SlideShare a Scribd company logo
1 of 18
Download to read offline
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Disrupting Traditional Payment
Systems Architecture with AWS
Anthony Galleno
Solution Architect
AWS Financial Services
F S V 3 2 0
Andrew Shortt
Solution Delivery Manager
AWS Financial Services
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Agenda
Rapid Evolution In Payments
PCI DSS Compliance
PCI Architecture on AWS
Serverless Architectures on AWS
Q & A
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
The global payments landscape is shifting
Shift to digital
accelerated by
growing smartphone
adoption and new
channels for non-cash
transactions
New non-banks and
Payment Service
Providers (PSPs) offering
payment services and
technology, enabling
transactions outside
traditional channels
Changing customer
demands including
frictionless payments
experience, one-touch
options, and instant
settlement
Progressive changes
among regulators
promoting transparency,
security, innovation,
interoperability, and
competition
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Consumer demands are driving innovation
Retail and corporate payments customers want faster, easier, digital payments.
Now: Payments as a differentiator
• Firms investing in payments technologies and
processing infrastructure
• Faster, seamless payment experiences and
better use of customer data
• Collaborative payment ecosystem focused on
customer demands
• New payments channels replace cash in small
transactions and increase firm’s revenue
Before: Payments as a commodity
• Small transactions dominated by cash
• Check payments still common
• Most digital payments running on legacy
platforms
• Card payments processing handled by
credit card networks
• Payments considered low profit product by
banks and Payment Service Providers
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customers Innovating Payments with AWS
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
PCI DSS Compliance
“If you accept or process payment cards, the PCI Data Security Standards apply to you.”
In order to connect to the major
card networks, the system you
build must comply with PCI DSS
guidelines and be scoped, audited,
and reviewed by an on-site PCI
Qualified Security Assessor.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
PCI DSS Compliance on AWS
Scale Compute to match
demand
Advanced data storage
and analytics
Seamless customer
experience
Model Risk, Credit and lending
decisions
Build, test, launch new
features
Serverless/Infrastructure
as code
Security and compliance
Connect payment apps
More than 60 AWS services are PCI-DSS compliant. With pay as you go pricing and global
availability customers can leverage these services to deliver fast, frictionless payment systems.
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
PCI DSS Guidelines on AWS
Build Maintain a Secure Network
and Systems
1. Install and Maintain a Firewall
Configuration to Protect Cardholder Data
2. Do Not Use Vendor-Supplied Defaults for
System Passwords and Other Security
Parameters
VPN Gateway
Protect Cardholder Data
3. Protect Stored Cardholder Data
4. Encrypt transmission of cardholder data
across open, public networks
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
PCI DSS Compliance on AWS
Maintain a Vulnerability
Management Program
5. Protect all systems against malware and
regularly update anti-virus software
6. Develop and maintain secure systems
and applications
Implement Strong Access Controls
7. Restrict Access to Cardholder Data by
Need to know
8. Identify and Authenticate Access to
System Components
9. Restrict Physical Access to Cardholder
Data
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
PCI DSS Compliance on AWS
Regularly Monitor and Test
Networks
10. Track and monitor all access to network
resources and cardholder data
11. Regularly test security systems and
processes Flow logs
Maintain an Information Security
Policy
12. Maintain a policy that addresses
information security for all personnel
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
PCI quick-start on AWS
Availability zone
Public Subnet
VPC
Internet
Private Subnet Private Subnet
RDS MySQL
DB instance
NAT gateway
Availability zone
Public Subnet
Private SubnetPrivate Subnet
Auto Scaling group
Instances Auto Scaling InstancesAuto Scaling NAT gateway
RDS MySQL
DB instance
Auto Scaling group
Instances Auto Scaling InstancesAuto Scaling
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Serverless API Development
POST /v1/pay
GET /v1/preferences/001
paymentbackend.com
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Related breakouts
Tuesday, November 27
FSV302 - Transforming Consumer Banking with a 100% Cloud-based Bank
4:45 – 5:45 | Venetian, Level 3, Murano 3205
Thursday, November 29
FSV305 - How HSBC Uses Serverless to Process Millions of Transactions in Real Time
1:00 – 2:00 | Bellagio, Level 1, Grand Ballroom 2
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Serverless API Development
POST /v1/pay
GET /v1/preferences/001
paymentbackend.com
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
PCI quick-start on AWS
Availability zone
Public Subnet
VPC
Internet
Private Subnet Private Subnet
RDS MySQL
DB instance
NAT gateway
Availability zone
Public Subnet
Private SubnetPrivate Subnet
Auto Scaling group
Instances Auto Scaling InstancesAuto Scaling NAT gateway
RDS MySQL
DB instance
Auto Scaling group
Instances Auto Scaling InstancesAuto Scaling
Thank you!
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Anthony Galleno
gallenoa@amazon.com
Andrew Shortt
ashortt@amazon.com
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.

