SlideShare una empresa de Scribd logo
1 de 55
Descargar para leer sin conexión
Nick Matthews, Solutions Architect, AWS
Matt Keil, Director of Product Marketing - Public Cloud, Palo Alto Networks
John Plishker, Solution Architect, REAN Cloud
Automate the Provisioning
of Secure Developer Environments
on Amazon Web Services
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What is Driving AWS Adoption?
Urgent Need to Respond to Business Needs for:
Increased
Agility
Flexibility
Lower Costs and
Transparency
More
Capabilities
Go Global in
Minutes
Remove Infrastructure
Dependencies
Remove IT as a “Blocker” to Innovation
Compelling Events on the Journey
Value
Time
Discovery
and Testing
Application-
Based Projects
Cloud-First /
Standardization
Business
Transformation
Build applications
to run on the AWS
Cloud
Dev & Test /
Startups
Production App
Migration
“Cloud-First”
Standardization /
Mass Migration
Automation /
Business Innovation
Projects
Current State
1
2
3
4
5
Automating logging
and monitoring
Simplifying resource
access
Making it easy
to encrypt properly
Enforcing
strong authentication
AWS Can Be More Secure than Your
Existing Environment
In a recent report which found that most customers can be more secure in
AWS than their on-premises environment. How?
AWS and You Share Responsibility
for Security
Constantly Monitored
 Network access is monitored by AWS
security managers daily
 AWS CloudTrail lets you monitor
and record all API calls
 Amazon Inspector automatically assesses
applications for vulnerabilities
The AWS infrastructure is protected by extensive network
and security monitoring systems:
Highly Available
 44 Availability Zones in 16 regions for
multi-synchronous geographic redundancy
 Retain control of where your data resides
for compliance with regulatory requirements
 Mitigate the risk of DDoS attacks using
services like Route 53
 Dynamically grow to meet unforeseen demand
using Auto Scaling
The AWS infrastructure footprint helps protect your data
from costly downtime:
Integrated with Your Existing Resources
 Integrate your existing Active Directory
 Use dedicated connections as a secure,
low-latency extension of your data center
 Provide and manage your own encryption
keys if you choose
AWS enables you to improve your security using many
of your existing tools and practices:
Key AWS Certifications and
Assurance Programs
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Palo Alto Networks
Matt Keil, Director of Product Marketing - Public Cloud, Palo Alto Networks
Applications and Data Are the Target
The attack life cycle applies to both physical or virtualized
networks in the cloud
Infect
User
Gain
Foothold
Move
Laterally Steal
Data
Build
Botnets
Harvest
Bitcoin
Execute Goal:
On the network
or in the Cloud
What We Do
Next-generation firewall on AWS
Deployed as an EC2 instance in a VPC
 Identify and control apps – not ports
 Prevent known and unknown threats
 Centrally managed for policy consistency
 Automation to keep pace with the cloud
Hourly and annual Marketplace subscriptions
and bring your own license (BYOL)
AWS Security Competency
Approved through integration with
ELB/ALB and Auto Scaling
Shared Responsibility Model: Where We Can
Help
Where Palo
Alto
Networks Can
Help
Complete
Application Visibility
Scalability &
Resiliency
Threat
Prevention
Touchless
Deployment
Application
Segmentation
Centralized
Management
 Reducing the threat exposure with
application-based security policies
 Preventing known and unknown
threats within allowed applications;
blocking lateral movement
 Controlling file movement within
allowed applications
Palo Alto Networks VM-Series Features
We Complement Security Groups and Web Application Firewalls (WAF)
by…
Devops and Security Working Together?
DevOps
 Dynamic environment
 Frequent workload changes
 Code security is Job 1
Security
 Structured, follow change
control best practices
 Protection of digital assets
is Job 1
The Solution: Automation
Fully documented XML APIXML API
Dynamic Policy Updates
Bootstrapping
Automate Firewall Deployments
Attach to Panorama
Device Group
vm-series-bootstrap-aws-s3-
bucket=<bucketname>
Amazon
S3
VM-Series configuration
Security policies
Firewall licenses
Software updates
Dynamic content
Bi-Directional Integration Via an XML API
Inbound
 XML changes to Bootstrap file
 Block lists
 3rd party policy management tools
Outbound
 Amazon CloudWatch
 ServiceNow
 Orchestration tools
Dynamically Update Firewall Policies
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
REAN Cloud
John Plishker, Solution Architect, REAN Cloud
Who We Are
Established: 2013
Presence:
USA, India
Number of Employees: 300+
AWS Certifications: 150+ (Including 15+ Professional
Certifications)
Industry Focus:
Education, Government, Healthcare / Life Sciences,
Financial Services, and ISV
Corporate Highlights:
Migration Competency
DevOps Competency
Storage Competency
Microsoft Workloads Competency
Life Sciences Competency
Government Competency
Education Competency
Financial Services Competency
Managed Services Partner
Market Place Partner
REAN Cloud Service Offering
REAN Managed
Cloud Services
REAN
Implementation
Services
REAN Business
Consulting
Migration
Native AWS
Application
Development
DevOps (CI|CD)
Implementation Billing as a Service
Secure Infrastructure
Setup
Security & Risk Assessment
ROI & Business Case
Justification Cloud Adoption Strategy Cloud Architecture
CloudSecOpsDataDevOpsBizDevOps
Managed Cloud Services
DR & Business Continuity Planning
(BCP) Governance & Compliance
REAN Cloud DevOps Adoption Steps
Test-Driven
Deployment
Automated
Deployments
Automated
Operations
Metrics
