AWS Control Tower
Deploy and Govern at Scale with AWS Control TowerDeploy and Govern at Scale with AWS Control Tower
Deploy and Govern at Scale with AWS Control Tower
 
How HSBC Uses Serverless to Process Millions of Transactions in Real Time (FS...
How HSBC Uses Serverless to Process Millions of Transactions in Real Time (FS...How HSBC Uses Serverless to Process Millions of Transactions in Real Time (FS...
How HSBC Uses Serverless to Process Millions of Transactions in Real Time (FS...
 
Building-a-Data-Lake-on-AWS
Building-a-Data-Lake-on-AWSBuilding-a-Data-Lake-on-AWS
Building-a-Data-Lake-on-AWS
 
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...Using AWS Control Tower to govern multi-account AWS environments at scale - G...
Using AWS Control Tower to govern multi-account AWS environments at scale - G...
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
 
롯데이커머스의 마이크로 서비스 아키텍처 진화와 비용 관점의 운영 노하우-나현길, 롯데이커머스 클라우드플랫폼 팀장::AWS 마이그레이션 A ...
롯데이커머스의 마이크로 서비스 아키텍처 진화와 비용 관점의 운영 노하우-나현길, 롯데이커머스 클라우드플랫폼 팀장::AWS 마이그레이션 A ...롯데이커머스의 마이크로 서비스 아키텍처 진화와 비용 관점의 운영 노하우-나현길, 롯데이커머스 클라우드플랫폼 팀장::AWS 마이그레이션 A ...
롯데이커머스의 마이크로 서비스 아키텍처 진화와 비용 관점의 운영 노하우-나현길, 롯데이커머스 클라우드플랫폼 팀장::AWS 마이그레이션 A ...
 
AWS Migration Planning Roadmap
AWS Migration Planning RoadmapAWS Migration Planning Roadmap
AWS Migration Planning Roadmap
 
[AWS Builders] AWS상의 보안 위협 탐지 및 대응
[AWS Builders] AWS상의 보안 위협 탐지 및 대응[AWS Builders] AWS상의 보안 위협 탐지 및 대응
[AWS Builders] AWS상의 보안 위협 탐지 및 대응
 
Data Center Migration to the AWS Cloud
Data Center Migration to the AWS CloudData Center Migration to the AWS Cloud
Data Center Migration to the AWS Cloud
 
Building Data Lakes with AWS
Building Data Lakes with AWSBuilding Data Lakes with AWS
Building Data Lakes with AWS
 
Migrating your Data Centre to AWS
Migrating your Data Centre to AWSMigrating your Data Centre to AWS
Migrating your Data Centre to AWS
 

Similar a AWS Governance Overview - Beach

Accelerating SharePoint for Mobile Solutions on AWS
Accelerating SharePoint for Mobile Solutions on AWSAccelerating SharePoint for Mobile Solutions on AWS
Accelerating SharePoint for Mobile Solutions on AWS
Amazon Web Services
 
선도 금융사들의 aws security 활용 방안 소개 :: Eugene Yu :: AWS Finance...
선도 금융사들의 aws security 활용 방안 소개 :: Eugene Yu :: AWS Finance...선도 금융사들의 aws security 활용 방안 소개 :: Eugene Yu :: AWS Finance...
선도 금융사들의 aws security 활용 방안 소개 :: Eugene Yu :: AWS Finance...
Amazon Web Services Korea
 
16h30 aws gru security deck
16h30   aws gru security deck16h30   aws gru security deck
16h30 aws gru security deck
infolive
 

Similar a AWS Governance Overview - Beach (20)

Running Microsoft SharePoint On AWS - Smartronix and AWS - Webinar
Running Microsoft SharePoint On AWS - Smartronix and AWS - WebinarRunning Microsoft SharePoint On AWS - Smartronix and AWS - Webinar
Running Microsoft SharePoint On AWS - Smartronix and AWS - Webinar
 
Accelerating SharePoint for Mobile Solutions on AWS
Accelerating SharePoint for Mobile Solutions on AWSAccelerating SharePoint for Mobile Solutions on AWS
Accelerating SharePoint for Mobile Solutions on AWS
 
Best Practices: Microsoft on AWS - Miles Ward - AWS Summit 2012 Australia
Best Practices: Microsoft on AWS - Miles Ward - AWS Summit 2012 AustraliaBest Practices: Microsoft on AWS - Miles Ward - AWS Summit 2012 Australia
Best Practices: Microsoft on AWS - Miles Ward - AWS Summit 2012 Australia
 
Microsoft Best Practices - AWS India Summit 2012
Microsoft Best Practices - AWS India Summit 2012Microsoft Best Practices - AWS India Summit 2012
Microsoft Best Practices - AWS India Summit 2012
 
AWS Security for Financial Services
AWS Security for Financial ServicesAWS Security for Financial Services
AWS Security for Financial Services
 
Smartronix - Building Secure Applications on the AWS Cloud
Smartronix - Building Secure Applications on the AWS CloudSmartronix - Building Secure Applications on the AWS Cloud
Smartronix - Building Secure Applications on the AWS Cloud
 
