SlideShare a Scribd company logo
1 of 15
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Jason Lee
Iron Patriot Chief Architect, Lockheed Martin Space
David English, Mission Solutions Chief Engineer, Lockheed Martin Space
v1.0
Getting on C2S: Lessons Learned
Migrating Space Operational Systems
to the Cloud on AWS
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Lockheed Martin Space
Special
ProgramsAdvanced Technology Center
Optics, RF
& Photonics
Adv. Materials
& Nano
Systems
Space Sciences
& Instruments
Military Space
Protected
Comms
Narrowband
Comms
Early
Warning
Navigation Weather Space
Protection
Strategic & Missile Defense
Missile DefenseStrategic MissilesAdv Programs
Mission Solutions
End-to-End
Mission
Systems
Geospatial
Technologies
SubsidiariesCommercial and Civil Space
Communication
Systems
Weather & Remote
Sensing
Deep Space
Exploration
Human Space
Exploration
NASA
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
LM Space Mission Solutions Delivers
•Scalable, Secure, High-Performance Systems on
AWS
•‘End-to-End’ Mission Solutions
•Satellite C2 and Sensor Data Processing
•Predictive Analytics and Big Data Applications
•Systems and Software Engineering
•Geospatial Technologies
•Space Security / System Resiliency
Mission-critical intelligence and information across a secure global network
Systems Designed, Developed, Engineered and Operated from the Ground Up
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
LM Perspective: The Value of the Cloud
Scalability:
• Perform missions with highly variable
processing needs using an efficient cost
structure
• Add missions on tight timelines
• Vertically or horizontally scale as missions
change
Resilience:
• Deploy highly available software systems with
failover between AWS availability zones and
regions
• Ability to build and deliver always-running
services with zero downtime
Security:
• AWS provides the tools to build to the security level required by the
mission
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer Mandate: Move to the Cloud
Timeline:
• 2014: Customer begins transition to
the cloud.
• 2015/2016: Initial path-finder efforts
• 2017: First Production Systems
• 2018: Most RFPs are mandating
Cloud
Initial Roadblocks:
• Access
• Contract Scope
• Customer Understanding
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Case: C2S Migration of a Product Quality System
Challenges
• Migration of over 50 different product quality assessment applications
• Move from desktop apps to cloud
• Various CPU architectures and operating systems
• Many tools require GPU capabilities
Solutions
• Linux and Windows AMIs with tools pre-installed
• Auto-scaled servers using ELB, serving up user desktops
• Custom CloudWatch metrics for users per server
• Held AWS well-architected review (first for customer)
• Invest in internal AWS training and expertise
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Case: C2S Migration of a Multi-Level Security System
Challenges
• Motivated to move to C2S for elasticity, but security requirements were
above what C2S provided natively
• Needed to protected data in all phases (motion, rest, use) within the
VPC
• Contractor-provided security enhancements were needed to augment
native AWS security
Solutions
• Utilized the VPC, EC2, and EBS services for hosting and fault-
tolerance
• Avoided use of other services, such as SQS, SNS, RDS, Kinesis, and
EMR, so that security requirements could be met
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Case: C2S Migration of a Processing System
Challenges
• Could not afford down-time for legacy mission critical
system to stop and move to cloud
• Hybrid approach introduced bandwidth as a limiting factor,
including the intricacies of networking between Government
segments
Solutions
• Hybrid approach became most effective (keep processing
on-premise, but also flip some to cloud)
• Acquire the necessary Direct Connects for the needed
bandwidth
• Fully map the Government segment network topography to
understand the bandwidth issues completely
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Lesson Learned #1: Security Policy and Controls
Issue: Customer Security Controls
• Security controls needs to be examined for each AWS service
• Customer stance evolving; data and mission specific
Solution
• Understand underlying AWS service security stand
• Prepare standard approaches per service
• Customer lessons learned session
• Work with Amazon Solutions architects
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Lesson Learned #2: Security Controls
Issue: Customer Security Policy
• Evolving from facility-based
• Amount of changing systems – work backlog for customer
• Re-examine security controls
• Transition from ICD 503 to risk management framework (RMF)
Solution
• Security-focused software engineers
• Learn with the customer
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Lesson Learned #3: Bandwidth to The Cloud
Issue: Remote users or data and planning bandwidth
• Cloud moves compute away from users or data generation
• Network are evolving to meet additional bandwidth, reliability
needs
Solution
• Early engagement with customer
Networks team
• Understand timelines, latencies, and
resiliency levels
• Customers have advanced the
capability to use Direct Connect
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Lesson Learned #4: Cost Monitoring
Issue: Understanding and planning for operational costs
• Legacy architecture may have inefficient compute usage
• Development and Test resource environments can get expensive
Solution
• Use Cost Explorer + an enforced tagging policy
• Scripts and tools that enforce tagging policy
• Use cost information to target architecture areas for improvement
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Lesson Learned #5: Transition Approaches
Issue: Traditional ‘big bang’ upgrades to C2S
• System transitions from legacy data center to C2S
• Transition is possible, but complex:
• More extensive testing
• Interface changeovers
• Complex failback
Solution
• Incrementally move capabilities
• Use as opportunity to transform architecture
• The Cloud becomes a part of the system boundary
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Questions?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank you!

