SlideShare a Scribd company logo
1 of 22
Download to read offline
© 2015, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Mark Ryland (markry@), Director of Solutions Architecture, WWPS
Alan Halachmi (halachmi@), Principal Solutions Architect, WWPS
October 2015
ISM206
Modern IT Governance Through
Transparency and Automation
IT governance: high-level definition
• “The leadership, organizational structures, and
processes to ensure that the organization's IT
sustains and extends the organization's
strategies and objectives.”
→IT Governance Institute
Where does governance sit?
• Part of a larger complex of GRC(S): governance, risk
management, compliance/security
• Compliance (policy) and security (implementation) are shared
responsibilities on AWS
• Risk management (balancing of risks and benefits) is a
strategic requirement and responsibility
• Governance: high level category encompassing all required
policies and practices that assure safe and sane usage of IT
• Governance is your responsibility, with help from AWS tools
and capabilities
Key governance questions
• What do I have?
• How it is performing?
• Who is controlling it?
• What is it costing me?
• Is it secure and compliant?
• Are changes occurring with the right processes and
protections?
AWS and governance
• AWS capabilities and services provide key building
blocks for systems that answer these questions
• Better answers than ever before in traditional
infrastructure
• Integration challenges remain, but don’t be constrained
by on-prem systems when leveraging the cloud
What do I have?
• Describe* calls provide comprehensive lists of all
resources (for example, aws ec2 describe-instances)
• AWS Config provides graph-based integration, time-
based insights
• (Building a comprehensive, accurate configuration DB on-
premises is practically impossible)
• AWS Config Rules to evaluate changes and respond
• Partner ecosystem adds more value, richer capabilities
• Theme: AWS provides data feeds, anyone can build tooling
How is it performing?
• Services emit metrics into Amazon CloudWatch
• Accessible through console, CLI, API
• Alerting and alarming on all metrical data
• Amazon CloudWatch Logs integrates OS and app log data
• AWS Elastic Search automates the pooling, querying, and
visualization of CW Logs
• Rich integration of both CW and CWL w/ Simple Notification Service
• AWS Trusted Advisor (TA) for dashboard and alerts for under-
utilization, security, availability issues
• Rich integration into third-party monitoring platforms from
AWS partners
Who is controlling it?
• Powerful, fine-grained AWS Identity and Access
Management (IAM) capabilities
• Authentication and authorization
• Reporting and analysis
• Rich integration to enterprise identity systems
through SAML or directly into Active Directory
• Tagging for authorization, administration, billing
Cost transparency and control
• Everything billed by hour, gigabyte, etc.
• Billing data updated ~4x per day
• Programmatic access to all billing data
linked to user-created resource tags
• Cost Explorer and other tooling
• CloudWatch tools/alarms for billing data
• AWS MarketPlace helps with software
license management challenges
Secure and compliant?...
• … Are changes occurring with the right processes and
protections?
• AWS infrastructure: yes
• See frequently updated third-party audits
• Customer usage: get to yes like never before
• Great tools and building blocks to build the right models,
processes, and automation
Tools and building blocks
• Trusted Advisor displays obvious (possible) issues
• CloudWatch (Logs), VPC Flow Logs, Amazon S3 logs, Elastic
Load Balancing logs
• AWS Elasticsearch Service for managed search, analysis, visualization
• AWS CloudTrail, Config, and Config Rules, Inspector
• VPC peering (including cross-account)
• Identity federation and cross-account role-based access
• AWS Service Catalog/AWS CloudFormation for repeatable
processes
• GoldBase: pre-audited layers w/ automation framework for
completely compliant environments (demo coming)
Customer’s horizontal shared responsibility
• Mission teams control their own infrastructure (VPCs,
instances, Amazon Machine Images (AMIs), databases,
S3 buckets, etc.)
• Central GRC/security team has audit and control rights
over core infrastructure along with “shared security &
compliance services”
• Best of both worlds: agility benefits of mission-driven
“shadow IT,” governance/security benefits of central IT
control
Concretely: Managed Services Organization (MSO)
• Central team providing shared services:
• Account creation and AWS IAM provisioning/setup
• Identity management, federation endpoints
• Core networking security and IAM policies
• Golden OS images (AMIs), associated IAM limits
• Central auditing services
• CloudTrail, Config, security log management
• Incident response/forensics services
• Cost alarm/review/auditing services
Demo: scenario
• Development Team requires:
• Direct access to AWS Management Console
• On-demand provisioning of dev environments
• Login credentials for running instances
• Support for continuous integration and deployment
• Company requires:
• Adherence to approved reference architectures
• Auditability of activities within the account and instances
• Visibility to resources used and network traffic flow
• Control of the account, VPCs, and instances
Demo: automating governance
• Company creates a Managed Services Organization (MSO)
• Delivers the implementation piece of
the governance puzzle
• Provides automated, self-service
delivery of approved architectures
• Maintains centralized control of
accounts, security oversight
• Leverages AWS GoldBase
Demonstration: target architecture
Demo [screen capture video]
Automate, automate, automate
• Programmable infrastructure changes everything!
• Service Catalog, AWS CloudFormation, APIs for everything at
the infrastructure level
• For apps, AWS Elastic Beanstalk, AWS OpsWorks, AWS
CodeDeploy, AWS CodePipeline
• Visibility and control via
• Manage everything (including security and compliance) using
SDL from a source code repository
• Security and compliance baked in to your continuous
integration/continuous deployment pipeline
It’s happening!
• Not a pipe dream, but a growing reality at enterprises
and agencies around the globe
• Even security-conscious government agencies like USA
Dept of Homeland Security (Citizenship and Immigration
Services)
• Mark Schwartz, CIO: https://youtu.be/QwHVlJtqhaI
• DevOps and CI/CD on the AWS cloud providing dev/ops
CI/CD agility with baked-in governance and security
benefits
Relevant upcoming sessions
• SEC314: AWS Config: Using Visibility to Improve Governance over
Configuration Changes to Your ResourcesSEC318: AWS CloudTrail Deep
Dive
• SEC403: Timely Security Alerts and Analytics: Diving into AWS CloudTrail Events
by Using Apache Spark on Amazon EMR
• SEC321: AWS for the Enterprise—Implementing Policy, Governance, and
Security for Enterprise Workloads
• SEC307: A Progressive Journey Through AWS IAM Federation Options:
From Roles to SAML to Custom Identity Brokers
• SEC316: Harden Your Architecture with Security Incident Response
Simulations (SIRS)
• DVO206L: Lessons from a CISO: How to Securely Scale Teams,
Workloads, and Budgets
Thank you!
Mark Ryland (markry@amazon.com)
Alan Halachmi (halachmi@amazon.com)
Remember to complete
your evaluations!

