SlideShare a Scribd company logo
1 of 40
Download to read offline
Leveraging Marketplace and AWS
Partner Network Resources
Josh Hofmann, Senior Manager, NA Partner Development
Barry Russell, Head of Global Marketplace BD
Matt Yanchyshyn, Senior Manager, Solution Architecture
Partner
Network
Agenda - Leveraging AWS Partner Network
resources
1. APN and AWS Global Partner
Programs and best practices
2. Leveraging the AWS
Marketplace
3. Incorporating security best
practices into your solutions
Partner
Network
AWS Global Partner Programs and
Best Practices
Josh Hofmann
NA Partner Leader West
jhof@amazon.com
Trends in the AWS Partner Network ecosystem
Partners are:
• Joining the APN at record pace
• Growing their AWS offerings quickly
• Offering packaged services & solutions
Enterprises are:
• Asking for DevOps and managed services
• Increasingly deploying SaaS software
• Using AWS Marketplace software for production
Provide:
• Software
• Databases
• OS and tooling solutions
Provide:
• Professional services
• AWS integration, migration,
managed services
Technology partners Consulting partners
Premier
Advanced
Standard
Registered
Delivery Model ExpertiseExperiencePartner Type
Your roadmap: AWS Global Partner Programs
Channel Programs
MSP Program
SaaS Program
Competency
Program
Government
Program
Test Drive
AWS Marketplace
Consulting
Technology
GTM Resources
Go-To-Market
Partner
Network
APN Benefits for partners
Training & Enablement
• On-Demand Sales & Technical
Training & Accreditations
• APN Webcast Videos
• 20% Discount Classroom Training
• Solutions Architect Office Hours
• AWS QuickStarts
• Subsidized Classroom Training
• ProServe Bootcamp Training
• Product Development Credits
• Named Solutions Architect
• 10 Days Free AWS ProServe
Marketing & Go-to-Market
• Syndicated Web Content
• Email Marketing Platform
• Partner Enablement Guides
• Opportunity Registration
• Listing in the AWS Directory
• Marketing Development Funding
• Demand Generation Campaigns
• AWS Written Case Study
• Proof-of-Concept Credits/Funding
• Listed on AWS Solution Pages
• Named Partner Manager
• Validates partners with proven workload and
vertical capabilities
• Differentiates APN Partners to AWS Customers
• Validated based on:
• Customer success, AWS certifications,
technical readiness, AWS product or practice
review, customer references
APN Competency Program
Current APN competencies
Digital media
Storage
Life sciences Healthcare
SAP Oracle
Big data
Microsoft
Channel Reseller Program
Validation Audit for all Partners in the Program
• Enables qualified APN Consulting
Partners to resell AWS services to
both commercial and public sector
AWS customers
• Ideal for partners building value-
added offerings on AWS
• Partner handles billing,
procurement, and support for their
customers
“Being an AWS Channel Reseller
enables us to establish an even
closer partnership with our
customers and deliver value to
them by accelerating adoption of
the services provided by AWS.“
- Cloudreach
Value-added solutions are driving revenue
AWS Managed Services Program
For Consulting Partners offering managed
services on AWS
• Technical Enablement – DevOps Approach,
Security, Customer Expectations
• Business Enablement – Marketing and Go-to-Market
Validation Audit to Qualify for the Program
• Migration, operations, security, and cloud infrastructure management
• Proactive monitoring and automation of customer’s environment
Self-Assess with the Validation Checklist in the APN Portal
“AWS is raising the bar on partners to ensure a consistent and rewarding
customer experience” – 2nd Watch
Professional Services / Strategy Consulting / Architecture
2x to 5x
Multiplier on
top
Of AWS
Application / Development / Integration / Migration
$50k
To
$200K
Managed Infrastructure Services
15% to 40%
Uplift
On AWS
AWS Optimization
RI Purchases
Reduce Costs
30% to 60%
Software
5% to 30%
License
MarginsApp/Dev Example:
 $150K to build app
 $100K on-demand over 1 year to run on AWS
 $50K in third-party SW license
