SlideShare una empresa de Scribd logo
1 de 28
Descargar para leer sin conexión
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Immersion Day
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Schedule
Time Agenda Item
9:00 AM Introduction & Opening Remarks
9:15 AM AWS Fundamentals
10:00 AM Break
10:15 AM AWS Core Services Overview
11:45 PM Lunch
12:30 PM Cybersecurity: A Driving Force Behind Cloud Adoption
2:00 PM Break
2:15 PM VMware Cloud on AWS
3:00 PM High Performance Computing in AWS
3:45 PM Closing Remarks
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
What is Cloud Computing?
The on-demand delivery of IT resources over
public or private networks with zero up-front
costs, no long-term contracts, and pay-as-you-go
pricing
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
No Up Front Expense
Pay for what you Use
Improve Agility
Scale Up and
Down
Self-Service
Infrastructure
AWS Cloud
Equipment
Resources and
Administration
Contracts Cost
Traditional
Infrastructure
Millions of Active Customers
2012 2013 2015 Today2014 20162008 2009 2010 2011
Pace of Innovation
5 1 6
2 4 4 8 6 1 8 2
1 5 9
2 8 0
7 2 2
1 , 0 1 7
LAUNCHES
2 0 0 8 2 0 0 9 2 0 1 0 2 0 1 1 2 0 1 2 2 0 1 3 2 0 1 4 2 0 1 5 2 0 1 6
1 , 4 0 0 +
2 0 1 7
New capabilities daily
Lower
Cost
Higher
Reliability
Scale
Better
Capacity
Virtuous cycle
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Global Infrastructure
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Global Infrastructure
• 22 Regions with 69 Availability Zones
• 3 Regions coming soon: Cape Town, Milan
and Jakarta
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
180 CloudFront PoPs
• 169 Edge Locations
• 11 Regional Edge Caches
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Multiple Edge Locations
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
89 Direct Connect
Locations
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Global Network
• Redundant 100 GbE network
• Private network capacity between
all AWS Region, except China
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Regions are comprised of multiple AZs for high availability, high scalability, and
high fault tolerance. Applications and data are replicated in real time and consistent in
the different AZs
AWS Region Design
AWS Availability Zone (AZ)
A Region is a physical location in the
world where we have multiple Availability
Zones.
Availability Zones consist of one or more discrete data
centers, each with redundant power, networking, and
connectivity, housed in separate facilities.
AZ
AZ
AZ AZ
Transit
Transit
AWS Region
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Architected for Government Security Requirements
And many more: https://aws.amazon.com/compliance/
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
DoD Information Impact Levels
SRG v1r2
Impact
Level
Maximum
Data Type
Information Characterization
2
Non-Controlled
Unclassified
Information
Unclassified information approved for public release
Unclassified, not designated as controlled unclassified information (CUI) or critical mission data,
but requires some minimal level of access control
4
Controlled
Unclassified
Information
Requires protection from unauthorized disclosure as established by Executive Order 13556 (Nov
2010); Education, Training, SSN, Recruiting (if medical is not included), Credit card information for
individuals (i.e., PX or MWR events)
PII, PHI, SSN, Credit card information for individuals, Export Control, FOUO, Law Enforcement
Sensitive, Email
5
Controlled
Unclassified
Information +
NSS
National Security Systems and other information requiring a higher level of protection as deemed
necessary by the information owner, public law, or other government regulations
6 Classified up to
SECRET