More Related Content

What's hot

Cloud Adoption in Financial Services
Cloud Adoption in Financial Services Cloud Adoption in Financial Services
Cloud Adoption in Financial Services
Amazon Web Services
 

What's hot (20)

Building the business case for AWS
Building the business case for AWSBuilding the business case for AWS
Building the business case for AWS
 
Build your first blockchain application with Amazon Managed Blockchain - SVC2...
Build your first blockchain application with Amazon Managed Blockchain - SVC2...Build your first blockchain application with Amazon Managed Blockchain - SVC2...
Build your first blockchain application with Amazon Managed Blockchain - SVC2...
 
AWS Foundations
AWS FoundationsAWS Foundations
AWS Foundations
 
Accelerate Your Cloud Migration Journey.pdf
Accelerate Your Cloud Migration Journey.pdfAccelerate Your Cloud Migration Journey.pdf
Accelerate Your Cloud Migration Journey.pdf
 
AWS for Backup and Recovery
AWS for Backup and RecoveryAWS for Backup and Recovery
AWS for Backup and Recovery
 
Leveraging the AWS Sales Methodology and Partner Best Practices aws-partner-s...
Leveraging the AWS Sales Methodology and Partner Best Practices aws-partner-s...Leveraging the AWS Sales Methodology and Partner Best Practices aws-partner-s...
Leveraging the AWS Sales Methodology and Partner Best Practices aws-partner-s...
 
Hybrid Cloud Architectures on VMware Cloud on AWS.pdf
Hybrid Cloud Architectures on VMware Cloud on AWS.pdfHybrid Cloud Architectures on VMware Cloud on AWS.pdf
Hybrid Cloud Architectures on VMware Cloud on AWS.pdf
 
Simplify & Standardise Your Migration to AWS with a Migration Landing Zone
Simplify & Standardise Your Migration to AWS with a Migration Landing ZoneSimplify & Standardise Your Migration to AWS with a Migration Landing Zone
Simplify & Standardise Your Migration to AWS with a Migration Landing Zone
 
Executing a Large-Scale Migration to AWS
Executing a Large-Scale Migration to AWSExecuting a Large-Scale Migration to AWS
Executing a Large-Scale Migration to AWS
 
Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018
Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018
Module 2: Core AWS Compute and Storage Services - Virtual AWSome Day June 2018
 
APN Program Update
APN Program UpdateAPN Program Update
APN Program Update
 
Overview of AWS by Andy Jassy - SVP, AWS
Overview of AWS by Andy Jassy - SVP, AWSOverview of AWS by Andy Jassy - SVP, AWS
Overview of AWS by Andy Jassy - SVP, AWS
 
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
Module 1: Introduction to the AWS Cloud - AWSome Day Online Conference 2019
 
Your Journey with AWS as an APN partner and APN Resources to Help You
Your Journey with AWS as an APN partner and APN Resources to Help YouYour Journey with AWS as an APN partner and APN Resources to Help You
Your Journey with AWS as an APN partner and APN Resources to Help You
 