More Related Content

What's hot

What's hot (20)

One Data Lake, Many Uses: Enable Multi-Tenant Analytics with Amazon EMR (ANT3...
One Data Lake, Many Uses: Enable Multi-Tenant Analytics with Amazon EMR (ANT3...One Data Lake, Many Uses: Enable Multi-Tenant Analytics with Amazon EMR (ANT3...
One Data Lake, Many Uses: Enable Multi-Tenant Analytics with Amazon EMR (ANT3...
 
Google Cloud Storage | Google Cloud Platform Tutorial | Google Cloud Architec...
Google Cloud Storage | Google Cloud Platform Tutorial | Google Cloud Architec...Google Cloud Storage | Google Cloud Platform Tutorial | Google Cloud Architec...
Google Cloud Storage | Google Cloud Platform Tutorial | Google Cloud Architec...
 
Customer Experience at Disney+ Through Data Perspective
Customer Experience at Disney+ Through Data PerspectiveCustomer Experience at Disney+ Through Data Perspective
Customer Experience at Disney+ Through Data Perspective
 
Customer experience at disney+ through data perspective
Customer experience at disney+ through data perspectiveCustomer experience at disney+ through data perspective
Customer experience at disney+ through data perspective
 
How Workato creates robust data pipelines and automations for you?
How Workato creates robust data pipelines and automations for you?How Workato creates robust data pipelines and automations for you?
How Workato creates robust data pipelines and automations for you?
 
Building Advanced Workflows with AWS Glue (ANT372) - AWS re:Invent 2018
Building Advanced Workflows with AWS Glue (ANT372) - AWS re:Invent 2018Building Advanced Workflows with AWS Glue (ANT372) - AWS re:Invent 2018
Building Advanced Workflows with AWS Glue (ANT372) - AWS re:Invent 2018
 
Effective Data Lakes: Challenges and Design Patterns (ANT316) - AWS re:Invent...
Effective Data Lakes: Challenges and Design Patterns (ANT316) - AWS re:Invent...Effective Data Lakes: Challenges and Design Patterns (ANT316) - AWS re:Invent...
Effective Data Lakes: Challenges and Design Patterns (ANT316) - AWS re:Invent...
 
#EarthOnAWS | AWS Public Sector Summit 2017
#EarthOnAWS | AWS Public Sector Summit 2017#EarthOnAWS | AWS Public Sector Summit 2017
#EarthOnAWS | AWS Public Sector Summit 2017
 
Using data lakes to quench your analytics fire - AWS Summit Cape Town 2018
Using data lakes to quench your analytics fire - AWS Summit Cape Town 2018Using data lakes to quench your analytics fire - AWS Summit Cape Town 2018
Using data lakes to quench your analytics fire - AWS Summit Cape Town 2018
 
Build on Amazon Aurora with MySQL Compatibility (DAT348-R4) - AWS re:Invent 2018
Build on Amazon Aurora with MySQL Compatibility (DAT348-R4) - AWS re:Invent 2018Build on Amazon Aurora with MySQL Compatibility (DAT348-R4) - AWS re:Invent 2018
Build on Amazon Aurora with MySQL Compatibility (DAT348-R4) - AWS re:Invent 2018
 
Analyzing Streams
Analyzing StreamsAnalyzing Streams
Analyzing Streams
 
Building Serverless Analytics Pipelines with AWS Glue (ANT308) - AWS re:Inven...
Building Serverless Analytics Pipelines with AWS Glue (ANT308) - AWS re:Inven...Building Serverless Analytics Pipelines with AWS Glue (ANT308) - AWS re:Inven...
Building Serverless Analytics Pipelines with AWS Glue (ANT308) - AWS re:Inven...
 