Pursuant to EO 12958 as amended by EO 13292; classified national security information or
pursuant to the Atomic Energy Act of 1954, as amended to be Restricted Data (RD)
DoD Cloud Computing Security Requirements Guide (SRG): http://iase.disa.mil/cloud_security/Pages/index.aspx
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
US AWS Regions
# Commercial Region and Number of Availability Zones
3
3
3
6
3
3
3
3
# GovCloud Region and Number of Availability Zones
# Classified Region and Number of Availability Zones
HIGH MOD
DoD
IL
2/4/5
MOD
DoD
IL
2
MOD
DoD
IL
2
MOD
DoD
IL
2
MOD
DoD
IL
2
ICD
503
TS/SCIICD
503
SECRET
DoD
IL 6
HIGH MOD
DoD
IL
2/4/5
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Services in
Scope
✓ This service is currently in scope and
is reflected in current reports
https://aws.amazon.com/com
pliance/services-in-scope/
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Shared Responsibility Model
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Inheritance
Personnel
Incident Response
Boundary Protection
Identity & Access Control
Disaster Recovery
Configuration Management
High Availability Architecture
System Mgmt. & Monitoring
Log Management & Monitoring
Compute & Storage
Networking
Virtualization
Data Center
Specific
Mission
Owner
Controls
Controls fully
inherited
Mission
Owner
on Prem
Mission
Owner
Controls
Hybrid
Controls
Mission
Owner
on AWS
+
Mission
Owner
Mission
Owner
Controls
ATO
Package
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
DoD Secure Cloud Computing Architecture
• Secure Cloud Computing Architecture Functional
Requirements Document (SCCA FRD)
• Released March 9th 2017
• Provides implementation flexibility
• Freedom to architect and manage
as a shared services enclave
The SCCA provides a standard approach for boundary and application
level security for impact level 4 and 5 data hosted in commercial cloud
environments.
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
SCCA Architecture Approach in AWS
GovCloud Region
App Subnet
Availability Zone A
Database Subnet
DMZ Subnet
Web
Server
App
Server
DB
Server
primary
Availability Zone B
Database Subnet
DB
Server
secondary
Web
Server
App
Server
App Subnet
DMZ Subnet
Web
Server
auto scaling group
auto scaling group
security groupsecurity group
synchronous
replication
CND
Direct
Connect
Co-
Location
CAP
CND
DoDIN
IAP
VGW
Mission Owner Virtual Private Cloud (VPC)
Virtual Datacenter Security Stack (VDSS)
Availability Zone BAvailability Zone A
Network Firewall Services
Network Intrusion Detection/Prevention Services
Full Packet Capture Services
Web Application Firewall Services
Availability Zone B
ACAS / Vulnerability Scanning Services
HBSS / Endpoint Protection Services
AD / DNS / SSO / OCSP / DCHP Services
Other Shared Services
Availability Zone A
VGW
VGW
Virtual Datacenter Management Stack (VDMS)Inernet
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Leveraged Services Supporting Multiple Mission Owners
GovCloud Region
App
Subnet
AZB
Database
Subnet
DMZ
Subnet
Web
Server
App
Server
DB
Server
primary
CND
Direct
Connect
Co-
Location
CAP
CND
DoDIN
IAP
VGW
Mission Owner Virtual Private Cloud (VPC)
Virtual Datacenter Security Stack (VDSS)
Availability Zone BAvailability Zone A
Network Firewall Services
Network Intrusion Detection/Prevention Services
Full Packet Capture Services
Web Application Firewall Services
Availability Zone B
ACAS / Vulnerability Scanning Services
HBSS / Endpoint Protection Services
AD / DNS / SSO / OCSP / DCHP Services
Other Shared Services
Availability Zone A
VGW
VGW
Virtual Datacenter Management Stack (VDMS)Inernet
App
Subnet
AZA
Database
Subnet
DMZ
Subnet
Web
Server
App
Server
DB
Server
primary
App
Subnet
AZB
Database
Subnet
DMZ
Subnet
Web
Server
App
Server
DB
Server
primary
App
Subnet
AZA
Database
Subnet
DMZ
Subnet
Web
Server
App
Server
DB
Server
primary