Defining Your Cloud Strategy
Defining Your Cloud StrategyDefining Your Cloud Strategy
Defining Your Cloud Strategy
 
Go-to Market with AWS for Startups
Go-to Market with AWS for StartupsGo-to Market with AWS for Startups
Go-to Market with AWS for Startups
 
Building a Better Business Case for Migrating to Cloud
Building a Better Business Case for Migrating to CloudBuilding a Better Business Case for Migrating to Cloud
Building a Better Business Case for Migrating to Cloud
 
Cloud Migration Workshop
Cloud Migration WorkshopCloud Migration Workshop
Cloud Migration Workshop
 
Aws ppt
Aws pptAws ppt
Aws ppt
 
Cloud Adoption in Financial Services
Cloud Adoption in Financial Services Cloud Adoption in Financial Services
Cloud Adoption in Financial Services
 

Similar to Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS re:Invent 2018

設計可擴展-安全的創新金融科技-FinTech-應用-深入探討現代化的數位支付服務
設計可擴展-安全的創新金融科技-FinTech-應用-深入探討現代化的數位支付服務設計可擴展-安全的創新金融科技-FinTech-應用-深入探討現代化的數位支付服務
設計可擴展-安全的創新金融科技-FinTech-應用-深入探討現代化的數位支付服務
Amazon Web Services
 
Presentation Pci-dss compliance on the cloud
Presentation Pci-dss compliance on the cloudPresentation Pci-dss compliance on the cloud
Presentation Pci-dss compliance on the cloud
Hassan EL ALLOUSSI
 
Track 1 Session 5_數位創新 市場資料雲端分析與應用(new).pptx
Track 1 Session 5_數位創新  市場資料雲端分析與應用(new).pptxTrack 1 Session 5_數位創新  市場資料雲端分析與應用(new).pptx
Track 1 Session 5_數位創新 市場資料雲端分析與應用(new).pptx
Amazon Web Services
 

Similar to Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS re:Invent 2018 (20)

Automated Frameworks to Deliver DevOps at Speed and Scale on AWS
 Automated Frameworks to Deliver DevOps at Speed and Scale on AWS Automated Frameworks to Deliver DevOps at Speed and Scale on AWS
Automated Frameworks to Deliver DevOps at Speed and Scale on AWS
 
How To Build Credit Card Payment Processing Platform on AWS?
How To Build Credit Card Payment Processing Platform on AWS?How To Build Credit Card Payment Processing Platform on AWS?
How To Build Credit Card Payment Processing Platform on AWS?
 
How to Process Transactions Like a Boss! AWS Developer Workshop at Web Summit...
How to Process Transactions Like a Boss! AWS Developer Workshop at Web Summit...How to Process Transactions Like a Boss! AWS Developer Workshop at Web Summit...
How to Process Transactions Like a Boss! AWS Developer Workshop at Web Summit...
 
Building Highly Sophisticated Environments for Security and Compliance on AWS
Building Highly Sophisticated Environments for Security and Compliance on AWSBuilding Highly Sophisticated Environments for Security and Compliance on AWS
Building Highly Sophisticated Environments for Security and Compliance on AWS
 
設計可擴展-安全的創新金融科技-FinTech-應用-深入探討現代化的數位支付服務
設計可擴展-安全的創新金融科技-FinTech-應用-深入探討現代化的數位支付服務設計可擴展-安全的創新金融科技-FinTech-應用-深入探討現代化的數位支付服務
設計可擴展-安全的創新金融科技-FinTech-應用-深入探討現代化的數位支付服務
 
Blockchain in Retail (RET217) - AWS re:Invent 2018
Blockchain in Retail (RET217) - AWS re:Invent 2018Blockchain in Retail (RET217) - AWS re:Invent 2018
Blockchain in Retail (RET217) - AWS re:Invent 2018
 
Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT
 Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT
Guard Against Fraud and Financial Crime with NICE Actimize & AWS PPT
 
New Tools for a New World
New Tools for a New WorldNew Tools for a New World
New Tools for a New World
 
Presentation Pci-dss compliance on the cloud
Presentation Pci-dss compliance on the cloudPresentation Pci-dss compliance on the cloud
Presentation Pci-dss compliance on the cloud
 
ENT305 Compliance and Cloud Security for Regulated Industries
ENT305 Compliance and Cloud Security for Regulated IndustriesENT305 Compliance and Cloud Security for Regulated Industries
ENT305 Compliance and Cloud Security for Regulated Industries
 
Track 1 Session 5_數位創新 市場資料雲端分析與應用(new).pptx
Track 1 Session 5_數位創新  市場資料雲端分析與應用(new).pptxTrack 1 Session 5_數位創新  市場資料雲端分析與應用(new).pptx
Track 1 Session 5_數位創新 市場資料雲端分析與應用(new).pptx
 
Enabling a Digital Platform with Microservices Architecture (ARC218-S) - AWS ...
Enabling a Digital Platform with Microservices Architecture (ARC218-S) - AWS ...Enabling a Digital Platform with Microservices Architecture (ARC218-S) - AWS ...
Enabling a Digital Platform with Microservices Architecture (ARC218-S) - AWS ...
 
Building Enterprise Solutions with Blockchain and Ledger Technology - SVC202 ...
Building Enterprise Solutions with Blockchain and Ledger Technology - SVC202 ...Building Enterprise Solutions with Blockchain and Ledger Technology - SVC202 ...
Building Enterprise Solutions with Blockchain and Ledger Technology - SVC202 ...
 
AWS Data Analytics on AWS
AWS Data Analytics on AWSAWS Data Analytics on AWS
AWS Data Analytics on AWS
 
AWS - Security & Compliance
AWS - Security & ComplianceAWS - Security & Compliance
AWS - Security & Compliance
 
Financial Services in the Cloud
Financial Services in the CloudFinancial Services in the Cloud
Financial Services in the Cloud
 
AWS IoT for Frictionless Consumer Experiences in Retail (RET201) - AWS re:Inv...
AWS IoT for Frictionless Consumer Experiences in Retail (RET201) - AWS re:Inv...AWS IoT for Frictionless Consumer Experiences in Retail (RET201) - AWS re:Inv...
AWS IoT for Frictionless Consumer Experiences in Retail (RET201) - AWS re:Inv...
 
Generational shiftsRedefining Customer Experience And The Way To Insure
Generational shiftsRedefining Customer Experience And The Way To InsureGenerational shiftsRedefining Customer Experience And The Way To Insure
Generational shiftsRedefining Customer Experience And The Way To Insure
 
AWS IoT: servizi costruiti per migliorare le performance di business
AWS IoT: servizi costruiti per migliorare le performance di businessAWS IoT: servizi costruiti per migliorare le performance di business
AWS IoT: servizi costruiti per migliorare le performance di business
 
Accelerated Saa S Exec Briefing V2
Accelerated Saa S Exec Briefing V2Accelerated Saa S Exec Briefing V2
Accelerated Saa S Exec Briefing V2
 