Focused
Platform
Continuous
Security &
Compliance
REAN Cloud - Accelerators Framework
Deploy Verify Manage
Executive
Dashboards
Operational
Accelerators
CI/CD/CC
Automations
REAN Deploy - Packaged Cloud Resources
Features
 Drag and Drop
Environment
 Infrastructure as Code
 Multi-Platform Support
 Provisioner Agnostic
REAN Deploy - Infrastructure as Code
Cloud
Provider
Resources
Application
Packages
DEV / QA / PROD
Environment Blueprint
+
CD Pipeline
Provision/Validate
Infrastructure
Provision/Validate
Applications
Functional
Regression
Testing
Security Testing
Infrastructure
As
Code (IaC)
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Success Story: Gigamon
Background: Who is Gigamon
Gigamon is an ISV that offers a Visibility Platform
that helps manage, secure, and understand data
in motion
 Solution levered in federal, financial services,
healthcare, and technology service providers
 Used Palo Alto Network Firewall in their on-prem
development environments
 Global offices across 20 different countries
Challenge: Efficiently & Securely Providing
Developer Environments
 Needed to take their solution to support the
cloud
 Did a migration to the cloud for development
and had some challenging results
 Virtually unlimited developer access to cloud
resources introduced vulnerabilities
 Unstructured environments hampered
developer productivity
 New environments being spun up by
developers put operating budgets at risk
Challenge: Security Bottlenecks
 Deploying third party security into VPCs was
introducing bottlenecks
 Developers wanted to operate freely, and
iterate quickly
 Security team concerned about new,
unsecured environments
Define and develop
a simple, fast, and
automated solution
Provision new Amazon
VPCs automatically
protected by VM-
Series Firewall
Develop control VPC
to accept new VPN
connections from
developer VPCs
Automate all workflows
to simplify the creation
of developer
environments
The Palo Alto Networks and
REAN Cloud Solution
Securing Developer VPCs
 Install the VM-Series into the control VPC
 Setup VPNs to VPCs and to other locations
 Implement an orchestration tool to extract
instance IP addresses
 Build bootstrap code out of the network
interfaces and IP addresses
 Leverage the bootstrap code to spin up new
environments with VM-Series and security
policies already in place
Creating the right foundation….
 Setting up a common
security infrastructure to
support a range of
developer needs
 Control VPC supports
connections for:
 Development VPCs
 Separate Regions
 On-Premise
 High Availability
Automating the deployment
 Provision the Control VPC
 Multiple automaton
approaches; REAN Deploy,
Cloud Formation,
Teraform, etc.
 Deploy in layers
REAN Deploy
Automating the VM-Series Firewall
 Fully managed
deployment in any VPC
configuration
 Bootstrap the VM-Series
Firewall
Challenge: How do you know
about the network interfaces
before you deployed the
instances
Automating the VM-Series Firewall
Challenge: How do you know
about the network interfaces
before you deployed the
instances
 Deploy networking
infrastructure
 Use an Orchestrator (i.e.
Jenkins)
 Pull IP addresses of
deployed configuration
Automating the VM-Series Firewall
 Need to create bootstrap
code
 Built config manually
 Exported configuration
 XML output
Automating the VM-Series Firewall
Snippet of xml configuration: Ruby ERB configuration:
Automating the VM-Series Firewall
 Stored the Bootstrap in S3
buckets
Automating the VM-Series Firewall
 bootstrap.xml is
generated by
the orchestrator
Automating the VM-Series Firewall
Automating the VM-Series Firewall
1. Provision Instances
Automating the VM-Series Firewall
1. Provision Instances
2. Instances read from
Bootstraps
Automating the VM-Series Firewall
1. Provision Instances
2. Instances read from
Bootstraps
a. HA
b. Create VPN
3. Connected to Gigamon
Office
Automating the VM-Series Firewall
 Use XML API to establish
HA
 Floating ENI
 Elastic IP
Automating the VM-Series Firewall
 Ready for Developer to
deploy
 Automated the
deployment of a series of
configurations
Automating the VM-Series Firewall
 5-10 minute deployment
time
 Developer up and running
with access to VPC from
on-prem network
 Automated teardown as-
well
Automating the VM-Series Firewall
 Ready for Developer to
deploy
 Automated the
deployment of a series of
configurations
Automating the VM-Series Firewall
 Ready for Developer to
deploy
 Automated the
deployment of a series of
configurations
Automating the VM-Series Firewall
 Included support for VPCs
in multiple Regions
Automating the VM-Series Firewall
 Included support for VPCs
in multiple Regions
Results and Benefits
Deploy one or more
already secured
developer VPCs with
the push of a button
New VPCs are
connected to central
VPC via IPsec to
maintain compliance
Unsecured developer
environments are no
longer a concern
Successfully extended
their portfolio to cloud
technologies while
maintaining efficiency
and security
Next Steps
Available in AWS Marketplace
 Two bundles available as annual
or hourly subscriptions
Bring your own license (BYOL)
 Pick and choose licenses,
subscriptions and support to best
suite our needs
 Supported in AWS Regions and AWS
GovCloud (US)
Palo Alto Networks REAN Cloud
Consulting Services
 Cloud Architecture Designs
 Security Assessments
Implementation Services
 Build secure Foundation (Landing Zone)
 Blueprints for various
VM Series deployments
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Q & A
Nick Matthews, Solutions Architect, AWS
Matt Keil, Director of Product Marketing - Public Cloud, Palo Alto Networks
John Plishker, Solution Architect, REAN Cloud