Mission Owner A – Application Stack / VPC
Mission Owner B – Application Stack / VPC
VGW
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
A Full Range of Capabilities for Mission Owners
Key Management
Service
Manage creation and
control of encryption keys
CloudHSM
Hardware-based key
storage
Server-Side
Encryption
Flexible data encryption
options
Encryption
IAM
Manage user access and
encryption keys
SAML Federation
SAML 2.0 support to
allow on-prem identities
Directory Service
Host and manage
Microsoft Active Directory
Organizations
Manage settings for
multiple accounts
Identity & Access Mgmt
Virtual Private Cloud
Network-isolated cloud
resources
Web Application
Firewall
Filter Malicious Web
Traffic
AWS Shield
DDoS protection
Certificate Manager
Provision, manage, and
deploy SSL/TSL
certificates
Networking
VPC Flow Logs
Comprehensive netflow
data with click of button
AWS Service Catalog
Create and use
standardized products
AWS Config
Track resource inventory
and changes
CloudTrail
Track user activity and
API usage
CloudWatch
Monitor resources and
applications
GuardDuty
Intrusion detection and
analysis
Trusted Advisor
Warning and reports on
proper configuration
Visibility and Control
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
n
Identity & access
management
Detective
controls
Infrastructure
protection
Incident
response
Data
protection
AWS Security Solutions
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS Breadth and Depth
CORE SERVICES
Integrated Networking
Rules Engine
Device Shadows
Device SDKs
Device Gateway
Registry
Local Compute
Custom Model
Training & Hosting
Conversational Chatbots
Virtual Desktops
App Streaming
Schema Conversion
Image & Scene
Recognition
Sharing &
Collaboration
Exabyte-Scale
Data Migration
Text to Speech
Corporate Email Application Migration
Database Migration
Regions
Availability Zones
Points of Presence
Data Warehousing
Business Intelligence
Elasticsearch
Hadoop/Spark
Data Pipelines
Streaming Data
Collection
ETL
Streaming Data
Analysis
Interactive SQL
Queries
Queuing & Notifications
Workflow
Email
Transcoding
Deep Learning
(Apache MXNet,
TensorFlow, & others)
Server MigrationCommunications
MARKETPLACE
Business Apps Business Intelligence DevOps Tools Security Networking StorageDatabases
API Gateway
Single Integrated
Console
Identity
Sync
Mobile Analytics
Mobile App Testing
Targeted Push
Notifications
One-clickApp
Deployment
DevOps Resource
Management
Application Lifecycle
Management
Containers
Triggers
Resource Templates
Build & Test
Analyze & Debug
Identity
Management
Key Management
& Storage
Monitoring &
Logs
Configuration
Compliance
Web Application
Firewall
Assessment
& Reporting
Resource & Usage
Auditing
Access Control
Account
Grouping
DDOS
Protection
TECHNICAL & BUSINESS SUPPORT
Support
Professional
Services
Optimization
Guidance
Partner
Ecosystem
Training &
Certification
Solutions Management Account Management
Security & Billing
Reports
Personalized
Dashboard
Monitoring
Manage
Resources
Data Integration
Integrated Identity &
Access
Integrated Resource &
Deployment Management
Integrated Devices
& Edge Systems
Resource
Templates
Configuration
Tracking
Server
Management
Service
Catalogue
Search
MIGRATIONHYBRID ARCHITECTUREENTERPRISE APPSMACHINE LEARNINGIoTMOBILE SERVICESDEV OPSANALYTICS
APP SERVICES
INFRASTRUCTURE SECURITY & COMPLIANCE MANAGEMENT TOOLS
Compute
VMs, Auto-scaling, Load
Balancing, Containers,
Virtual Private Servers,
Batch Computing, Cloud
Functions, Elastic GPUs,
Edge Computing
Storage
Object, Blocks, File, Archivals,
Import/Export, Exabyte-scale
data transfer
CDN
Databases
Relational, NoSQL,
Caching, Migration,
PostgreSQL compatible
Networking
VPC, DX, DNS
Facial Recognition &
Analysis
Facial Search
Patching
Contact Center
© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Questions?