On-premises to AWS cloud transformation:
3X to 10X uplift over AWS spend
Customer example for managed services
3X = $300K
$150K
25% = $25K
40% reduce
$40K 20% margin
$10K
Overall Cost:
$635K
$450K project
$85k recurring
Software-as-a-Service Program (Preview)
Enables partners to deploy on AWS in
a SaaS delivery model
Technical & Business Enablement
• Apply on APN Portal today
• SaaS Reference Page on Portal
• SaaS Webcasts
• SaaS Program Office Hours
• Creating a SaaS Partner Community to
collaborate and share best practices
“By 2017, about 26.2% of all new business software
purchases will be of service-enabled software.” - IDC
“We are pleased to be one of the
members of AWS’ SaaS Partner
Program, which gives us access to
tools and training to assist us in
designing and delivering cloud-based
applications.” - PegaSystems
Consulting Partner best practices
Packaged service
& solution offerings
Fixed price
migration
DevOps
workshops
Security as a
service
Script most
common projects
Technology Partner best practices
Deploying
SaaS on AWS
Engaging
Consulting
Partners
Taking a solution
approach
Promotion via the
AWS brand
All-in on AWS
18% of all software delivery will be
SaaS by 2017 (IDC)
Cloud software will grow to $76.1 billion by 2017 (IDC)
AWS Marketplace
Barry Russell
Head of Global Business Development
barryr@amazon.com
Where does AWS Marketplace fit?...as part of a
customer solution enabling Workloads moving to AWS
Enterprise Applications
Administration & Security
Core Services
Platform Services
Infrastructure
AWS Marketplace
Why cloud changes software procurement
“35MM+ physical servers
globally today – only
15% in the cloud” *IDC
Cloud is shifting software from
perpetuity to subscription OR
consumption-based
Enterprises invest $310B
annually in software
Selecting, purchasing, and
deploying is still slow and
manual
“…50% of workloads will
move to the cloud by
2018” *IDC
Companies use BYOL to
bring premise license over
or buy “as needed”
through AWS Marketplace
So what shift is happening?
• Enterprise, Government, SMB
changing how they buy and
deploy
• Procurement teams looking to
cloud catalogs for departmental
projects
• Software consumption “as you go”
• Software market now transforming
with cloud, as did infrastructure
• And a 5 Workload to cloud model
(we are aligning with our Global
Field):
– Media Workloads
– BI/Big Data Workloads
– Storage Workloads
– WebSite Workloads
– DevOps Workloads
AWS Marketplace
About us
• Launched in April 2012
• Publishes software
• Over 700 software partners
• More than 2,200 product listings
Benefits to customers
• Easy product discovery
• Simplifies procurement for
customers
• Eliminate license management
• One AWS bill
• Consume hourly, monthly, annually
By the numbers…
400% Usage Growth in
2014
Over 1B Hours of software
consumed annually
2,200 products and growing
AWS Marketplace customers – Who is buying?
AWS Intelligence Community (IC) Marketplace
(*note we are taking ISV submissions now for this catalog)
SoftNAS – Success of the start-up on AWS
• With software vetted on AWS Marketplace,
Enterprises can buy start-up with confidence and
without any additional paperwork
• From 15 customers to 280+ in 1 year
• 87% conversion to paid customers from free trials
“AWS Marketplace reduced over 20 individual steps to a
simple ‘1-Click’ allowing us to deliver…in less than 2 minutes.
What took customers weeks if not months, and costs
thousands of dollars can now be accomplished in under two
minutes…It enables SoftNAS to deliver a seamless cloud
based storage solution, get access to the global AWS
customer base while at the same time provide a low-cost
channel compared to traditional IT channels.”
– Bill Hood, Founder and SVP Cloud Markets
Digital marketing drives adoption
How does an ISV, SI, or VAR get into AWS Marketplace?
• Simple process; can be ready in 30 days
• Security product testing and screen
• Provide us products as an AMI
• Give us metadata about your product
• Tell us how to price your products