Más contenido relacionado

La actualidad más candente

Deep Dive on New Features in Amazon S3 & Glacier - AWS Online Tech Talks
Deep Dive on New Features in Amazon S3 & Glacier - AWS Online Tech TalksDeep Dive on New Features in Amazon S3 & Glacier - AWS Online Tech Talks
Deep Dive on New Features in Amazon S3 & Glacier - AWS Online Tech TalksAmazon Web Services
 
Modernize and Move your Microsoft Applications on AWS
Modernize and Move your Microsoft Applications on AWSModernize and Move your Microsoft Applications on AWS
Modernize and Move your Microsoft Applications on AWSAmazon Web Services
 
Migrating Your Microsoft Applications to AWS - ENT325 - re:Invent 2017
Migrating Your Microsoft Applications to AWS - ENT325 - re:Invent 2017Migrating Your Microsoft Applications to AWS - ENT325 - re:Invent 2017
Migrating Your Microsoft Applications to AWS - ENT325 - re:Invent 2017Amazon Web Services
 
AWS Storage and Data Migration: AWS Innovate Ottawa
AWS Storage and Data Migration: AWS Innovate OttawaAWS Storage and Data Migration: AWS Innovate Ottawa
AWS Storage and Data Migration: AWS Innovate OttawaAmazon Web Services
 
Aws for Startups Building Cloud Enabled Apps
Aws for Startups Building Cloud Enabled AppsAws for Startups Building Cloud Enabled Apps
Aws for Startups Building Cloud Enabled AppsAmazon Web Services
 
AWS Data Transfer Services - AWS Gateway, AWS Snowball, AWS Snowball Edge, an...
AWS Data Transfer Services - AWS Gateway, AWS Snowball, AWS Snowball Edge, an...AWS Data Transfer Services - AWS Gateway, AWS Snowball, AWS Snowball Edge, an...
AWS Data Transfer Services - AWS Gateway, AWS Snowball, AWS Snowball Edge, an...Amazon Web Services
 
AWS January 2016 Webinar Series - Cloud Data Migration: 6 Strategies for Gett...
AWS January 2016 Webinar Series - Cloud Data Migration: 6 Strategies for Gett...AWS January 2016 Webinar Series - Cloud Data Migration: 6 Strategies for Gett...
AWS January 2016 Webinar Series - Cloud Data Migration: 6 Strategies for Gett...Amazon Web Services
 
Migrating Your Oracle Database to PostgreSQL - AWS Online Tech Talks
Migrating Your Oracle Database to PostgreSQL - AWS Online Tech TalksMigrating Your Oracle Database to PostgreSQL - AWS Online Tech Talks
Migrating Your Oracle Database to PostgreSQL - AWS Online Tech TalksAmazon Web Services
 
Security at Scale with AWS - AWS Summit Cape Town 2017
Security at Scale with AWS - AWS Summit Cape Town 2017 Security at Scale with AWS - AWS Summit Cape Town 2017
Security at Scale with AWS - AWS Summit Cape Town 2017 Amazon Web Services
 
Scaling the Platform for Your Startup
Scaling the Platform for Your StartupScaling the Platform for Your Startup
Scaling the Platform for Your StartupAmazon Web Services
 
Building and Managing Scalable Applications on AWS: 1 to 500K users
Building and Managing Scalable Applications on AWS: 1 to 500K usersBuilding and Managing Scalable Applications on AWS: 1 to 500K users
Building and Managing Scalable Applications on AWS: 1 to 500K usersAmazon Web Services
 
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀Track 5 Session 5_STG03 AWS 檔案儲存服務概觀
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀Amazon Web Services
 
How to Bring Microsoft Apps to AWS - AWS Online Tech Talks
How to Bring Microsoft Apps to AWS - AWS Online Tech TalksHow to Bring Microsoft Apps to AWS - AWS Online Tech Talks
How to Bring Microsoft Apps to AWS - AWS Online Tech TalksAmazon Web Services
 
NY Startup Day: Welcome & Keynote
NY Startup Day: Welcome & KeynoteNY Startup Day: Welcome & Keynote
NY Startup Day: Welcome & KeynoteAmazon Web Services
 
Serverlesss Big Data Analytics with Amazon Athena and Quicksight
Serverlesss Big Data Analytics with Amazon Athena and QuicksightServerlesss Big Data Analytics with Amazon Athena and Quicksight
Serverlesss Big Data Analytics with Amazon Athena and QuicksightAmazon Web Services
 
Artificial Intelligence on the AWS Cloud - AWS Innovate Ottawa
Artificial Intelligence on the AWS Cloud - AWS Innovate OttawaArtificial Intelligence on the AWS Cloud - AWS Innovate Ottawa
Artificial Intelligence on the AWS Cloud - AWS Innovate OttawaAmazon Web Services
 
Introducing Amazon Aurora with PostgreSQL Compatibility - AWS Online Tech Talks
Introducing Amazon Aurora with PostgreSQL Compatibility - AWS Online Tech TalksIntroducing Amazon Aurora with PostgreSQL Compatibility - AWS Online Tech Talks
Introducing Amazon Aurora with PostgreSQL Compatibility - AWS Online Tech TalksAmazon Web Services
 

La actualidad más candente (20)

Deep Dive on New Features in Amazon S3 & Glacier - AWS Online Tech Talks
Deep Dive on New Features in Amazon S3 & Glacier - AWS Online Tech TalksDeep Dive on New Features in Amazon S3 & Glacier - AWS Online Tech Talks
Deep Dive on New Features in Amazon S3 & Glacier - AWS Online Tech Talks
 
Modernize and Move your Microsoft Applications on AWS
Modernize and Move your Microsoft Applications on AWSModernize and Move your Microsoft Applications on AWS
Modernize and Move your Microsoft Applications on AWS
 
Migrating Your Microsoft Applications to AWS - ENT325 - re:Invent 2017
Migrating Your Microsoft Applications to AWS - ENT325 - re:Invent 2017Migrating Your Microsoft Applications to AWS - ENT325 - re:Invent 2017
Migrating Your Microsoft Applications to AWS - ENT325 - re:Invent 2017
 
AWS Storage and Data Migration: AWS Innovate Ottawa
AWS Storage and Data Migration: AWS Innovate OttawaAWS Storage and Data Migration: AWS Innovate Ottawa
AWS Storage and Data Migration: AWS Innovate Ottawa
 
Aws for Startups Building Cloud Enabled Apps
Aws for Startups Building Cloud Enabled AppsAws for Startups Building Cloud Enabled Apps
Aws for Startups Building Cloud Enabled Apps
 
AWS Data Transfer Services - AWS Gateway, AWS Snowball, AWS Snowball Edge, an...
AWS Data Transfer Services - AWS Gateway, AWS Snowball, AWS Snowball Edge, an...AWS Data Transfer Services - AWS Gateway, AWS Snowball, AWS Snowball Edge, an...
AWS Data Transfer Services - AWS Gateway, AWS Snowball, AWS Snowball Edge, an...
 