Más contenido relacionado

La actualidad más candente

La actualidad más candente (20)

VMware Cloud on AWS - Canberra Lunch & Learn
VMware Cloud on AWS - Canberra Lunch & LearnVMware Cloud on AWS - Canberra Lunch & Learn
VMware Cloud on AWS - Canberra Lunch & Learn
 
High Performance Computing in AWS, Immersion Day Huntsville 2019
High Performance Computing in AWS, Immersion Day Huntsville 2019High Performance Computing in AWS, Immersion Day Huntsville 2019
High Performance Computing in AWS, Immersion Day Huntsville 2019
 
AWS AutoScalling- Tech Talks Maio 2019
AWS AutoScalling- Tech Talks Maio 2019AWS AutoScalling- Tech Talks Maio 2019
AWS AutoScalling- Tech Talks Maio 2019
 
Costruire Architetture Ibride con AWS
Costruire Architetture Ibride con AWSCostruire Architetture Ibride con AWS
Costruire Architetture Ibride con AWS
 
Hybrid Cloud Architectures on VMware Cloud on AWS.pdf
Hybrid Cloud Architectures on VMware Cloud on AWS.pdfHybrid Cloud Architectures on VMware Cloud on AWS.pdf
Hybrid Cloud Architectures on VMware Cloud on AWS.pdf
 
VMware Cloud on AWS Cloud Migration Deep Dive
 VMware Cloud on AWS Cloud Migration Deep Dive VMware Cloud on AWS Cloud Migration Deep Dive
VMware Cloud on AWS Cloud Migration Deep Dive
 
VMWare Cloud on AWS | Floor 28
VMWare Cloud on AWS | Floor 28VMWare Cloud on AWS | Floor 28
VMWare Cloud on AWS | Floor 28
 
Presidio: Hybrid Cloud Optimization: A How-To Guide from VMware & Presidio
Presidio: Hybrid Cloud Optimization: A How-To Guide from VMware & PresidioPresidio: Hybrid Cloud Optimization: A How-To Guide from VMware & Presidio
Presidio: Hybrid Cloud Optimization: A How-To Guide from VMware & Presidio
 
Hybrid Cloud on AWS - Introduction and Art of the Possible
Hybrid Cloud on AWS - Introduction and Art of the PossibleHybrid Cloud on AWS - Introduction and Art of the Possible
Hybrid Cloud on AWS - Introduction and Art of the Possible
 
Accelerating your Cloud Migration with VMware Cloud on AWS
Accelerating your Cloud Migration with VMware Cloud on AWSAccelerating your Cloud Migration with VMware Cloud on AWS
Accelerating your Cloud Migration with VMware Cloud on AWS
 
Lambda Function Security
Lambda Function SecurityLambda Function Security
Lambda Function Security
 
打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載打破時空藩籬,輕鬆存取您的雲端工作負載
打破時空藩籬,輕鬆存取您的雲端工作負載
 
VMware Cloud on AWS - AWS Learning Series
VMware Cloud on AWS - AWS Learning SeriesVMware Cloud on AWS - AWS Learning Series
VMware Cloud on AWS - AWS Learning Series
 
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
La tua organizzazione è pronta per adottare una strategia di cloud ibrido?
 
AWS networking fundamentals - SVC303 - Santa Clara AWS Summit
AWS networking fundamentals - SVC303 - Santa Clara AWS SummitAWS networking fundamentals - SVC303 - Santa Clara AWS Summit
AWS networking fundamentals - SVC303 - Santa Clara AWS Summit
 
Bringing Cloud to the Edge - AWS Summit Sydney
Bringing Cloud to the Edge - AWS Summit SydneyBringing Cloud to the Edge - AWS Summit Sydney
Bringing Cloud to the Edge - AWS Summit Sydney
 
AWS Security Deep Dive
AWS Security Deep DiveAWS Security Deep Dive
AWS Security Deep Dive
 
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS SummitAWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
AWS PrivateLink: Fundamentals - SRV211 - Anaheim AWS Summit
 
ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre...
 ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre... ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre...
ENT307 Move your Desktops and Apps to AWS with Amazon WorkSpaces and AppStre...
 
AWS App Mesh (Service Mesh Magic)- AWS Container Day 2019 Barcelona
AWS App Mesh (Service Mesh Magic)- AWS Container Day 2019 BarcelonaAWS App Mesh (Service Mesh Magic)- AWS Container Day 2019 Barcelona
AWS App Mesh (Service Mesh Magic)- AWS Container Day 2019 Barcelona
 

Similar a AWS Fundamentals for DoD, Immersion Day Huntsville 2019

Learn how AWS customers are implementing robust security posture for their A...
 Learn how AWS customers are implementing robust security posture for their A... Learn how AWS customers are implementing robust security posture for their A...
Learn how AWS customers are implementing robust security posture for their A...
Amazon Web Services
 