• Engage AWS Marketplace BD for launch plan
…and you are ready to go!!!
How do I build a transformational business with
AWS Marketplace?
• Use AWS Marketplace as primary sales and
delivery channel (ISV and Consulting Partners)
• Train your technical and field staff on AWS using
APN Programs
• Participate in our Customer Data Sharing Program
• GTM best practices:
– Comp your field to align with ours
– Build website assets; point to your listing
– Develop quarterly GTM plans
• List your full software suite - price annually
• Take advantage of PoC GTM funding
Security Best Practices
Matt Yanchyshyn
Sr. Manager, Solutions Architecture
AWS Foundation Services
Compute Storage Database Networking
AWS Global
Infrastructure Regions
Availability Zones
Edge
locations
AWS is responsible for the security of the cloud
AWS Foundation Services
Compute Storage Database Networking
AWS Global
Infrastructure Regions
Availability Zones
Edge
Locations
Client-side data
encryption
Server-side data
encryption
Network traffic
protection
Platform, applications, identity & access management
Operating system, network, & firewall configuration
Customer applications & contentCustomers
Customers configure their security in the cloud
Defense-in-depth
AWS compliance
program
Third-party
attestations
Physical
Security groups
VPC
configuration
Network
Web application
firewalls
Bastion hosts
Encryption
in-transit
Hardened AMIs
OS and app
patch mgmt.
IAM roles for
EC2
IAM credentials
Systemsecurity
Logical access
controls
User
authentication
Encryption
at-rest
Datasecurity
AWS security offerings
Auditability
Compliance
reports
Visibility
Amazon CloudWatch
AWS CloudTrail
AWS Config
“Describe” APIs
Control
AWS IAM
AWS CloudHSM
AWS CloudFormation
AWS KMS
Encryption: data at rest
EBS
Volume encryption
EBS encryption OS tools
AWS
marketplace/partner
Object encryption
S3 server-side
encryption (SSE)
S3 SSE w/ customer
provided keys Client-side encryption
Database encryption
Amazon Redshift
encryption
RDS
PostgreSQL
KMS
RDS
MYSQL
KMS
RDS
ORACLE
TDE/HSM
RDS MSSQL
TDE
Built-in firewall: security groups and NACLs
• VPC security groups (mandatory)
– Instance level, stateful
– Supports ALLOW rules only
– Default deny inbound, allow outbound
– Use as “whitelist” – least privilege
• VPC NACLs (optional)
– Subnet level, stateless
– Supports ALLOW and DENY
– Default allow all
– Use as “blacklist”/“guardrails”(port 135,21,23…)
• Separation of duties
• Changes audited via AWS CloudTrail
• Additional cost for SGs/NACLs: $0
Physical Interfaces
Customer 1
Hypervisor
Customer 2 Customer n…
…
Virtual Interfaces
Firewall
Customer 1
Security
Groups
Customer 2
Security
Groups
Customer n
Security
Groups
Security Groups
Enforce consistent security on your hosts
Launch
instance
EC2
AMI catalog Running instance
Your instance
Hardening
Audit and logging
Vulnerability management
Malware and HIPS
Whitelisting and integrity
User administration
Operating system
Configure
instance
Configure and harden EC2 instances based on security and compliance needs
Host-based protection software
Restrict access where possible
Connect to existing services
Separate static assets and move servers away from
the edge
Inbound HTTP
CloudFront
Amazon S3
WAFDynamic
App
App
AppPeering
Identity and Access Management (IAM)
Create appropriate principles, authorization, and privileges for AWS resources
Multi-factor authentication
AWS Identify and
Access Management
Policies
User
Groups
Roles
Principle of least privilege
User User Hardware Virtual
IAM AWS administrative users
Root account
Note: Always associate the account owner ID with
an MFA device and store it in a secured place!
AWS partner solutions extend & enhance security
• Some examples:
– Cisco CSR (VPN)
– Sophos UTM (firewall, …)
– Alert Logic Web Security Manager (WAF)
– Alert Logic Threat Manager (NIDS)
– Trend Micro Deep Security (IDPS)
– Trend Micro SecureCloud (encryption)
– Dome9 SecOps (security group audit & management)
– …
Best Practices for Partnering with AWS