Leadership Session: AWS Database and Analytics (DAT206-L) - AWS re:Invent 2018
Leadership Session: AWS Database and Analytics (DAT206-L) - AWS re:Invent 2018Leadership Session: AWS Database and Analytics (DAT206-L) - AWS re:Invent 2018
Leadership Session: AWS Database and Analytics (DAT206-L) - AWS re:Invent 2018
 
Building Advanced Workflows with AWS Glue (ANT333) - AWS re:Invent 2018
Building Advanced Workflows with AWS Glue (ANT333) - AWS re:Invent 2018Building Advanced Workflows with AWS Glue (ANT333) - AWS re:Invent 2018
Building Advanced Workflows with AWS Glue (ANT333) - AWS re:Invent 2018
 
Data Warehouses and Data Lakes
Data Warehouses and Data LakesData Warehouses and Data Lakes
Data Warehouses and Data Lakes
 
What's New with Amazon Redshift ft. Dow Jones (ANT350-R) - AWS re:Invent 2018
What's New with Amazon Redshift ft. Dow Jones (ANT350-R) - AWS re:Invent 2018What's New with Amazon Redshift ft. Dow Jones (ANT350-R) - AWS re:Invent 2018
What's New with Amazon Redshift ft. Dow Jones (ANT350-R) - AWS re:Invent 2018
 
The Open Data Lake Platform Brief - Data Sheets | Whitepaper
The Open Data Lake Platform Brief - Data Sheets | WhitepaperThe Open Data Lake Platform Brief - Data Sheets | Whitepaper
The Open Data Lake Platform Brief - Data Sheets | Whitepaper
 
Building Data Lakes That Cost Less and Deliver Results Faster - AWS Online Te...
Building Data Lakes That Cost Less and Deliver Results Faster - AWS Online Te...Building Data Lakes That Cost Less and Deliver Results Faster - AWS Online Te...
Building Data Lakes That Cost Less and Deliver Results Faster - AWS Online Te...
 
How One Growing U.S. County Protects Residents' Data on AWS
 How One Growing U.S. County Protects Residents' Data on AWS How One Growing U.S. County Protects Residents' Data on AWS
How One Growing U.S. County Protects Residents' Data on AWS
 
Google App Engine
Google App EngineGoogle App Engine
Google App Engine
 

Similar to Getting on C2S: Lessons Learned Migrating Space Operational Systems to the Cloud on AWS

Similar to Getting on C2S: Lessons Learned Migrating Space Operational Systems to the Cloud on AWS (20)

Migrating Legacy Applications to AWS Cloud: Strategies and Challenges
Migrating Legacy Applications to AWS Cloud: Strategies and ChallengesMigrating Legacy Applications to AWS Cloud: Strategies and Challenges
Migrating Legacy Applications to AWS Cloud: Strategies and Challenges
 
Gitex journey to the cloud
Gitex journey to the cloudGitex journey to the cloud
Gitex journey to the cloud
 
Distributed Solar Systems at EDF Renewables and AWS IoT: A Natural Fit (PUT30...
Distributed Solar Systems at EDF Renewables and AWS IoT: A Natural Fit (PUT30...Distributed Solar Systems at EDF Renewables and AWS IoT: A Natural Fit (PUT30...
Distributed Solar Systems at EDF Renewables and AWS IoT: A Natural Fit (PUT30...
 
Cloud Migration - CCS Technologies (P) Ltd.
Cloud Migration - CCS Technologies (P) Ltd.Cloud Migration - CCS Technologies (P) Ltd.
Cloud Migration - CCS Technologies (P) Ltd.
 