Similar a AWS Fundamentals for DoD, Immersion Day Huntsville 2019 (20)

Cybersecurity: A Drive Force Behind Cloud Adoption
Cybersecurity: A Drive Force Behind Cloud AdoptionCybersecurity: A Drive Force Behind Cloud Adoption
Cybersecurity: A Drive Force Behind Cloud Adoption
 
Managing Security on AWS
Managing Security on AWSManaging Security on AWS
Managing Security on AWS
 
Innovate - Cybersecurity: A Drive Force Behind Cloud Adoption
Innovate - Cybersecurity: A Drive Force Behind Cloud AdoptionInnovate - Cybersecurity: A Drive Force Behind Cloud Adoption
Innovate - Cybersecurity: A Drive Force Behind Cloud Adoption
 
How to Architect and Bring to Market SaaS on AWS GovCloud (US)
How to Architect and Bring to Market SaaS on AWS GovCloud (US)How to Architect and Bring to Market SaaS on AWS GovCloud (US)
How to Architect and Bring to Market SaaS on AWS GovCloud (US)
 
How to Leverage Traffic Analysis to Navigate through Cloudy Skies - DEM03-R ...
 How to Leverage Traffic Analysis to Navigate through Cloudy Skies - DEM03-R ... How to Leverage Traffic Analysis to Navigate through Cloudy Skies - DEM03-R ...
How to Leverage Traffic Analysis to Navigate through Cloudy Skies - DEM03-R ...
 
Delivering applications securely with AWS - SVC303 - Chicago AWS Summit
Delivering applications securely with AWS - SVC303 - Chicago AWS SummitDelivering applications securely with AWS - SVC303 - Chicago AWS Summit
Delivering applications securely with AWS - SVC303 - Chicago AWS Summit
 
AWS_Security_Essentials
AWS_Security_EssentialsAWS_Security_Essentials
AWS_Security_Essentials
 
DDoS attack detection at scale - SDD408 - AWS re:Inforce 2019
DDoS attack detection at scale - SDD408 - AWS re:Inforce 2019 DDoS attack detection at scale - SDD408 - AWS re:Inforce 2019
DDoS attack detection at scale - SDD408 - AWS re:Inforce 2019
 
Strengthen Your Organizations Security and Privacy.pdf
Strengthen Your Organizations Security and Privacy.pdfStrengthen Your Organizations Security and Privacy.pdf
Strengthen Your Organizations Security and Privacy.pdf
 
Learn how AWS customers are implementing robust security posture for their A...
 Learn how AWS customers are implementing robust security posture for their A... Learn how AWS customers are implementing robust security posture for their A...
Learn how AWS customers are implementing robust security posture for their A...
 
Hybrid Solutions at the Edge – Go Global Faster, Efficiently, and More Secure...
Hybrid Solutions at the Edge – Go Global Faster, Efficiently, and More Secure...Hybrid Solutions at the Edge – Go Global Faster, Efficiently, and More Secure...
Hybrid Solutions at the Edge – Go Global Faster, Efficiently, and More Secure...
 
Secure & Automate AWS Deployments with Next-Generation on Security
Secure & Automate AWS Deployments with Next-Generation on SecuritySecure & Automate AWS Deployments with Next-Generation on Security
Secure & Automate AWS Deployments with Next-Generation on Security
 
Failure is not an Option - Designing Highly Resilient AWS Systems
Failure is not an Option - Designing Highly Resilient AWS SystemsFailure is not an Option - Designing Highly Resilient AWS Systems
Failure is not an Option - Designing Highly Resilient AWS Systems
 
NIST Compliance, AWS Federal Pop-Up Loft
NIST Compliance, AWS Federal Pop-Up LoftNIST Compliance, AWS Federal Pop-Up Loft
NIST Compliance, AWS Federal Pop-Up Loft
 
Innovate - Become Migration Ready: Accelerate and Optimise your Cloud Adoptio...
Innovate - Become Migration Ready: Accelerate and Optimise your Cloud Adoptio...Innovate - Become Migration Ready: Accelerate and Optimise your Cloud Adoptio...
Innovate - Become Migration Ready: Accelerate and Optimise your Cloud Adoptio...
 