More Related Content

Viewers also liked

(SPOT208) How to Sponsor a Diversity Circle in a Tech Workplace
(SPOT208) How to Sponsor a Diversity Circle in a Tech Workplace(SPOT208) How to Sponsor a Diversity Circle in a Tech Workplace
(SPOT208) How to Sponsor a Diversity Circle in a Tech WorkplaceAmazon Web Services
 
Intro to AWS: Amazon EC2 and Compute Services
Intro to AWS: Amazon EC2 and Compute ServicesIntro to AWS: Amazon EC2 and Compute Services
Intro to AWS: Amazon EC2 and Compute ServicesAmazon Web Services
 
Creating Velocity in Data Centre Migrations to AWS
Creating Velocity in Data Centre Migrations to AWSCreating Velocity in Data Centre Migrations to AWS
Creating Velocity in Data Centre Migrations to AWSAmazon Web Services
 
Intro to AWS: Database Services
Intro to AWS: Database ServicesIntro to AWS: Database Services
Intro to AWS: Database ServicesAmazon Web Services
 
Razorfish Global Tech Summit 2015 - The Third Channel Razorfish
Razorfish Global Tech Summit 2015 - The Third Channel RazorfishRazorfish Global Tech Summit 2015 - The Third Channel Razorfish
Razorfish Global Tech Summit 2015 - The Third Channel RazorfishRazorfish
 
Aws Architecture Fundamentals
Aws Architecture FundamentalsAws Architecture Fundamentals
Aws Architecture Fundamentals2nd Watch
 
(SEC403) Diving into AWS CloudTrail Events w/ Apache Spark on EMR
(SEC403) Diving into AWS CloudTrail Events w/ Apache Spark on EMR(SEC403) Diving into AWS CloudTrail Events w/ Apache Spark on EMR
(SEC403) Diving into AWS CloudTrail Events w/ Apache Spark on EMRAmazon Web Services
 
(MBL402) Mobile Identity Management & Data Sync Using Amazon Cognito
(MBL402) Mobile Identity Management & Data Sync Using Amazon Cognito(MBL402) Mobile Identity Management & Data Sync Using Amazon Cognito
(MBL402) Mobile Identity Management & Data Sync Using Amazon CognitoAmazon Web Services
 
Expanding Through Indirect
Expanding Through IndirectExpanding Through Indirect
Expanding Through IndirectMark Doornbosch
 
Managing Indirect Channels - Webinar for ASAP Association
Managing Indirect Channels - Webinar for ASAP AssociationManaging Indirect Channels - Webinar for ASAP Association
Managing Indirect Channels - Webinar for ASAP AssociationJay McBain
 
Increased overall sales by 35% within 6 months using B2B Partner Management p...
Increased overall sales by 35% within 6 months using B2B Partner Management p...Increased overall sales by 35% within 6 months using B2B Partner Management p...
Increased overall sales by 35% within 6 months using B2B Partner Management p...Expedux Technologies
 
GWAVACon 2013: Partner Program Updates - New Partner Portal
GWAVACon 2013: Partner Program Updates - New Partner PortalGWAVACon 2013: Partner Program Updates - New Partner Portal
GWAVACon 2013: Partner Program Updates - New Partner PortalGWAVA
 
AWS July Webinar Series: Overview: Build and Manage your APIs with Amazon API...
AWS July Webinar Series: Overview: Build and Manage your APIs with Amazon API...AWS July Webinar Series: Overview: Build and Manage your APIs with Amazon API...
AWS July Webinar Series: Overview: Build and Manage your APIs with Amazon API...Amazon Web Services
 