AWS January 2016 Webinar Series - Cloud Data Migration: 6 Strategies for Gett...
AWS January 2016 Webinar Series - Cloud Data Migration: 6 Strategies for Gett...AWS January 2016 Webinar Series - Cloud Data Migration: 6 Strategies for Gett...
AWS January 2016 Webinar Series - Cloud Data Migration: 6 Strategies for Gett...
 
Migrating Your Oracle Database to PostgreSQL - AWS Online Tech Talks
Migrating Your Oracle Database to PostgreSQL - AWS Online Tech TalksMigrating Your Oracle Database to PostgreSQL - AWS Online Tech Talks
Migrating Your Oracle Database to PostgreSQL - AWS Online Tech Talks
 
Builders' Day- Mastering Kubernetes on AWS
Builders' Day- Mastering Kubernetes on AWSBuilders' Day- Mastering Kubernetes on AWS
Builders' Day- Mastering Kubernetes on AWS
 
Security at Scale with AWS - AWS Summit Cape Town 2017
Security at Scale with AWS - AWS Summit Cape Town 2017 Security at Scale with AWS - AWS Summit Cape Town 2017
Security at Scale with AWS - AWS Summit Cape Town 2017
 
Data Migration Best Practices
Data Migration Best PracticesData Migration Best Practices
Data Migration Best Practices
 
Scaling the Platform for Your Startup
Scaling the Platform for Your StartupScaling the Platform for Your Startup
Scaling the Platform for Your Startup
 
Building and Managing Scalable Applications on AWS: 1 to 500K users
Building and Managing Scalable Applications on AWS: 1 to 500K usersBuilding and Managing Scalable Applications on AWS: 1 to 500K users
Building and Managing Scalable Applications on AWS: 1 to 500K users
 
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀Track 5 Session 5_STG03 AWS 檔案儲存服務概觀
Track 5 Session 5_STG03 AWS 檔案儲存服務概觀
 
How to Bring Microsoft Apps to AWS - AWS Online Tech Talks
How to Bring Microsoft Apps to AWS - AWS Online Tech TalksHow to Bring Microsoft Apps to AWS - AWS Online Tech Talks
How to Bring Microsoft Apps to AWS - AWS Online Tech Talks
 
NY Startup Day: Welcome & Keynote
NY Startup Day: Welcome & KeynoteNY Startup Day: Welcome & Keynote
NY Startup Day: Welcome & Keynote
 
Serverlesss Big Data Analytics with Amazon Athena and Quicksight
Serverlesss Big Data Analytics with Amazon Athena and QuicksightServerlesss Big Data Analytics with Amazon Athena and Quicksight
Serverlesss Big Data Analytics with Amazon Athena and Quicksight
 
Artificial Intelligence on the AWS Cloud - AWS Innovate Ottawa
Artificial Intelligence on the AWS Cloud - AWS Innovate OttawaArtificial Intelligence on the AWS Cloud - AWS Innovate Ottawa
Artificial Intelligence on the AWS Cloud - AWS Innovate Ottawa
 
EC2 and VPC Workshop
EC2 and VPC WorkshopEC2 and VPC Workshop
EC2 and VPC Workshop
 
Introducing Amazon Aurora with PostgreSQL Compatibility - AWS Online Tech Talks
Introducing Amazon Aurora with PostgreSQL Compatibility - AWS Online Tech TalksIntroducing Amazon Aurora with PostgreSQL Compatibility - AWS Online Tech Talks
Introducing Amazon Aurora with PostgreSQL Compatibility - AWS Online Tech Talks
 

Destacado

PASS 17: RDS SQL Server on Amazon Web Services Overview
PASS 17: RDS SQL Server on Amazon Web Services OverviewPASS 17: RDS SQL Server on Amazon Web Services Overview
PASS 17: RDS SQL Server on Amazon Web Services OverviewAmazon Web Services
 
Voice of the Customer: Zocdoc and Elevating Security While Moving to AWS
Voice of the Customer: Zocdoc and Elevating Security While Moving to AWSVoice of the Customer: Zocdoc and Elevating Security While Moving to AWS
Voice of the Customer: Zocdoc and Elevating Security While Moving to AWSAmazon Web Services
 
Welcome and AWS Big Data Solution Overview
Welcome and AWS Big Data Solution OverviewWelcome and AWS Big Data Solution Overview
Welcome and AWS Big Data Solution OverviewAmazon Web Services
 
Deploy and Enforce Compliance Controls When Archiving Large-Scale Data Stores...
Deploy and Enforce Compliance Controls When Archiving Large-Scale Data Stores...Deploy and Enforce Compliance Controls When Archiving Large-Scale Data Stores...
Deploy and Enforce Compliance Controls When Archiving Large-Scale Data Stores...Amazon Web Services
 
Turn Big Data into Big Value on Informatica and AWS
Turn Big Data into Big Value on Informatica and AWSTurn Big Data into Big Value on Informatica and AWS
Turn Big Data into Big Value on Informatica and AWSAmazon Web Services
 
Maturing your organization from DevOps to DevSecOps
Maturing your organization from DevOps to DevSecOpsMaturing your organization from DevOps to DevSecOps
Maturing your organization from DevOps to DevSecOpsAmazon Web Services
 
Dev & Test on AWS Webinar October 2017 - IL Webinar
Dev & Test on AWS Webinar October 2017 - IL WebinarDev & Test on AWS Webinar October 2017 - IL Webinar
Dev & Test on AWS Webinar October 2017 - IL WebinarAmazon Web Services
 
Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT
 Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT
Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPTAmazon Web Services
 
Secure and Streamline Access to Your AWS Management Console with Okta PPT
Secure and Streamline Access to Your AWS Management Console with Okta PPTSecure and Streamline Access to Your AWS Management Console with Okta PPT
Secure and Streamline Access to Your AWS Management Console with Okta PPTAmazon Web Services
 
Building a Strong Foundation with AWS Storage Services
Building a Strong Foundation with AWS Storage ServicesBuilding a Strong Foundation with AWS Storage Services
Building a Strong Foundation with AWS Storage ServicesAmazon Web Services
 
Detective Controls: Gain Visibility and Record Change:
Detective Controls: Gain Visibility and Record Change: Detective Controls: Gain Visibility and Record Change:
Detective Controls: Gain Visibility and Record Change: Amazon Web Services
 
Incident Response: Preparing and Simulating Threat Response
Incident Response: Preparing and Simulating Threat ResponseIncident Response: Preparing and Simulating Threat Response
Incident Response: Preparing and Simulating Threat ResponseAmazon Web Services
 
PASS 17 SQL Server on AWS Best Practices
PASS 17 SQL Server on AWS Best PracticesPASS 17 SQL Server on AWS Best Practices
PASS 17 SQL Server on AWS Best PracticesAmazon Web Services
 
Big Data Experience Sharing: Building Collaborative Data Analytics Platform -...
Big Data Experience Sharing: Building Collaborative Data Analytics Platform -...Big Data Experience Sharing: Building Collaborative Data Analytics Platform -...
Big Data Experience Sharing: Building Collaborative Data Analytics Platform -...Amazon Web Services
 

Destacado (16)

PASS 17: RDS SQL Server on Amazon Web Services Overview
PASS 17: RDS SQL Server on Amazon Web Services OverviewPASS 17: RDS SQL Server on Amazon Web Services Overview
PASS 17: RDS SQL Server on Amazon Web Services Overview
 
Future of Enterprise IT
Future of Enterprise IT Future of Enterprise IT
Future of Enterprise IT
 
Voice of the Customer: Zocdoc and Elevating Security While Moving to AWS
Voice of the Customer: Zocdoc and Elevating Security While Moving to AWSVoice of the Customer: Zocdoc and Elevating Security While Moving to AWS
Voice of the Customer: Zocdoc and Elevating Security While Moving to AWS
 
Opportunities derived by AI
Opportunities derived by AIOpportunities derived by AI
Opportunities derived by AI
 
Welcome and AWS Big Data Solution Overview
Welcome and AWS Big Data Solution OverviewWelcome and AWS Big Data Solution Overview
Welcome and AWS Big Data Solution Overview
 
Deploy and Enforce Compliance Controls When Archiving Large-Scale Data Stores...
Deploy and Enforce Compliance Controls When Archiving Large-Scale Data Stores...Deploy and Enforce Compliance Controls When Archiving Large-Scale Data Stores...
Deploy and Enforce Compliance Controls When Archiving Large-Scale Data Stores...
 
Turn Big Data into Big Value on Informatica and AWS
Turn Big Data into Big Value on Informatica and AWSTurn Big Data into Big Value on Informatica and AWS
Turn Big Data into Big Value on Informatica and AWS
 
Maturing your organization from DevOps to DevSecOps
Maturing your organization from DevOps to DevSecOpsMaturing your organization from DevOps to DevSecOps
Maturing your organization from DevOps to DevSecOps
 
Dev & Test on AWS Webinar October 2017 - IL Webinar
Dev & Test on AWS Webinar October 2017 - IL WebinarDev & Test on AWS Webinar October 2017 - IL Webinar
Dev & Test on AWS Webinar October 2017 - IL Webinar
 
Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT
 Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT
Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT
 
Secure and Streamline Access to Your AWS Management Console with Okta PPT
Secure and Streamline Access to Your AWS Management Console with Okta PPTSecure and Streamline Access to Your AWS Management Console with Okta PPT
Secure and Streamline Access to Your AWS Management Console with Okta PPT
 
Building a Strong Foundation with AWS Storage Services
Building a Strong Foundation with AWS Storage ServicesBuilding a Strong Foundation with AWS Storage Services
Building a Strong Foundation with AWS Storage Services
 
Detective Controls: Gain Visibility and Record Change:
Detective Controls: Gain Visibility and Record Change: Detective Controls: Gain Visibility and Record Change:
Detective Controls: Gain Visibility and Record Change:
 
Incident Response: Preparing and Simulating Threat Response
Incident Response: Preparing and Simulating Threat ResponseIncident Response: Preparing and Simulating Threat Response
Incident Response: Preparing and Simulating Threat Response
 
PASS 17 SQL Server on AWS Best Practices
PASS 17 SQL Server on AWS Best PracticesPASS 17 SQL Server on AWS Best Practices
PASS 17 SQL Server on AWS Best Practices
 
Big Data Experience Sharing: Building Collaborative Data Analytics Platform -...
Big Data Experience Sharing: Building Collaborative Data Analytics Platform -...Big Data Experience Sharing: Building Collaborative Data Analytics Platform -...
Big Data Experience Sharing: Building Collaborative Data Analytics Platform -...
 