Scale - Failure is not an Option: Designing Highly Resilient AWS Systems
Scale - Failure is not an Option: Designing Highly Resilient AWS SystemsScale - Failure is not an Option: Designing Highly Resilient AWS Systems
Scale - Failure is not an Option: Designing Highly Resilient AWS Systems
 
AWS Initiate Day Dublin 2019 – Security and Compliance in your VPC
AWS Initiate Day Dublin 2019 – Security and Compliance in your VPCAWS Initiate Day Dublin 2019 – Security and Compliance in your VPC
AWS Initiate Day Dublin 2019 – Security and Compliance in your VPC
 
AWS Initiate Day Manchester 2019 – AWS Security Compliance in your VPC
AWS Initiate Day Manchester 2019 – AWS Security Compliance in your VPCAWS Initiate Day Manchester 2019 – AWS Security Compliance in your VPC
AWS Initiate Day Manchester 2019 – AWS Security Compliance in your VPC
 
How FINRA achieves DevOps agility while securing its AWS environments - GRC33...
How FINRA achieves DevOps agility while securing its AWS environments - GRC33...How FINRA achieves DevOps agility while securing its AWS environments - GRC33...
How FINRA achieves DevOps agility while securing its AWS environments - GRC33...
 
Introduction to the AWS Cloud - AWSome Day 2019 - Charlotte
Introduction to the AWS Cloud - AWSome Day 2019 - CharlotteIntroduction to the AWS Cloud - AWSome Day 2019 - Charlotte
Introduction to the AWS Cloud - AWSome Day 2019 - Charlotte
 