Viewers also liked (13)

(SPOT208) How to Sponsor a Diversity Circle in a Tech Workplace
(SPOT208) How to Sponsor a Diversity Circle in a Tech Workplace(SPOT208) How to Sponsor a Diversity Circle in a Tech Workplace
(SPOT208) How to Sponsor a Diversity Circle in a Tech Workplace
 
Intro to AWS: Amazon EC2 and Compute Services
Intro to AWS: Amazon EC2 and Compute ServicesIntro to AWS: Amazon EC2 and Compute Services
Intro to AWS: Amazon EC2 and Compute Services
 
Creating Velocity in Data Centre Migrations to AWS
Creating Velocity in Data Centre Migrations to AWSCreating Velocity in Data Centre Migrations to AWS
Creating Velocity in Data Centre Migrations to AWS
 
Intro to AWS: Database Services
Intro to AWS: Database ServicesIntro to AWS: Database Services
Intro to AWS: Database Services
 
Razorfish Global Tech Summit 2015 - The Third Channel Razorfish
Razorfish Global Tech Summit 2015 - The Third Channel RazorfishRazorfish Global Tech Summit 2015 - The Third Channel Razorfish
Razorfish Global Tech Summit 2015 - The Third Channel Razorfish
 
Aws Architecture Fundamentals
Aws Architecture FundamentalsAws Architecture Fundamentals
Aws Architecture Fundamentals
 
(SEC403) Diving into AWS CloudTrail Events w/ Apache Spark on EMR
(SEC403) Diving into AWS CloudTrail Events w/ Apache Spark on EMR(SEC403) Diving into AWS CloudTrail Events w/ Apache Spark on EMR
(SEC403) Diving into AWS CloudTrail Events w/ Apache Spark on EMR
 
(MBL402) Mobile Identity Management & Data Sync Using Amazon Cognito
(MBL402) Mobile Identity Management & Data Sync Using Amazon Cognito(MBL402) Mobile Identity Management & Data Sync Using Amazon Cognito
(MBL402) Mobile Identity Management & Data Sync Using Amazon Cognito
 
Expanding Through Indirect
Expanding Through IndirectExpanding Through Indirect
Expanding Through Indirect
 
Managing Indirect Channels - Webinar for ASAP Association
Managing Indirect Channels - Webinar for ASAP AssociationManaging Indirect Channels - Webinar for ASAP Association
Managing Indirect Channels - Webinar for ASAP Association
 
Increased overall sales by 35% within 6 months using B2B Partner Management p...
Increased overall sales by 35% within 6 months using B2B Partner Management p...Increased overall sales by 35% within 6 months using B2B Partner Management p...
Increased overall sales by 35% within 6 months using B2B Partner Management p...
 
GWAVACon 2013: Partner Program Updates - New Partner Portal
GWAVACon 2013: Partner Program Updates - New Partner PortalGWAVACon 2013: Partner Program Updates - New Partner Portal
GWAVACon 2013: Partner Program Updates - New Partner Portal
 
AWS July Webinar Series: Overview: Build and Manage your APIs with Amazon API...
AWS July Webinar Series: Overview: Build and Manage your APIs with Amazon API...AWS July Webinar Series: Overview: Build and Manage your APIs with Amazon API...
AWS July Webinar Series: Overview: Build and Manage your APIs with Amazon API...
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalitĂ  Server...
Big Data per le Startup: come creare applicazioni Big Data in modalitĂ  Server...Big Data per le Startup: come creare applicazioni Big Data in modalitĂ  Server...
Big Data per le Startup: come creare applicazioni Big Data in modalitĂ  Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalitĂ  Server...
Big Data per le Startup: come creare applicazioni Big Data in modalitĂ  Server...Big Data per le Startup: come creare applicazioni Big Data in modalitĂ  Server...
Big Data per le Startup: come creare applicazioni Big Data in modalitĂ  Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Recently uploaded

Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024Rafal Los
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEarley Information Science
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...Neo4j
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel AraĂşjo
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Paola De la Torre
 

Recently uploaded (20)

Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptxEIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
EIS-Webinar-Prompt-Knowledge-Eng-2024-04-08.pptx
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101Salesforce Community Group Quito, Salesforce 101
Salesforce Community Group Quito, Salesforce 101
 

Best Practices for Partnering with AWS

  • 1. Leveraging Marketplace and AWS Partner Network Resources Josh Hofmann, Senior Manager, NA Partner Development Barry Russell, Head of Global Marketplace BD Matt Yanchyshyn, Senior Manager, Solution Architecture Partner Network
  • 2. Agenda - Leveraging AWS Partner Network resources 1. APN and AWS Global Partner Programs and best practices 2. Leveraging the AWS Marketplace 3. Incorporating security best practices into your solutions Partner Network
  • 3. AWS Global Partner Programs and Best Practices Josh Hofmann NA Partner Leader West jhof@amazon.com
  • 4. Trends in the AWS Partner Network ecosystem Partners are: • Joining the APN at record pace • Growing their AWS offerings quickly • Offering packaged services & solutions Enterprises are: • Asking for DevOps and managed services • Increasingly deploying SaaS software • Using AWS Marketplace software for production
  • 5. Provide: • Software • Databases • OS and tooling solutions Provide: • Professional services • AWS integration, migration, managed services Technology partners Consulting partners
  • 6. Premier Advanced Standard Registered Delivery Model ExpertiseExperiencePartner Type Your roadmap: AWS Global Partner Programs Channel Programs MSP Program SaaS Program Competency Program Government Program Test Drive AWS Marketplace Consulting Technology GTM Resources Go-To-Market Partner Network
  • 7. APN Benefits for partners Training & Enablement • On-Demand Sales & Technical Training & Accreditations • APN Webcast Videos • 20% Discount Classroom Training • Solutions Architect Office Hours • AWS QuickStarts • Subsidized Classroom Training • ProServe Bootcamp Training • Product Development Credits • Named Solutions Architect • 10 Days Free AWS ProServe Marketing & Go-to-Market • Syndicated Web Content • Email Marketing Platform • Partner Enablement Guides • Opportunity Registration • Listing in the AWS Directory • Marketing Development Funding • Demand Generation Campaigns • AWS Written Case Study • Proof-of-Concept Credits/Funding • Listed on AWS Solution Pages • Named Partner Manager
  • 8. • Validates partners with proven workload and vertical capabilities • Differentiates APN Partners to AWS Customers • Validated based on: • Customer success, AWS certifications, technical readiness, AWS product or practice review, customer references APN Competency Program
  • 9. Current APN competencies Digital media Storage Life sciences Healthcare SAP Oracle Big data Microsoft
  • 10. Channel Reseller Program Validation Audit for all Partners in the Program • Enables qualified APN Consulting Partners to resell AWS services to both commercial and public sector AWS customers • Ideal for partners building value- added offerings on AWS • Partner handles billing, procurement, and support for their customers “Being an AWS Channel Reseller enables us to establish an even closer partnership with our customers and deliver value to them by accelerating adoption of the services provided by AWS.“ - Cloudreach
  • 11. Value-added solutions are driving revenue
  • 12. AWS Managed Services Program For Consulting Partners offering managed services on AWS • Technical Enablement – DevOps Approach, Security, Customer Expectations • Business Enablement – Marketing and Go-to-Market Validation Audit to Qualify for the Program • Migration, operations, security, and cloud infrastructure management • Proactive monitoring and automation of customer’s environment Self-Assess with the Validation Checklist in the APN Portal “AWS is raising the bar on partners to ensure a consistent and rewarding customer experience” – 2nd Watch
