7. SAS 70 Type II Audit ISO 27001/2 Certification PCI DSS 2.0 Level 1-5 HIPAA/SOX Compliance FISMA A&A Low Encrypt data in transit Encrypt data at rest Protect your AWS Credentials Rotate your keys Secure your application, OS, Stack and AMIs Enforce IAM policies Use MFA, VPC, Leverage S3 bucket policies, EC2 Security groups, EFS in EC2 Etc.. In the cloud, Security is a Shared Responsibility How we secure our infrastructure How can you secure your application and what is your responsibility? What security options and features are available to you?
9. Keys to choosing a Cloud Security and OperationalExcellence Provides Flexibility and Choice
10. The “Living and Evolving” AWS Cloud Your Application Tools to access services Libraries and SDKs .NET/Java etc. Web Interface Management Console Tools AWS Toolkit for Eclipse Command Line Interface Cross Service features Authentication and AuthorizationAWS IAM, MFA Monitoring Amazon CloudWatch Deployment and Automation AWS Elastic BeanstalkAWS CloudFormation High-level Infrastructure building blocks Content Delivery Amazon CloudFront Email Amazon SES Payments Amazon DevPay Amazon FPS Parallel Processing Amazon Elastic MapReduce Messaging Amazon SNS Amazon SQS Workforce Amazon Mechanical Turk Low-level Infrastructure building blocks Compute Amazon EC2 Auto Scaling Network Amazon VPC Elastic LB Amazon Route 53 Storage Amazon S3 Amazon EBS Database Amazon RDS Amazon SimpleDB Amazon Global Physical Infrastructure (Geographical Regions, Availability Zones, Edge Locations)
11. The “Living and Evolving” AWS Cloud Your Application Tools to access services Libraries and SDKs .NET/Java etc. Web Interface Management Console Tools AWS Toolkit for Eclipse Command Line Interface Cross Service features Authentication and AuthorizationAWS IAM, MFA Monitoring Amazon CloudWatch Deployment and Automation AWS Elastic BeanstalkAWS CloudFormation High-level Infrastructure building blocks Content Delivery Amazon CloudFront Email Amazon SES Payments Amazon DevPay Amazon FPS Parallel Processing Amazon Elastic MapReduce Messaging Amazon SNS Amazon SQS Workforce Amazon Mechanical Turk Low-level Infrastructure building blocks Compute Amazon EC2 Network Amazon VPC Elastic LB Amazon Route 53 Storage Amazon S3 Amazon EBS Database Amazon RDS Amazon SimpleDB Amazon Global Physical Infrastructure (Geographical Regions, Availability Zones, Edge Locations)
12. Keys to choosing a Cloud Security and OperationalExcellence Provides Flexibility and Choice
13. Keys to choosing a Cloud Security and OperationalExcellence Provides Flexibility and Choice Listens to the customer’s requests and iterates quickly
14.
15. Boot from Amazon EBS» Amazon CloudFront Streaming » Amazon VPC enters Unlimited Beta » AWS Region in Northern California » International Support for AWS Import/Export » AWS Multi-Factor Authentication » Virtual Private Cloud » Lower Reserved Instance Pricing » Reserved Instances in EU Region » Elastic MapReduce » SQS in EU Region » Amazon RDS » High-Memory Instances » Lower EC2 Pricing » New SimpleDB Features » FPS General Availability » Amazon SNS » AWS Security Center 2009 Jan 2010 Jan Jul Sep Oct Dec Aug Nov Feb Mar Apr Jun May Feb Mar » Amazon EC2 with Windows » Amazon EC2 in EU Region » AWS Toolkit for Eclipse » Amazon EC2 Reserved Instances » Amazon CloudFront Private Content » SAS70 Type II Audit » AWS SDK for .NET » Amazon Elastic MapReduce in Europe » Amazon EC2 Reserved Instances with Windows, Extra Large High Memory Instances » Amazon S3 Versioning Feature » Consolidated Billing for AWS » Lower pricing for Outbound Data Transfer » AWS Import/Export » New CloudFront Feature » Monitoring, Auto Scaling & Elastic Load Balancing » EBS Shared Snapshots » SimpleDB in EU Region » Monitoring, Auto Scaling & Elastic Load Balancing in EU » Lower pricing tiers for Amazon CloudFront » AWS Management Console The pace of innovation in 2009
16. » Free Monitoring EC2 » Amazon Route 53 » PCI DSS Level 1 Certification » Mobile SDKs (Android, iPhone) » Large Object S3 Support » Florida POP » Import/Export APAC » Amazon SNS » Combined AWS Data Transfer Savings » Amazon EMR Bootstrap Actions » Amazon ELB Session Stickiness » Amazon RDS in EU » New Singapore Region » RDS Reserved » CloudFront Default Root » Startup Challenge 2010 » CloudFront Invalidation » AWS Elastic Beanstalk » Amazon Simple Email Service » Improved AWS Support “Bronze” » Amazon CloudWatch Console » CloudFront HTTPS » NYC Edge Location » Lowers Pricing HTTP » AWS Import Export GA » Amazon SNS » Amazon S3 Console » Amazon EBS CloudWatch » Amazon RDS Read Replicas » Suse EC2 Linux » Amazon SNS Console » Amazon ELB HTTPS » AWS Free Tier » EMR Resizing Cluster » EMR JobFlow Debugging » Simple DB