Getting Started with AWS Security
Getting Started with AWS SecurityGetting Started with AWS Security
Getting Started with AWS Security
 
17h30 aws enterprise_app_jvaria
17h30 aws enterprise_app_jvaria17h30 aws enterprise_app_jvaria
17h30 aws enterprise_app_jvaria
 
[AWS Summit 2012] ソリューションセッション#4 AWS: Overview of Security Processes
[AWS Summit 2012] ソリューションセッション#4 AWS: Overview of Security Processes[AWS Summit 2012] ソリューションセッション#4 AWS: Overview of Security Processes
[AWS Summit 2012] ソリューションセッション#4 AWS: Overview of Security Processes
 
Building Secure Architectures on AWS
Building Secure Architectures on AWSBuilding Secure Architectures on AWS
Building Secure Architectures on AWS
 
Intro & Security Update
Intro & Security UpdateIntro & Security Update
Intro & Security Update
 
선도 금융사들의 aws security 활용 방안 소개 :: Eugene Yu :: AWS Finance...
선도 금융사들의 aws security 활용 방안 소개 :: Eugene Yu :: AWS Finance...선도 금융사들의 aws security 활용 방안 소개 :: Eugene Yu :: AWS Finance...
선도 금융사들의 aws security 활용 방안 소개 :: Eugene Yu :: AWS Finance...
 
16h30 aws gru security deck
16h30   aws gru security deck16h30   aws gru security deck
16h30 aws gru security deck
 
Getting Started on AWS
Getting Started on AWSGetting Started on AWS
Getting Started on AWS
 
Security on AWS
Security on AWSSecurity on AWS
Security on AWS
 
Getting Started with AWS Security
Getting Started with AWS SecurityGetting Started with AWS Security
Getting Started with AWS Security
 
Cloud Connections: Integrating Enterprise IT with the Cloud
Cloud Connections: Integrating Enterprise IT with the CloudCloud Connections: Integrating Enterprise IT with the Cloud
Cloud Connections: Integrating Enterprise IT with the Cloud
 
Deploy a DoD Secure Cloud Computing Architecture Environment in AWS | AWS Pub...
Deploy a DoD Secure Cloud Computing Architecture Environment in AWS | AWS Pub...Deploy a DoD Secure Cloud Computing Architecture Environment in AWS | AWS Pub...
Deploy a DoD Secure Cloud Computing Architecture Environment in AWS | AWS Pub...
 
AWS June Webinar Series - Deep dive: Hybrid Architectures
AWS June Webinar Series - Deep dive: Hybrid ArchitecturesAWS June Webinar Series - Deep dive: Hybrid Architectures
AWS June Webinar Series - Deep dive: Hybrid Architectures
 
CJIS Evidence Management in the Cloud using AWS GovCloud (US) | AWS Public Se...
CJIS Evidence Management in the Cloud using AWS GovCloud (US) | AWS Public Se...CJIS Evidence Management in the Cloud using AWS GovCloud (US) | AWS Public Se...
CJIS Evidence Management in the Cloud using AWS GovCloud (US) | AWS Public Se...
 

Más de Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

Más de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 
Come costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWSCome costruire un'architettura Serverless nel Cloud AWS
Come costruire un'architettura Serverless nel Cloud AWS
 

Último

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 

Último (20)

ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024FWD Group - Insurer Innovation Award 2024
FWD Group - Insurer Innovation Award 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 