  • 13. Professional Services / Strategy Consulting / Architecture 2x to 5x Multiplier on top Of AWS Application / Development / Integration / Migration $50k To $200K Managed Infrastructure Services 15% to 40% Uplift On AWS AWS Optimization RI Purchases Reduce Costs 30% to 60% Software 5% to 30% License MarginsApp/Dev Example:  $150K to build app  $100K on-demand over 1 year to run on AWS  $50K in third-party SW license On-premises to AWS cloud transformation: 3X to 10X uplift over AWS spend Customer example for managed services 3X = $300K $150K 25% = $25K 40% reduce $40K 20% margin $10K Overall Cost: $635K $450K project $85k recurring
  • 14. Software-as-a-Service Program (Preview) Enables partners to deploy on AWS in a SaaS delivery model Technical & Business Enablement • Apply on APN Portal today • SaaS Reference Page on Portal • SaaS Webcasts • SaaS Program Office Hours • Creating a SaaS Partner Community to collaborate and share best practices “By 2017, about 26.2% of all new business software purchases will be of service-enabled software.” - IDC “We are pleased to be one of the members of AWS’ SaaS Partner Program, which gives us access to tools and training to assist us in designing and delivering cloud-based applications.” - PegaSystems
  • 15. Consulting Partner best practices Packaged service & solution offerings Fixed price migration DevOps workshops Security as a service Script most common projects
  • 16. Technology Partner best practices Deploying SaaS on AWS Engaging Consulting Partners Taking a solution approach Promotion via the AWS brand All-in on AWS 18% of all software delivery will be SaaS by 2017 (IDC) Cloud software will grow to $76.1 billion by 2017 (IDC)
  • 17. AWS Marketplace Barry Russell Head of Global Business Development barryr@amazon.com
  • 18. Where does AWS Marketplace fit?...as part of a customer solution enabling Workloads moving to AWS Enterprise Applications Administration & Security Core Services Platform Services Infrastructure AWS Marketplace
  • 19. Why cloud changes software procurement “35MM+ physical servers globally today – only 15% in the cloud” *IDC Cloud is shifting software from perpetuity to subscription OR consumption-based Enterprises invest $310B annually in software Selecting, purchasing, and deploying is still slow and manual “…50% of workloads will move to the cloud by 2018” *IDC Companies use BYOL to bring premise license over or buy “as needed” through AWS Marketplace
  • 20. So what shift is happening? • Enterprise, Government, SMB changing how they buy and deploy • Procurement teams looking to cloud catalogs for departmental projects • Software consumption “as you go” • Software market now transforming with cloud, as did infrastructure • And a 5 Workload to cloud model (we are aligning with our Global Field): – Media Workloads – BI/Big Data Workloads – Storage Workloads – WebSite Workloads – DevOps Workloads
  • 21. AWS Marketplace About us • Launched in April 2012 • Publishes software • Over 700 software partners • More than 2,200 product listings Benefits to customers • Easy product discovery • Simplifies procurement for customers • Eliminate license management • One AWS bill • Consume hourly, monthly, annually
  • 22. By the numbers… 400% Usage Growth in 2014 Over 1B Hours of software consumed annually 2,200 products and growing
  • 23. AWS Marketplace customers – Who is buying?
  • 24. AWS Intelligence Community (IC) Marketplace (*note we are taking ISV submissions now for this catalog)
  • 25. SoftNAS – Success of the start-up on AWS • With software vetted on AWS Marketplace, Enterprises can buy start-up with confidence and without any additional paperwork • From 15 customers to 280+ in 1 year • 87% conversion to paid customers from free trials “AWS Marketplace reduced over 20 individual steps to a simple ‘1-Click’ allowing us to deliver…in less than 2 minutes. What took customers weeks if not months, and costs thousands of dollars can now be accomplished in under two minutes…It enables SoftNAS to deliver a seamless cloud based storage solution, get access to the global AWS customer base while at the same time provide a low-cost channel compared to traditional IT channels.” – Bill Hood, Founder and SVP Cloud Markets