Consistent Reads » Simple DB Conditional Puts » VM Connector » Tokyo Region » AWS Support JP 2010 Jan 2011 Jan Jul Sep Oct Dec Aug Nov Feb Mar Apr Jun May Feb Mar » New VPC » Dedicated Instances » Windows 2008 R2 » Amazon S3 Lowered Pricing » CloudFront GA, SLA » S3 Multipart » GPGPU Instance Types » ISO27001/2 Certification » Amazon SQS Longer retention, Free Tier Amazon S3 Bucket Policies » Amazon VPC IP Address » Cluster Compute Instances » Amazon S3 RRS Notifications » AWS Java SDK » Windows BYOL » Singapore Pop » CloudFront Private Streaming » Lowered Pricing EC2 » AWS IAM » Amazon VPC Console » Micro Instances » Amazon Linux AMI » Amazon EC2 Tagging, Filtering, Idempotency, » Oracle Certified AWS » AWS PHP SDK » AWS CloudFormation » Amazon S3 Static Websites » AWS IAM Website Login » Paris Edge Location » Amazon EC2 Reserved Instances with Windows, Extra Large High Memory Instances » Amazon S3 Versioning Feature » Consolidated Billing for AWS » Lower pricing for Outbound Data Transfer » VPC in EU » Amazon RDS in US-west » Amazon CloudFront Access Logs » Amazon RDS Multi-AZ » Amazon S3 RRS » Amazon RDS Console And pace accelerates in 2010….
17. Innovative Business Models For Spiky workloads For Steady State Workloads For Time-insensitive workloads For Regulatory and Compliant Workloads
18. Keys to choosing a Cloud Security and OperationalExcellence Provides Flexibility and Choice Listens to the customer’s requests and iterates quickly
19. Keys to choosing a Cloud Security and OperationalExcellence Provides Flexibility and Choice Listens to the customer’s requests and iterates quickly Continues to lower costs for customers
20. AWS History of Lowering Prices Apr 22, 2008 AWS Lowers Data Transfer Costs – Effective May 1 Oct 09, 2008 New Tiered Pricing for Amazon S3 Storage Jan 28, 2009 New Lower Pricing Tiers for Amazon CloudFront Aug 20, 2009 New Lower Prices for Amazon EC2 Reserved Instances Sep 30, 2009 New Lower Price for Windows Instances with Authentication Services Oct 27, 2009 Announcing Lower Amazon EC2 Instance Pricing Dec 08, 2009 AWS Announces Pricing Changes Amazon S3 Storage Pricing Tiers Amazon S3 EU (Ireland) Pricing Amazon EC2 Windows Instance EU (Ireland) Pricing Free Inbound Data Transfer (until June 30, 2010) Feb 01, 2010 AWS Announces Lower Pricing for Outbound Data Transfer Apr 01, 2010 Announcing Combined AWS Data Transfer Pricing May 19, 2010 Announcing Amazon S3 Reduced Redundancy Storage Jun 07, 2010 Amazon CloudFront Adds HTTPS Support, Lowers Prices, Opens NYC Edge Location Jul 01, 2010 Amazon SQS introduces Free Tier Sep 01, 2010 New Lower Prices for High Memory Double and Quadruple XL Instances Oct 05, 2010 Lower High Memory DB Instance Prices for Amazon RDS Oct 21, 2010 Announcing AWS Free Usage Tier Nov 01, 2010 Amazon S3 Reduces Storage Pricing Dec 03, 2010 Amazon CloudWatch Free Monitoring
21. Keys to choosing a Cloud Security and OperationalExcellence Provides Flexibility and Choice Listens to the customer’s requests and iterates quickly Continues to lower costs for customers Helps the customer compete in the Global Market
22. Keys to choosing a Cloud Security and OperationalExcellence Provides Flexibility and Choice Listens to the customer’s requests and iterates quickly Continues to lower costs for customers Helps the customer compete in the Global Market
23. US West (Northern California) US East (Northern Virginia) Europe West (Dublin) Asia Pacific Region (Singapore) Asia Pacific Region (Japan) Ashburn, Dallas, Los Angeles, Miami, Newark, Palo Alto, Seattle, St. Louis, Amsterdam, Dublin, Frankfurt, London, Hong Kong, Singapore, Tokyo Amazon CloudFront Edge Locations
24. Asia Traffic Europe Traffic US West Traffic US East Traffic DNS Geo IP/Directional DNS Server CNAME Singapore US-West US-East EU-West ELB ELB ELB ELB AutoScaling group : Web App Tier AutoScaling group : Web App Tier AutoScaling group : Web App Tier AutoScaling group : Web App Tier Singapore-1b US-West-1b US-East-1b EU-West-1b Web Web Web Web Web Web Web Web Web Web Web Web Web Web Web Web Web Web Web Web Web Web Web Web App App App App App App App App App App App App App App App App App App App App App App App App RDS Master RDS Master RDS Master RDS Master RDS Multi-AZ RDS Multi-AZ RDS Multi-AZ RDS Multi-AZ Software-based Data Replicator
25. Keys to choosing a Cloud Security and OperationalExcellence Provides Flexibility and Choice Listens to the customer’s requests and iterates quickly Continues to lower costs for customers Helps the customer compete in the Global Market
27. Thank You! Jinesh Varia jvaria@amazon.com Follow me on Twitter: @jinman
Notas del editor
My favorite tweet from last week really summarizes the current situation that exists today.