More Related Content

What's hot

NASA Goddard: Head in the Clouds
NASA Goddard: Head in the CloudsNASA Goddard: Head in the Clouds
NASA Goddard: Head in the CloudsAmazon Web Services
 
Big Data in The Cloud: Architecting a Better Platform
Big Data in The Cloud: Architecting a Better PlatformBig Data in The Cloud: Architecting a Better Platform
Big Data in The Cloud: Architecting a Better PlatformAmazon Web Services
 
Enterprise Cloud Adoption Strategies in Higher Education
Enterprise Cloud Adoption Strategies in Higher EducationEnterprise Cloud Adoption Strategies in Higher Education
Enterprise Cloud Adoption Strategies in Higher EducationAmazon Web Services
 
Citizen Services: The New Mission Critical Apps
Citizen Services: The New Mission Critical AppsCitizen Services: The New Mission Critical Apps
Citizen Services: The New Mission Critical AppsAmazon Web Services
 
Acquisition Strategies and Contract Vehicles in the Public Sector
Acquisition Strategies and Contract Vehicles in the Public SectorAcquisition Strategies and Contract Vehicles in the Public Sector
Acquisition Strategies and Contract Vehicles in the Public SectorAmazon Web Services
 
1 cloud-transformation-strategies 062615.final
1  cloud-transformation-strategies 062615.final1  cloud-transformation-strategies 062615.final
1 cloud-transformation-strategies 062615.finalAmazon Web Services
 
Scaling by Design: AWS Web Services Patterns
Scaling by Design:AWS Web Services PatternsScaling by Design:AWS Web Services Patterns
Scaling by Design: AWS Web Services PatternsAmazon Web Services
 
Disaster Recovery in the Cloud: A Case Study - AWS Washington D.C. Symposium ...
Disaster Recovery in the Cloud: A Case Study - AWS Washington D.C. Symposium ...Disaster Recovery in the Cloud: A Case Study - AWS Washington D.C. Symposium ...
Disaster Recovery in the Cloud: A Case Study - AWS Washington D.C. Symposium ...Amazon Web Services
 
How Public Sector Entities are Advancing Their Security and Governance Capabi...
How Public Sector Entities are Advancing Their Security and Governance Capabi...How Public Sector Entities are Advancing Their Security and Governance Capabi...
How Public Sector Entities are Advancing Their Security and Governance Capabi...Amazon Web Services
 
3. 195883 open gis data slides jw_edit_js-mh
3. 195883 open gis data slides jw_edit_js-mh3. 195883 open gis data slides jw_edit_js-mh
3. 195883 open gis data slides jw_edit_js-mhAmazon Web Services
 