Más de Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

Más de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

AWS Fundamentals for DoD, Immersion Day Huntsville 2019

  • 1. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Immersion Day
  • 2. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Schedule Time Agenda Item 9:00 AM Introduction & Opening Remarks 9:15 AM AWS Fundamentals 10:00 AM Break 10:15 AM AWS Core Services Overview 11:45 PM Lunch 12:30 PM Cybersecurity: A Driving Force Behind Cloud Adoption 2:00 PM Break 2:15 PM VMware Cloud on AWS 3:00 PM High Performance Computing in AWS 3:45 PM Closing Remarks
  • 3. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  • 4. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What is Cloud Computing? The on-demand delivery of IT resources over public or private networks with zero up-front costs, no long-term contracts, and pay-as-you-go pricing
  • 5. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. No Up Front Expense Pay for what you Use Improve Agility Scale Up and Down Self-Service Infrastructure AWS Cloud Equipment Resources and Administration Contracts Cost Traditional Infrastructure
  • 6. Millions of Active Customers 2012 2013 2015 Today2014 20162008 2009 2010 2011
  • 7. Pace of Innovation 5 1 6 2 4 4 8 6 1 8 2 1 5 9 2 8 0 7 2 2 1 , 0 1 7 LAUNCHES 2 0 0 8 2 0 0 9 2 0 1 0 2 0 1 1 2 0 1 2 2 0 1 3 2 0 1 4 2 0 1 5 2 0 1 6 1 , 4 0 0 + 2 0 1 7 New capabilities daily
  • 9. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  • 10. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Global Infrastructure
  • 11. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Global Infrastructure • 22 Regions with 69 Availability Zones • 3 Regions coming soon: Cape Town, Milan and Jakarta © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  • 12. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 180 CloudFront PoPs • 169 Edge Locations • 11 Regional Edge Caches © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Multiple Edge Locations
  • 13. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 89 Direct Connect Locations © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  • 14. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Global Network • Redundant 100 GbE network • Private network capacity between all AWS Region, except China © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
  • 15. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Regions are comprised of multiple AZs for high availability, high scalability, and high fault tolerance. Applications and data are replicated in real time and consistent in the different AZs AWS Region Design AWS Availability Zone (AZ) A Region is a physical location in the world where we have multiple Availability Zones. Availability Zones consist of one or more discrete data centers, each with redundant power, networking, and connectivity, housed in separate facilities. AZ AZ AZ AZ Transit Transit AWS Region
  • 16. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Architected for Government Security Requirements And many more: https://aws.amazon.com/compliance/
  • 17. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. DoD Information Impact Levels SRG v1r2 Impact Level Maximum Data Type Information Characterization 2 Non-Controlled Unclassified Information Unclassified information approved for public release Unclassified, not designated as controlled unclassified information (CUI) or critical mission data, but requires some minimal level of access control 4 Controlled Unclassified Information Requires protection from unauthorized disclosure as established by Executive Order 13556 (Nov 2010); Education, Training, SSN, Recruiting (if medical is not included), Credit card information for individuals (i.e., PX or MWR events) PII, PHI, SSN, Credit card information for individuals, Export Control, FOUO, Law Enforcement Sensitive, Email 5 Controlled Unclassified Information + NSS National Security Systems and other information requiring a higher level of protection as deemed necessary by the information owner, public law, or other government regulations 6 Classified up to SECRET Pursuant to EO 12958 as amended by EO 13292; classified national security information or pursuant to the Atomic Energy Act of 1954, as amended to be Restricted Data (RD) DoD Cloud Computing Security Requirements Guide (SRG): http://iase.disa.mil/cloud_security/Pages/index.aspx
  • 18. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. US AWS Regions # Commercial Region and Number of Availability Zones 3 3 3 6 3 3 3 3 # GovCloud Region and Number of Availability Zones # Classified Region and Number of Availability Zones HIGH MOD DoD IL 2/4/5 MOD DoD IL 2 MOD DoD IL 2 MOD DoD IL 2 MOD DoD IL 2 ICD 503 TS/SCIICD 503 SECRET DoD IL 6 HIGH MOD DoD IL 2/4/5
  • 19. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Services in Scope ✓ This service is currently in scope and is reflected in current reports https://aws.amazon.com/com pliance/services-in-scope/
  • 20. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Shared Responsibility Model
  • 21. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Inheritance Personnel Incident Response Boundary Protection Identity & Access Control Disaster Recovery Configuration Management High Availability Architecture System Mgmt. & Monitoring Log Management & Monitoring Compute & Storage Networking Virtualization Data Center Specific Mission Owner Controls Controls fully inherited Mission Owner on Prem Mission Owner Controls Hybrid Controls Mission Owner on AWS + Mission Owner Mission Owner Controls ATO Package
  • 22. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. DoD Secure Cloud Computing Architecture • Secure Cloud Computing Architecture Functional Requirements Document (SCCA FRD) • Released March 9th 2017 • Provides implementation flexibility • Freedom to architect and manage as a shared services enclave The SCCA provides a standard approach for boundary and application level security for impact level 4 and 5 data hosted in commercial cloud environments.