Similar a Automate the Provisioning of Secure Developer Environments on AWS PPT

(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWSAmazon Web Services
 
Getting Started with AWS Security
Getting Started with AWS SecurityGetting Started with AWS Security
Getting Started with AWS SecurityAmazon Web Services
 
Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Envir...
Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Envir...Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Envir...
Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Envir...Amazon Web Services
 
How Symantec Cloud Workload Protection Secures LifeLock on AWS PPT
 How Symantec Cloud Workload Protection Secures LifeLock on AWS PPT How Symantec Cloud Workload Protection Secures LifeLock on AWS PPT
How Symantec Cloud Workload Protection Secures LifeLock on AWS PPTAmazon Web Services
 
How Symantec Cloud Workload Protection Secures LifeLock on AWS
 How Symantec Cloud Workload Protection Secures LifeLock on AWS How Symantec Cloud Workload Protection Secures LifeLock on AWS
How Symantec Cloud Workload Protection Secures LifeLock on AWSAmazon Web Services
 
Check Point Software Technologies: Secure Your AWS Workloads
 Check Point Software Technologies: Secure Your AWS Workloads Check Point Software Technologies: Secure Your AWS Workloads
Check Point Software Technologies: Secure Your AWS WorkloadsAmazon Web Services
 
Introduction to Cloud Computing with Amazon Web Services and Customer Case Study
Introduction to Cloud Computing with Amazon Web Services and Customer Case StudyIntroduction to Cloud Computing with Amazon Web Services and Customer Case Study
Introduction to Cloud Computing with Amazon Web Services and Customer Case StudyAmazon Web Services
 
CloudPassage Best Practices for Automatic Security Scaling
CloudPassage Best Practices for Automatic Security ScalingCloudPassage Best Practices for Automatic Security Scaling
CloudPassage Best Practices for Automatic Security ScalingAmazon Web Services
 
Cisco ACI for the Microsoft Cloud Platform
Cisco ACI for the Microsoft Cloud PlatformCisco ACI for the Microsoft Cloud Platform
Cisco ACI for the Microsoft Cloud PlatformShashi Kiran
 
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...Amazon Web Services
 
Getting Started with AWS Security
Getting Started with AWS SecurityGetting Started with AWS Security
Getting Started with AWS SecurityAmazon Web Services
 
Microsoft Private Cloud Strategy
Microsoft Private Cloud StrategyMicrosoft Private Cloud Strategy
Microsoft Private Cloud StrategyAmit Gatenyo
 
CSC AWS re:Invent Enterprise DevOps session
CSC AWS re:Invent Enterprise DevOps sessionCSC AWS re:Invent Enterprise DevOps session
CSC AWS re:Invent Enterprise DevOps sessionTom Laszewski
 
An Evolving Security Landscape – Security Patterns in the Cloud
An Evolving Security Landscape – Security Patterns in the CloudAn Evolving Security Landscape – Security Patterns in the Cloud
An Evolving Security Landscape – Security Patterns in the CloudAmazon Web Services
 
Getting Started With AWS Security
Getting Started With AWS SecurityGetting Started With AWS Security
Getting Started With AWS SecurityAmazon Web Services
 
How a National Transportation Software Provider Migrated a Mission-Critical T...
How a National Transportation Software Provider Migrated a Mission-Critical T...How a National Transportation Software Provider Migrated a Mission-Critical T...
How a National Transportation Software Provider Migrated a Mission-Critical T...Amazon Web Services
 
DELL Technologies - The Complete Portfolio in 25 Minutes
DELL Technologies - The Complete Portfolio in 25 MinutesDELL Technologies - The Complete Portfolio in 25 Minutes
DELL Technologies - The Complete Portfolio in 25 MinutesDell Technologies
 
Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)
Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)
Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)Jeremy Gray
 

Similar a Automate the Provisioning of Secure Developer Environments on AWS PPT (20)

(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
(NET208) Enable & Secure Your Business Apps via the Hybrid Cloud on AWS
 
Getting Started with AWS Security
Getting Started with AWS SecurityGetting Started with AWS Security
Getting Started with AWS Security
 
Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Envir...
Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Envir...Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Envir...
Innovate - How AsiaPac is helping Customers to Build a Restricted Cloud Envir...
 
How Symantec Cloud Workload Protection Secures LifeLock on AWS PPT
 How Symantec Cloud Workload Protection Secures LifeLock on AWS PPT How Symantec Cloud Workload Protection Secures LifeLock on AWS PPT
How Symantec Cloud Workload Protection Secures LifeLock on AWS PPT
 
How Symantec Cloud Workload Protection Secures LifeLock on AWS
 How Symantec Cloud Workload Protection Secures LifeLock on AWS How Symantec Cloud Workload Protection Secures LifeLock on AWS
How Symantec Cloud Workload Protection Secures LifeLock on AWS
 
Check Point Software Technologies: Secure Your AWS Workloads
 Check Point Software Technologies: Secure Your AWS Workloads Check Point Software Technologies: Secure Your AWS Workloads
Check Point Software Technologies: Secure Your AWS Workloads
 
Introduction to Cloud Computing with Amazon Web Services and Customer Case Study
Introduction to Cloud Computing with Amazon Web Services and Customer Case StudyIntroduction to Cloud Computing with Amazon Web Services and Customer Case Study
Introduction to Cloud Computing with Amazon Web Services and Customer Case Study
 
CloudPassage Best Practices for Automatic Security Scaling
CloudPassage Best Practices for Automatic Security ScalingCloudPassage Best Practices for Automatic Security Scaling
CloudPassage Best Practices for Automatic Security Scaling
 
Cisco ACI for the Microsoft Cloud Platform
Cisco ACI for the Microsoft Cloud PlatformCisco ACI for the Microsoft Cloud Platform
Cisco ACI for the Microsoft Cloud Platform
 
Cloud Security Alliance's GRC Stack Overview
Cloud Security Alliance's GRC Stack OverviewCloud Security Alliance's GRC Stack Overview
Cloud Security Alliance's GRC Stack Overview
 
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
 
Getting Started with AWS Security
Getting Started with AWS SecurityGetting Started with AWS Security
Getting Started with AWS Security
 
Microsoft Private Cloud Strategy
Microsoft Private Cloud StrategyMicrosoft Private Cloud Strategy
Microsoft Private Cloud Strategy
 
CSC AWS re:Invent Enterprise DevOps session
CSC AWS re:Invent Enterprise DevOps sessionCSC AWS re:Invent Enterprise DevOps session
CSC AWS re:Invent Enterprise DevOps session
 
An Evolving Security Landscape – Security Patterns in the Cloud
An Evolving Security Landscape – Security Patterns in the CloudAn Evolving Security Landscape – Security Patterns in the Cloud
An Evolving Security Landscape – Security Patterns in the Cloud
 
Getting Started With AWS Security
Getting Started With AWS SecurityGetting Started With AWS Security
Getting Started With AWS Security
 
Unlocking the Cloud Operating Model
Unlocking the Cloud Operating ModelUnlocking the Cloud Operating Model
Unlocking the Cloud Operating Model
 
How a National Transportation Software Provider Migrated a Mission-Critical T...
How a National Transportation Software Provider Migrated a Mission-Critical T...How a National Transportation Software Provider Migrated a Mission-Critical T...
How a National Transportation Software Provider Migrated a Mission-Critical T...
 