  • 27. How does an ISV, SI, or VAR get into AWS Marketplace? • Simple process; can be ready in 30 days • Security product testing and screen • Provide us products as an AMI • Give us metadata about your product • Tell us how to price your products • Engage AWS Marketplace BD for launch plan …and you are ready to go!!!
  • 28. How do I build a transformational business with AWS Marketplace? • Use AWS Marketplace as primary sales and delivery channel (ISV and Consulting Partners) • Train your technical and field staff on AWS using APN Programs • Participate in our Customer Data Sharing Program • GTM best practices: – Comp your field to align with ours – Build website assets; point to your listing – Develop quarterly GTM plans • List your full software suite - price annually • Take advantage of PoC GTM funding
  • 29. Security Best Practices Matt Yanchyshyn Sr. Manager, Solutions Architecture
  • 30. AWS Foundation Services Compute Storage Database Networking AWS Global Infrastructure Regions Availability Zones Edge locations AWS is responsible for the security of the cloud
  • 31. AWS Foundation Services Compute Storage Database Networking AWS Global Infrastructure Regions Availability Zones Edge Locations Client-side data encryption Server-side data encryption Network traffic protection Platform, applications, identity & access management Operating system, network, & firewall configuration Customer applications & contentCustomers Customers configure their security in the cloud
  • 32. Defense-in-depth AWS compliance program Third-party attestations Physical Security groups VPC configuration Network Web application firewalls Bastion hosts Encryption in-transit Hardened AMIs OS and app patch mgmt. IAM roles for EC2 IAM credentials Systemsecurity Logical access controls User authentication Encryption at-rest Datasecurity
  • 33. AWS security offerings Auditability Compliance reports Visibility Amazon CloudWatch AWS CloudTrail AWS Config “Describe” APIs Control AWS IAM AWS CloudHSM AWS CloudFormation AWS KMS
  • 34. Encryption: data at rest EBS Volume encryption EBS encryption OS tools AWS marketplace/partner Object encryption S3 server-side encryption (SSE) S3 SSE w/ customer provided keys Client-side encryption Database encryption Amazon Redshift encryption RDS PostgreSQL KMS RDS MYSQL KMS RDS ORACLE TDE/HSM RDS MSSQL TDE
  • 35. Built-in firewall: security groups and NACLs • VPC security groups (mandatory) – Instance level, stateful – Supports ALLOW rules only – Default deny inbound, allow outbound – Use as “whitelist” – least privilege • VPC NACLs (optional) – Subnet level, stateless – Supports ALLOW and DENY – Default allow all – Use as “blacklist”/“guardrails”(port 135,21,23…) • Separation of duties • Changes audited via AWS CloudTrail • Additional cost for SGs/NACLs: $0 Physical Interfaces Customer 1 Hypervisor Customer 2 Customer n… … Virtual Interfaces Firewall Customer 1 Security Groups Customer 2 Security Groups Customer n Security Groups Security Groups
  • 36. Enforce consistent security on your hosts Launch instance EC2 AMI catalog Running instance Your instance Hardening Audit and logging Vulnerability management Malware and HIPS Whitelisting and integrity User administration Operating system Configure instance Configure and harden EC2 instances based on security and compliance needs Host-based protection software Restrict access where possible Connect to existing services
  • 37. Separate static assets and move servers away from the edge Inbound HTTP CloudFront Amazon S3 WAFDynamic App App AppPeering
  • 38. Identity and Access Management (IAM) Create appropriate principles, authorization, and privileges for AWS resources Multi-factor authentication AWS Identify and Access Management Policies User Groups Roles Principle of least privilege User User Hardware Virtual IAM AWS administrative users Root account Note: Always associate the account owner ID with an MFA device and store it in a secured place!
  • 39. AWS partner solutions extend & enhance security • Some examples: – Cisco CSR (VPN) – Sophos UTM (firewall, …) – Alert Logic Web Security Manager (WAF) – Alert Logic Threat Manager (NIDS) – Trend Micro Deep Security (IDPS) – Trend Micro SecureCloud (encryption) – Dome9 SecOps (security group audit & management) – …