AWS Governance Overview - Beach

  • 1. AWS Cloud Governance Overview Nathan Beach Principle Solution Architect AWS Worldwide Public Sector October 2012
  • 2. centralized decentralized hybrid AWS Cloud Governance data infrastructure application A Shared Responsibility Model scalable highly available accessible
  • 3. Governance… “Governance implies control and oversight over policies, procedures, and standards for application development, as well as the design, implementation, testing, and monitoring of deployed services.” Wayne Jansen, Timothy Grace, NIST SP 800-144: Guidelines on Security and Privacy in Public Cloud Computing, January 2011. URL: http://csrc.nist.gov/publications/nistpubs/800-144/SP800-144.pdf
  • 4. …is a Shared Responsibility “Cloud Providers and Cloud Consumers collaboratively design, build, deploy, and operate cloud-based systems. The split of control means both parties now share the responsibilities in providing adequate protections to the cloud-based systems. Security is a shared responsibility.” Fang Liu, Jin Tong, Jian Mao, Robert Bohn, John Messina, Lee Badger and Dawn Leaf, NIST SP 500-292: NIST Cloud Computing Reference Architecture, September 2011.
  • 5. AWS Investments Establish a Trusted Foundation Certifications Physical Security HW, SW, Network SOC 1 Type 2 Datacenters in Systematic change (formerly SAS-70) nondescript facilities management ISO 27001 Physical access Phased updates strictly controlled deployment PCI DSS for EC2, S3, EBS, VPC, Must pass two-factor Safe storage RDS, ELB, IAM authentication at decommission least twice for floor Automated access monitoring and self- Physical access audit logged and audited Advanced network protection
  • 6. Authorizations and ATOs FISMA Moderate ITAR Compliant Region (GovCloud) DIACAP MAC III/Sensative
  • 7. Statement on Auditing Standards No. 70 (SAS 70) Type II report. Conducted in accordance with the Statement on Standards for Attestation Engagements No. 16 (SSAE 16) and the International Standards for Assurance Engagements No. 3402 (ISAE 3402) professional standards. Attests that AWS’ control objectives are appropriately designed and that the individual controls defined to safeguard customer data are operating effectively. Our commitment to the SOC 1 report is on-going with planned periodic audits. SOC 1 Type 2 Replaces Statement on Auditing Standards No. 70 (SAS 70) Type II report.
  • 8. ISO 27001 Certification AWS achieved ISO 27001 certification of our Information Security Management System (ISMS) covering our infrastructure, data centers, and services including Amazon Elastic Compute Cloud (Amazon EC2), Amazon Simple Storage Service (Amazon S3) and Amazon Virtual Private Cloud (Amazon VPC). Certifies our systematic and ongoing approach to managing information security risks that affect the confidentiality, integrity, and availability of company and customer information. AWS’s ISO 27001 certification includes all AWS data centers in all regions worldwide and AWS has established a formal program to maintain the certification. A copy of our ISO certificate, available to AWS customers, describes the ISMS services and geographic scope.
  • 9. Payment Card Industry (PCI) Data Security Standard (DSS) Certification PCI-DSS is a standard that specifies best practices and various security controls. Certification in the standard requires organizations to:  Build and maintain a secure network  Protect cardholder data  Maintain a vulnerability management program  Implement strong security measures  Regularly test and monitor networks  Maintain an information security policy
  • 10. Shared Responsibility to Implement Controls
  • 11. AWS Cloud Governance Service Enablers Governance Area AWS Technologies Roles and Responsibilities • Identity and Access Management: Policies, Roles Configuration Management • Cloud Formation Templates • Elastic Beanstalk • Private AMIs Financial Controls • Consolidated Billing • Linked Accounts • CloudWatch Billing Alarms Network Security • Virtual Private Cloud • Network ACLs • Security Groups • Virtual Private Gateways • VPN Connections • Route Tables and Subnets
  • 12. AWS Cloud Governance Service Enablers (cont.) Governance Area AWS Technologies Information Assurance • Corporate “Gold” Operating System Images Processing • VPC Workload Isolation • Dedicated EC2 Instances Information Assurance • S3 AES 256 bit Encryption Storage • Partner Extensions offer Boot Volume and EBS Volume Encryption Information Assurance • HW/SW VPN Connections Transmission • DirectConnect Network Security • Virtual Private Cloud • Network ACLs • Security Groups • Virtual Private Gateways • VPN Connections
  • 13. AWS Cloud Governance Service Enablers (cont.) Governance Area AWS Technologies Access Controls • Identity and Access Management Policies • Bucket Policies • EC2 Instance Roles • Query String Authentication • Access Control Lists Identification and • Identity and Access Management Authentication • Multi-Factor Authentication • Group Policies and Roles • Federated Identity Management API
  • 14. AWS Cloud Governance Service Enablers (cont.) Governance Area AWS Technologies Disaster Recovery and Data Continuity of Operations • EBS Snapshots • S3 Near-Line Storage • Glacier Near-Offline Storage • Storage Gateway • Bulk Data Import/Export • Managed AWS No-SQL/SQL Database Services • Extensive 3rd Party Solutions Workload • Elastic load Balancers • EC2 Auto Scaling • Route 53 – Latency Based Routing • Cloud Front – Content Delivery Network • Multi-AZ, Multi-Region Workload Deployment
  • 15. AWS Cloud Governance Service Enablers (cont.) Governance Area AWS Technologies Monitoring and Reporting • Cloud Watch • Cloud Watch Alarms • Simple Notification Service
  • 16. References and Further Reading Wayne Jansen, Timothy Grace, NIST SP 800-144: Guidelines on Security and Privacy in Public Cloud Computing, January 2011. URL: http://csrc.nist.gov/publications/nistpubs/800-144/SP800-144.pdf Fang Liu, Jin Tong, Jian Mao, Robert Bohn, John Messina, Lee Badger and Dawn Leaf, NIST SP 500-292: NIST Cloud Computing Reference Architecture, September 2011.URL: http://www.nist.gov/customcf/get_pdf.cfm?pub_id=909505 NIST SP 800-53 R3: Recommended Security Controls for Federal Information Systems and Organizations, August 2009. URL: http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3- final_updated-errata_05-01-2010.pdf Amazon Web Services: Security and Accreditation Center: Certifications URL: http://aws.amazon.com/security/#certifications
  • 17.
  • 18. AWS Cloud Governance Overview Nathan Beach Principle Solution Architect AWS Worldwide Public Sector E-Mail: nsbeach@amazon.com