DELL Technologies - The Complete Portfolio in 25 Minutes
DELL Technologies - The Complete Portfolio in 25 MinutesDELL Technologies - The Complete Portfolio in 25 Minutes
DELL Technologies - The Complete Portfolio in 25 Minutes
 
Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)
Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)
Running Regulated Workloads on Azure PaaS services (DogFoodCon 2018)
 

Más de Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

Más de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Automate the Provisioning of Secure Developer Environments on AWS PPT

  • 1. Nick Matthews, Solutions Architect, AWS Matt Keil, Director of Product Marketing - Public Cloud, Palo Alto Networks John Plishker, Solution Architect, REAN Cloud Automate the Provisioning of Secure Developer Environments on Amazon Web Services © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  • 2. What is Driving AWS Adoption? Urgent Need to Respond to Business Needs for: Increased Agility Flexibility Lower Costs and Transparency More Capabilities Go Global in Minutes Remove Infrastructure Dependencies Remove IT as a “Blocker” to Innovation
  • 3. Compelling Events on the Journey Value Time Discovery and Testing Application- Based Projects Cloud-First / Standardization Business Transformation Build applications to run on the AWS Cloud Dev & Test / Startups Production App Migration “Cloud-First” Standardization / Mass Migration Automation / Business Innovation Projects Current State 1 2 3 4 5
  • 4. Automating logging and monitoring Simplifying resource access Making it easy to encrypt properly Enforcing strong authentication AWS Can Be More Secure than Your Existing Environment In a recent report which found that most customers can be more secure in AWS than their on-premises environment. How?
  • 5. AWS and You Share Responsibility for Security
  • 6. Constantly Monitored  Network access is monitored by AWS security managers daily  AWS CloudTrail lets you monitor and record all API calls  Amazon Inspector automatically assesses applications for vulnerabilities The AWS infrastructure is protected by extensive network and security monitoring systems:
  • 7. Highly Available  44 Availability Zones in 16 regions for multi-synchronous geographic redundancy  Retain control of where your data resides for compliance with regulatory requirements  Mitigate the risk of DDoS attacks using services like Route 53  Dynamically grow to meet unforeseen demand using Auto Scaling The AWS infrastructure footprint helps protect your data from costly downtime:
  • 8. Integrated with Your Existing Resources  Integrate your existing Active Directory  Use dedicated connections as a secure, low-latency extension of your data center  Provide and manage your own encryption keys if you choose AWS enables you to improve your security using many of your existing tools and practices:
  • 9. Key AWS Certifications and Assurance Programs
  • 10. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Palo Alto Networks Matt Keil, Director of Product Marketing - Public Cloud, Palo Alto Networks
  • 11. Applications and Data Are the Target The attack life cycle applies to both physical or virtualized networks in the cloud Infect User Gain Foothold Move Laterally Steal Data Build Botnets Harvest Bitcoin Execute Goal: On the network or in the Cloud
  • 12. What We Do Next-generation firewall on AWS Deployed as an EC2 instance in a VPC  Identify and control apps – not ports  Prevent known and unknown threats  Centrally managed for policy consistency  Automation to keep pace with the cloud Hourly and annual Marketplace subscriptions and bring your own license (BYOL) AWS Security Competency Approved through integration with ELB/ALB and Auto Scaling
  • 13. Shared Responsibility Model: Where We Can Help Where Palo Alto Networks Can Help
  • 14. Complete Application Visibility Scalability & Resiliency Threat Prevention Touchless Deployment Application Segmentation Centralized Management  Reducing the threat exposure with application-based security policies  Preventing known and unknown threats within allowed applications; blocking lateral movement  Controlling file movement within allowed applications Palo Alto Networks VM-Series Features We Complement Security Groups and Web Application Firewalls (WAF) by…
  • 15. Devops and Security Working Together? DevOps  Dynamic environment  Frequent workload changes  Code security is Job 1 Security  Structured, follow change control best practices  Protection of digital assets is Job 1
  • 16. The Solution: Automation Fully documented XML APIXML API Dynamic Policy Updates Bootstrapping
  • 17. Automate Firewall Deployments Attach to Panorama Device Group vm-series-bootstrap-aws-s3- bucket=<bucketname> Amazon S3 VM-Series configuration Security policies Firewall licenses Software updates Dynamic content
  • 18. Bi-Directional Integration Via an XML API Inbound  XML changes to Bootstrap file  Block lists  3rd party policy management tools Outbound  Amazon CloudWatch  ServiceNow  Orchestration tools
  • 20. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. REAN Cloud John Plishker, Solution Architect, REAN Cloud
  • 21. Who We Are Established: 2013 Presence: USA, India Number of Employees: 300+ AWS Certifications: 150+ (Including 15+ Professional Certifications) Industry Focus: Education, Government, Healthcare / Life Sciences, Financial Services, and ISV Corporate Highlights: Migration Competency DevOps Competency Storage Competency Microsoft Workloads Competency Life Sciences Competency Government Competency Education Competency Financial Services Competency Managed Services Partner Market Place Partner
  • 22. REAN Cloud Service Offering REAN Managed Cloud Services REAN Implementation Services REAN Business Consulting Migration Native AWS Application Development DevOps (CI|CD) Implementation Billing as a Service Secure Infrastructure Setup Security & Risk Assessment ROI & Business Case Justification Cloud Adoption Strategy Cloud Architecture CloudSecOpsDataDevOpsBizDevOps Managed Cloud Services DR & Business Continuity Planning (BCP) Governance & Compliance