  • 23. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. SCCA Architecture Approach in AWS GovCloud Region App Subnet Availability Zone A Database Subnet DMZ Subnet Web Server App Server DB Server primary Availability Zone B Database Subnet DB Server secondary Web Server App Server App Subnet DMZ Subnet Web Server auto scaling group auto scaling group security groupsecurity group synchronous replication CND Direct Connect Co- Location CAP CND DoDIN IAP VGW Mission Owner Virtual Private Cloud (VPC) Virtual Datacenter Security Stack (VDSS) Availability Zone BAvailability Zone A Network Firewall Services Network Intrusion Detection/Prevention Services Full Packet Capture Services Web Application Firewall Services Availability Zone B ACAS / Vulnerability Scanning Services HBSS / Endpoint Protection Services AD / DNS / SSO / OCSP / DCHP Services Other Shared Services Availability Zone A VGW VGW Virtual Datacenter Management Stack (VDMS)Inernet
  • 24. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Leveraged Services Supporting Multiple Mission Owners GovCloud Region App Subnet AZB Database Subnet DMZ Subnet Web Server App Server DB Server primary CND Direct Connect Co- Location CAP CND DoDIN IAP VGW Mission Owner Virtual Private Cloud (VPC) Virtual Datacenter Security Stack (VDSS) Availability Zone BAvailability Zone A Network Firewall Services Network Intrusion Detection/Prevention Services Full Packet Capture Services Web Application Firewall Services Availability Zone B ACAS / Vulnerability Scanning Services HBSS / Endpoint Protection Services AD / DNS / SSO / OCSP / DCHP Services Other Shared Services Availability Zone A VGW VGW Virtual Datacenter Management Stack (VDMS)Inernet App Subnet AZA Database Subnet DMZ Subnet Web Server App Server DB Server primary App Subnet AZB Database Subnet DMZ Subnet Web Server App Server DB Server primary App Subnet AZA Database Subnet DMZ Subnet Web Server App Server DB Server primary Mission Owner A – Application Stack / VPC Mission Owner B – Application Stack / VPC VGW
  • 25. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. A Full Range of Capabilities for Mission Owners Key Management Service Manage creation and control of encryption keys CloudHSM Hardware-based key storage Server-Side Encryption Flexible data encryption options Encryption IAM Manage user access and encryption keys SAML Federation SAML 2.0 support to allow on-prem identities Directory Service Host and manage Microsoft Active Directory Organizations Manage settings for multiple accounts Identity & Access Mgmt Virtual Private Cloud Network-isolated cloud resources Web Application Firewall Filter Malicious Web Traffic AWS Shield DDoS protection Certificate Manager Provision, manage, and deploy SSL/TSL certificates Networking VPC Flow Logs Comprehensive netflow data with click of button AWS Service Catalog Create and use standardized products AWS Config Track resource inventory and changes CloudTrail Track user activity and API usage CloudWatch Monitor resources and applications GuardDuty Intrusion detection and analysis Trusted Advisor Warning and reports on proper configuration Visibility and Control
  • 26. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. n Identity & access management Detective controls Infrastructure protection Incident response Data protection AWS Security Solutions
  • 27. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Breadth and Depth CORE SERVICES Integrated Networking Rules Engine Device Shadows Device SDKs Device Gateway Registry Local Compute Custom Model Training & Hosting Conversational Chatbots Virtual Desktops App Streaming Schema Conversion Image & Scene Recognition Sharing & Collaboration Exabyte-Scale Data Migration Text to Speech Corporate Email Application Migration Database Migration Regions Availability Zones Points of Presence Data Warehousing Business Intelligence Elasticsearch Hadoop/Spark Data Pipelines Streaming Data Collection ETL Streaming Data Analysis Interactive SQL Queries Queuing & Notifications Workflow Email Transcoding Deep Learning (Apache MXNet, TensorFlow, & others) Server MigrationCommunications MARKETPLACE Business Apps Business Intelligence DevOps Tools Security Networking StorageDatabases API Gateway Single Integrated Console Identity Sync Mobile Analytics Mobile App Testing Targeted Push Notifications One-clickApp Deployment DevOps Resource Management Application Lifecycle Management Containers Triggers Resource Templates Build & Test Analyze & Debug Identity Management Key Management & Storage Monitoring & Logs Configuration Compliance Web Application Firewall Assessment & Reporting Resource & Usage Auditing Access Control Account Grouping DDOS Protection TECHNICAL & BUSINESS SUPPORT Support Professional Services Optimization Guidance Partner Ecosystem Training & Certification Solutions Management Account Management Security & Billing Reports Personalized Dashboard Monitoring Manage Resources Data Integration Integrated Identity & Access Integrated Resource & Deployment Management Integrated Devices & Edge Systems Resource Templates Configuration Tracking Server Management Service Catalogue Search MIGRATIONHYBRID ARCHITECTUREENTERPRISE APPSMACHINE LEARNINGIoTMOBILE SERVICESDEV OPSANALYTICS APP SERVICES INFRASTRUCTURE SECURITY & COMPLIANCE MANAGEMENT TOOLS Compute VMs, Auto-scaling, Load Balancing, Containers, Virtual Private Servers, Batch Computing, Cloud Functions, Elastic GPUs, Edge Computing Storage Object, Blocks, File, Archivals, Import/Export, Exabyte-scale data transfer CDN Databases Relational, NoSQL, Caching, Migration, PostgreSQL compatible Networking VPC, DX, DNS Facial Recognition & Analysis Facial Search Patching Contact Center
  • 28. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved.© 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Questions?