Mythbusting the Federal Cloud Journey
Mythbusting the Federal Cloud JourneyMythbusting the Federal Cloud Journey
Mythbusting the Federal Cloud Journey
 
Cloud migration presentation
Cloud migration presentationCloud migration presentation
Cloud migration presentation
 
Ask The Architect: RightScale & AWS Dive Deep into Hybrid IT
Ask The Architect: RightScale & AWS Dive Deep into Hybrid ITAsk The Architect: RightScale & AWS Dive Deep into Hybrid IT
Ask The Architect: RightScale & AWS Dive Deep into Hybrid IT
 
Applying systems thinking to AWS enterprise application migration
Applying systems thinking to AWS enterprise application migrationApplying systems thinking to AWS enterprise application migration
Applying systems thinking to AWS enterprise application migration
 
Migrating Your Windows Datacenter to AWS
Migrating Your Windows Datacenter to AWSMigrating Your Windows Datacenter to AWS
Migrating Your Windows Datacenter to AWS
 
Critical Considerations for Moving Your Core Business Applications to the Clo...
Critical Considerations for Moving Your Core Business Applications to the Clo...Critical Considerations for Moving Your Core Business Applications to the Clo...
Critical Considerations for Moving Your Core Business Applications to the Clo...
 
Migration Recipes for Success - AWS Summit Cape Town 2017
Migration Recipes for Success - AWS Summit Cape Town 2017 Migration Recipes for Success - AWS Summit Cape Town 2017
Migration Recipes for Success - AWS Summit Cape Town 2017
 
Who Broke My Cloud? SaaS Monitoring Best Practices
Who Broke My Cloud? SaaS Monitoring Best PracticesWho Broke My Cloud? SaaS Monitoring Best Practices
Who Broke My Cloud? SaaS Monitoring Best Practices
 
AWS Business Essentials Day
AWS Business Essentials DayAWS Business Essentials Day
AWS Business Essentials Day
 
Risc and velostrata 2 28 2018 lessons_in_cloud_migration
Risc and velostrata  2 28 2018 lessons_in_cloud_migrationRisc and velostrata  2 28 2018 lessons_in_cloud_migration
Risc and velostrata 2 28 2018 lessons_in_cloud_migration
 
Stefan Haase Cloud
Stefan Haase CloudStefan Haase Cloud
Stefan Haase Cloud
 
(ENT202) Four Critical Things to Consider When Moving Your Core Business Appl...
(ENT202) Four Critical Things to Consider When Moving Your Core Business Appl...(ENT202) Four Critical Things to Consider When Moving Your Core Business Appl...
(ENT202) Four Critical Things to Consider When Moving Your Core Business Appl...
 
Embracing Cloud in a Traditional Data Center
Embracing Cloud in a Traditional Data CenterEmbracing Cloud in a Traditional Data Center
Embracing Cloud in a Traditional Data Center
 
AWS e-Zest Cloud Event 2013 - AWS for Enterprises
AWS e-Zest Cloud Event 2013 - AWS for EnterprisesAWS e-Zest Cloud Event 2013 - AWS for Enterprises
AWS e-Zest Cloud Event 2013 - AWS for Enterprises
 
What is cloud
What is cloudWhat is cloud
What is cloud
 
Univa Presentation at DAC 2020
Univa Presentation at DAC 2020 Univa Presentation at DAC 2020
Univa Presentation at DAC 2020
 

More from Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Getting on C2S: Lessons Learned Migrating Space Operational Systems to the Cloud on AWS