More from Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS re:Invent 2018

  • 1.
  • 2. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Disrupting Traditional Payment Systems Architecture with AWS Anthony Galleno Solution Architect AWS Financial Services F S V 3 2 0 Andrew Shortt Solution Delivery Manager AWS Financial Services
  • 3. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Agenda Rapid Evolution In Payments PCI DSS Compliance PCI Architecture on AWS Serverless Architectures on AWS Q & A
  • 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. The global payments landscape is shifting Shift to digital accelerated by growing smartphone adoption and new channels for non-cash transactions New non-banks and Payment Service Providers (PSPs) offering payment services and technology, enabling transactions outside traditional channels Changing customer demands including frictionless payments experience, one-touch options, and instant settlement Progressive changes among regulators promoting transparency, security, innovation, interoperability, and competition
  • 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Consumer demands are driving innovation Retail and corporate payments customers want faster, easier, digital payments. Now: Payments as a differentiator • Firms investing in payments technologies and processing infrastructure • Faster, seamless payment experiences and better use of customer data • Collaborative payment ecosystem focused on customer demands • New payments channels replace cash in small transactions and increase firm’s revenue Before: Payments as a commodity • Small transactions dominated by cash • Check payments still common • Most digital payments running on legacy platforms • Card payments processing handled by credit card networks • Payments considered low profit product by banks and Payment Service Providers
  • 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customers Innovating Payments with AWS
  • 7. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. PCI DSS Compliance “If you accept or process payment cards, the PCI Data Security Standards apply to you.” In order to connect to the major card networks, the system you build must comply with PCI DSS guidelines and be scoped, audited, and reviewed by an on-site PCI Qualified Security Assessor.
  • 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. PCI DSS Compliance on AWS Scale Compute to match demand Advanced data storage and analytics Seamless customer experience Model Risk, Credit and lending decisions Build, test, launch new features Serverless/Infrastructure as code Security and compliance Connect payment apps More than 60 AWS services are PCI-DSS compliant. With pay as you go pricing and global availability customers can leverage these services to deliver fast, frictionless payment systems.
  • 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. PCI DSS Guidelines on AWS Build Maintain a Secure Network and Systems 1. Install and Maintain a Firewall Configuration to Protect Cardholder Data 2. Do Not Use Vendor-Supplied Defaults for System Passwords and Other Security Parameters VPN Gateway Protect Cardholder Data 3. Protect Stored Cardholder Data 4. Encrypt transmission of cardholder data across open, public networks
  • 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. PCI DSS Compliance on AWS Maintain a Vulnerability Management Program 5. Protect all systems against malware and regularly update anti-virus software 6. Develop and maintain secure systems and applications Implement Strong Access Controls 7. Restrict Access to Cardholder Data by Need to know 8. Identify and Authenticate Access to System Components 9. Restrict Physical Access to Cardholder Data
  • 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. PCI DSS Compliance on AWS Regularly Monitor and Test Networks 10. Track and monitor all access to network resources and cardholder data 11. Regularly test security systems and processes Flow logs Maintain an Information Security Policy 12. Maintain a policy that addresses information security for all personnel
  • 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. PCI quick-start on AWS Availability zone Public Subnet VPC Internet Private Subnet Private Subnet RDS MySQL DB instance NAT gateway Availability zone Public Subnet Private SubnetPrivate Subnet Auto Scaling group Instances Auto Scaling InstancesAuto Scaling NAT gateway RDS MySQL DB instance Auto Scaling group Instances Auto Scaling InstancesAuto Scaling
  • 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Serverless API Development POST /v1/pay GET /v1/preferences/001 paymentbackend.com
  • 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Related breakouts Tuesday, November 27 FSV302 - Transforming Consumer Banking with a 100% Cloud-based Bank 4:45 – 5:45 | Venetian, Level 3, Murano 3205 Thursday, November 29 FSV305 - How HSBC Uses Serverless to Process Millions of Transactions in Real Time 1:00 – 2:00 | Bellagio, Level 1, Grand Ballroom 2
  • 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Serverless API Development POST /v1/pay GET /v1/preferences/001 paymentbackend.com
  • 16. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. PCI quick-start on AWS Availability zone Public Subnet VPC Internet Private Subnet Private Subnet RDS MySQL DB instance NAT gateway Availability zone Public Subnet Private SubnetPrivate Subnet Auto Scaling group Instances Auto Scaling InstancesAuto Scaling NAT gateway RDS MySQL DB instance Auto Scaling group Instances Auto Scaling InstancesAuto Scaling
  • 17. Thank you! © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Anthony Galleno gallenoa@amazon.com Andrew Shortt ashortt@amazon.com
  • 18. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.