  • 23. REAN Cloud DevOps Adoption Steps Test-Driven Deployment Automated Deployments Automated Operations Metrics Focused Platform Continuous Security & Compliance
  • 24. REAN Cloud - Accelerators Framework Deploy Verify Manage Executive Dashboards Operational Accelerators CI/CD/CC Automations
  • 25. REAN Deploy - Packaged Cloud Resources Features  Drag and Drop Environment  Infrastructure as Code  Multi-Platform Support  Provisioner Agnostic
  • 26. REAN Deploy - Infrastructure as Code Cloud Provider Resources Application Packages DEV / QA / PROD Environment Blueprint + CD Pipeline Provision/Validate Infrastructure Provision/Validate Applications Functional Regression Testing Security Testing Infrastructure As Code (IaC)
  • 27. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Success Story: Gigamon
  • 28. Background: Who is Gigamon Gigamon is an ISV that offers a Visibility Platform that helps manage, secure, and understand data in motion  Solution levered in federal, financial services, healthcare, and technology service providers  Used Palo Alto Network Firewall in their on-prem development environments  Global offices across 20 different countries
  • 29. Challenge: Efficiently & Securely Providing Developer Environments  Needed to take their solution to support the cloud  Did a migration to the cloud for development and had some challenging results  Virtually unlimited developer access to cloud resources introduced vulnerabilities  Unstructured environments hampered developer productivity  New environments being spun up by developers put operating budgets at risk
  • 30. Challenge: Security Bottlenecks  Deploying third party security into VPCs was introducing bottlenecks  Developers wanted to operate freely, and iterate quickly  Security team concerned about new, unsecured environments
  • 31. Define and develop a simple, fast, and automated solution Provision new Amazon VPCs automatically protected by VM- Series Firewall Develop control VPC to accept new VPN connections from developer VPCs Automate all workflows to simplify the creation of developer environments The Palo Alto Networks and REAN Cloud Solution
  • 32. Securing Developer VPCs  Install the VM-Series into the control VPC  Setup VPNs to VPCs and to other locations  Implement an orchestration tool to extract instance IP addresses  Build bootstrap code out of the network interfaces and IP addresses  Leverage the bootstrap code to spin up new environments with VM-Series and security policies already in place
  • 33. Creating the right foundation….  Setting up a common security infrastructure to support a range of developer needs  Control VPC supports connections for:  Development VPCs  Separate Regions  On-Premise  High Availability
  • 34. Automating the deployment  Provision the Control VPC  Multiple automaton approaches; REAN Deploy, Cloud Formation, Teraform, etc.  Deploy in layers
  • 36. Automating the VM-Series Firewall  Fully managed deployment in any VPC configuration  Bootstrap the VM-Series Firewall Challenge: How do you know about the network interfaces before you deployed the instances
  • 37. Automating the VM-Series Firewall Challenge: How do you know about the network interfaces before you deployed the instances  Deploy networking infrastructure  Use an Orchestrator (i.e. Jenkins)  Pull IP addresses of deployed configuration
  • 38. Automating the VM-Series Firewall  Need to create bootstrap code  Built config manually  Exported configuration  XML output
  • 39. Automating the VM-Series Firewall Snippet of xml configuration: Ruby ERB configuration:
  • 40. Automating the VM-Series Firewall  Stored the Bootstrap in S3 buckets
  • 42.  bootstrap.xml is generated by the orchestrator Automating the VM-Series Firewall
  • 43. Automating the VM-Series Firewall 1. Provision Instances
  • 44. Automating the VM-Series Firewall 1. Provision Instances 2. Instances read from Bootstraps
  • 45. Automating the VM-Series Firewall 1. Provision Instances 2. Instances read from Bootstraps a. HA b. Create VPN 3. Connected to Gigamon Office
  • 46. Automating the VM-Series Firewall  Use XML API to establish HA  Floating ENI  Elastic IP
  • 47. Automating the VM-Series Firewall  Ready for Developer to deploy  Automated the deployment of a series of configurations
  • 48. Automating the VM-Series Firewall  5-10 minute deployment time  Developer up and running with access to VPC from on-prem network  Automated teardown as- well
  • 49. Automating the VM-Series Firewall  Ready for Developer to deploy  Automated the deployment of a series of configurations
  • 50. Automating the VM-Series Firewall  Ready for Developer to deploy  Automated the deployment of a series of configurations
  • 51. Automating the VM-Series Firewall  Included support for VPCs in multiple Regions
  • 52. Automating the VM-Series Firewall  Included support for VPCs in multiple Regions
  • 53. Results and Benefits Deploy one or more already secured developer VPCs with the push of a button New VPCs are connected to central VPC via IPsec to maintain compliance Unsecured developer environments are no longer a concern Successfully extended their portfolio to cloud technologies while maintaining efficiency and security
  • 54. Next Steps Available in AWS Marketplace  Two bundles available as annual or hourly subscriptions Bring your own license (BYOL)  Pick and choose licenses, subscriptions and support to best suite our needs  Supported in AWS Regions and AWS GovCloud (US) Palo Alto Networks REAN Cloud Consulting Services  Cloud Architecture Designs  Security Assessments Implementation Services  Build secure Foundation (Landing Zone)  Blueprints for various VM Series deployments
  • 55. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Q & A Nick Matthews, Solutions Architect, AWS Matt Keil, Director of Product Marketing - Public Cloud, Palo Alto Networks John Plishker, Solution Architect, REAN Cloud