  • 1. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Jason Lee Iron Patriot Chief Architect, Lockheed Martin Space David English, Mission Solutions Chief Engineer, Lockheed Martin Space v1.0 Getting on C2S: Lessons Learned Migrating Space Operational Systems to the Cloud on AWS
  • 2. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Lockheed Martin Space Special ProgramsAdvanced Technology Center Optics, RF & Photonics Adv. Materials & Nano Systems Space Sciences & Instruments Military Space Protected Comms Narrowband Comms Early Warning Navigation Weather Space Protection Strategic & Missile Defense Missile DefenseStrategic MissilesAdv Programs Mission Solutions End-to-End Mission Systems Geospatial Technologies SubsidiariesCommercial and Civil Space Communication Systems Weather & Remote Sensing Deep Space Exploration Human Space Exploration NASA
  • 3. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. LM Space Mission Solutions Delivers •Scalable, Secure, High-Performance Systems on AWS •‘End-to-End’ Mission Solutions •Satellite C2 and Sensor Data Processing •Predictive Analytics and Big Data Applications •Systems and Software Engineering •Geospatial Technologies •Space Security / System Resiliency Mission-critical intelligence and information across a secure global network Systems Designed, Developed, Engineered and Operated from the Ground Up
  • 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. LM Perspective: The Value of the Cloud Scalability: • Perform missions with highly variable processing needs using an efficient cost structure • Add missions on tight timelines • Vertically or horizontally scale as missions change Resilience: • Deploy highly available software systems with failover between AWS availability zones and regions • Ability to build and deliver always-running services with zero downtime Security: • AWS provides the tools to build to the security level required by the mission
  • 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer Mandate: Move to the Cloud Timeline: • 2014: Customer begins transition to the cloud. • 2015/2016: Initial path-finder efforts • 2017: First Production Systems • 2018: Most RFPs are mandating Cloud Initial Roadblocks: • Access • Contract Scope • Customer Understanding
  • 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Case: C2S Migration of a Product Quality System Challenges • Migration of over 50 different product quality assessment applications • Move from desktop apps to cloud • Various CPU architectures and operating systems • Many tools require GPU capabilities Solutions • Linux and Windows AMIs with tools pre-installed • Auto-scaled servers using ELB, serving up user desktops • Custom CloudWatch metrics for users per server • Held AWS well-architected review (first for customer) • Invest in internal AWS training and expertise
  • 7. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Case: C2S Migration of a Multi-Level Security System Challenges • Motivated to move to C2S for elasticity, but security requirements were above what C2S provided natively • Needed to protected data in all phases (motion, rest, use) within the VPC • Contractor-provided security enhancements were needed to augment native AWS security Solutions • Utilized the VPC, EC2, and EBS services for hosting and fault- tolerance • Avoided use of other services, such as SQS, SNS, RDS, Kinesis, and EMR, so that security requirements could be met
  • 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Case: C2S Migration of a Processing System Challenges • Could not afford down-time for legacy mission critical system to stop and move to cloud • Hybrid approach introduced bandwidth as a limiting factor, including the intricacies of networking between Government segments Solutions • Hybrid approach became most effective (keep processing on-premise, but also flip some to cloud) • Acquire the necessary Direct Connects for the needed bandwidth • Fully map the Government segment network topography to understand the bandwidth issues completely
  • 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Lesson Learned #1: Security Policy and Controls Issue: Customer Security Controls • Security controls needs to be examined for each AWS service • Customer stance evolving; data and mission specific Solution • Understand underlying AWS service security stand • Prepare standard approaches per service • Customer lessons learned session • Work with Amazon Solutions architects
  • 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Lesson Learned #2: Security Controls Issue: Customer Security Policy • Evolving from facility-based • Amount of changing systems – work backlog for customer • Re-examine security controls • Transition from ICD 503 to risk management framework (RMF) Solution • Security-focused software engineers • Learn with the customer
  • 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Lesson Learned #3: Bandwidth to The Cloud Issue: Remote users or data and planning bandwidth • Cloud moves compute away from users or data generation • Network are evolving to meet additional bandwidth, reliability needs Solution • Early engagement with customer Networks team • Understand timelines, latencies, and resiliency levels • Customers have advanced the capability to use Direct Connect
  • 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Lesson Learned #4: Cost Monitoring Issue: Understanding and planning for operational costs • Legacy architecture may have inefficient compute usage • Development and Test resource environments can get expensive Solution • Use Cost Explorer + an enforced tagging policy • Scripts and tools that enforce tagging policy • Use cost information to target architecture areas for improvement
  • 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Lesson Learned #5: Transition Approaches Issue: Traditional ‘big bang’ upgrades to C2S • System transitions from legacy data center to C2S • Transition is possible, but complex: • More extensive testing • Interface changeovers • Complex failback Solution • Incrementally move capabilities • Use as opportunity to transform architecture • The Cloud becomes a part of the system boundary
  • 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Questions?
  • 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Thank you!