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…
InvestmentFocusMotivation (top down and bottom up)
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…
Make a joke…. Cannot fit in one slide…..anymore so (show next slide)11/2, Amazaon S3 price reduction10/21, AWS Free Usage Tier10/20, Resizable Elastic Map Reduce jobs10/18,Feature Release,Mgmt Console adds support for Simple Notifications Service10/14,Feature Release,Elastic Load Balancer termination of SSL certs10/8,Feature Release,Mgmt console support for Amazon Relational Database Service DB Engine Version10/6,Feature Release: Support for Suse Linux10/6,Price Reduction,RDS10/6,Feature Release,RDS Read Replicas9/29,Feature Release,Download invoices9/21,Feature Release,Amazon EC2 on the Oracle Virtual Machine and full Oracle Support, Certification and License portability9/20,Feature Release,Resource tagging & associated features9/17,Case Study,Matlab HPC benchmark9/15,Feature Release,Amazon Linux9/8,Feature Release,Mgmt console support for VPC9/2,Price reduction,M2.2x & M2.4x8/31,Case study,Authority to Operate-Appian BPM8/25,General Announcement,Updated Security Whitepaper8/24,Feature Release,Java SDK updated8/17,Feature Release,RDS reserved instances8/17,Feature Release,MySQL DB engine version mgmt8/6,Feature Release,CloudFront Default Root Object7/23,Opperational Change,Vulnerability Reporting and Pen Testing7/16,Feature Release,Use your own kernel7/15,Feature Release,Enhanced CF logs w/ Query strings7/14,Feature Release,RRS in Mgmt Console7/14,Feature Release,VPC IP address control & config file generation6/29,Feature Release,RDS support of SSL
Make a joke…. Cannot fit in one slide…..anymore so (show next slide)11/2, Amazaon S3 price reduction10/21, AWS Free Usage Tier10/20, Resizable Elastic Map Reduce jobs10/18,Feature Release,Mgmt Console adds support for Simple Notifications Service10/14,Feature Release,Elastic Load Balancer termination of SSL certs10/8,Feature Release,Mgmt console support for Amazon Relational Database Service DB Engine Version10/6,Feature Release: Support for Suse Linux10/6,Price Reduction,RDS10/6,Feature Release,RDS Read Replicas9/29,Feature Release,Download invoices9/21,Feature Release,Amazon EC2 on the Oracle Virtual Machine and full Oracle Support, Certification and License portability9/20,Feature Release,Resource tagging & associated features9/17,Case Study,Matlab HPC benchmark9/15,Feature Release,Amazon Linux9/8,Feature Release,Mgmt console support for VPC9/2,Price reduction,M2.2x & M2.4x8/31,Case study,Authority to Operate-Appian BPM8/25,General Announcement,Updated Security Whitepaper8/24,Feature Release,Java SDK updated8/17,Feature Release,RDS reserved instances8/17,Feature Release,MySQL DB engine version mgmt8/6,Feature Release,CloudFront Default Root Object7/23,Opperational Change,Vulnerability Reporting and Pen Testing7/16,Feature Release,Use your own kernel7/15,Feature Release,Enhanced CF logs w/ Query strings7/14,Feature Release,RRS in Mgmt Console7/14,Feature Release,VPC IP address control & config file generation6/29,Feature Release,RDS support of SSL
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…
There’s still a lot of noise out there about the cloud. As you take your next step into this new world, let me offer some suggestions on the key questions to ask yourself in choosing a provider…