Driving Innovation with Open Data
Driving Innovation with Open DataDriving Innovation with Open Data
Driving Innovation with Open DataAmazon Web Services
 
GIS on AWS Deep Dive - AWS Symposium 2014 - Washington D.C.
GIS on AWS Deep Dive - AWS Symposium 2014 - Washington D.C. GIS on AWS Deep Dive - AWS Symposium 2014 - Washington D.C.
GIS on AWS Deep Dive - AWS Symposium 2014 - Washington D.C. Amazon Web Services
 
Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 -...
Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 -...Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 -...
Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 -...Amazon Web Services
 
Emind’s Architecture for AWS Integration
Emind’s Architecture for AWS IntegrationEmind’s Architecture for AWS Integration
Emind’s Architecture for AWS IntegrationMonica Rut Avellino
 
AWSome Day Indonesia Keynote 2015
AWSome Day Indonesia Keynote 2015AWSome Day Indonesia Keynote 2015
AWSome Day Indonesia Keynote 2015Hwee Bee Tan
 

What's hot (19)

AWS GovCloud (US) - An Overview
AWS GovCloud (US) - An OverviewAWS GovCloud (US) - An Overview
AWS GovCloud (US) - An Overview
 
NASA Goddard: Head in the Clouds
NASA Goddard: Head in the CloudsNASA Goddard: Head in the Clouds
NASA Goddard: Head in the Clouds
 
Big Data in The Cloud: Architecting a Better Platform
Big Data in The Cloud: Architecting a Better PlatformBig Data in The Cloud: Architecting a Better Platform
Big Data in The Cloud: Architecting a Better Platform
 
Enterprise Cloud Adoption Strategies in Higher Education
Enterprise Cloud Adoption Strategies in Higher EducationEnterprise Cloud Adoption Strategies in Higher Education
Enterprise Cloud Adoption Strategies in Higher Education
 
Citizen Services: The New Mission Critical Apps
Citizen Services: The New Mission Critical AppsCitizen Services: The New Mission Critical Apps
Citizen Services: The New Mission Critical Apps
 
Acquisition Strategies and Contract Vehicles in the Public Sector
Acquisition Strategies and Contract Vehicles in the Public SectorAcquisition Strategies and Contract Vehicles in the Public Sector
Acquisition Strategies and Contract Vehicles in the Public Sector
 
1 cloud-transformation-strategies 062615.final
1  cloud-transformation-strategies 062615.final1  cloud-transformation-strategies 062615.final
1 cloud-transformation-strategies 062615.final
 
Scaling by Design: AWS Web Services Patterns
Scaling by Design:AWS Web Services PatternsScaling by Design:AWS Web Services Patterns
Scaling by Design: AWS Web Services Patterns
 
Disaster Recovery in the Cloud: A Case Study - AWS Washington D.C. Symposium ...
Disaster Recovery in the Cloud: A Case Study - AWS Washington D.C. Symposium ...Disaster Recovery in the Cloud: A Case Study - AWS Washington D.C. Symposium ...
Disaster Recovery in the Cloud: A Case Study - AWS Washington D.C. Symposium ...
 
How Public Sector Entities are Advancing Their Security and Governance Capabi...
How Public Sector Entities are Advancing Their Security and Governance Capabi...How Public Sector Entities are Advancing Their Security and Governance Capabi...
How Public Sector Entities are Advancing Their Security and Governance Capabi...
 
3. 195883 open gis data slides jw_edit_js-mh
3. 195883 open gis data slides jw_edit_js-mh3. 195883 open gis data slides jw_edit_js-mh
3. 195883 open gis data slides jw_edit_js-mh
 
Driving Innovation with Open Data
Driving Innovation with Open DataDriving Innovation with Open Data
Driving Innovation with Open Data
 
GIS on AWS Deep Dive - AWS Symposium 2014 - Washington D.C.
GIS on AWS Deep Dive - AWS Symposium 2014 - Washington D.C. GIS on AWS Deep Dive - AWS Symposium 2014 - Washington D.C.
GIS on AWS Deep Dive - AWS Symposium 2014 - Washington D.C.
 
AWS Marketplace
AWS MarketplaceAWS Marketplace
AWS Marketplace
 
Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 -...
Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 -...Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 -...
Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 -...
 
Data-Driven Civic Innovation
Data-Driven Civic InnovationData-Driven Civic Innovation
Data-Driven Civic Innovation
 
Emind’s Architecture for AWS Integration
Emind’s Architecture for AWS IntegrationEmind’s Architecture for AWS Integration
Emind’s Architecture for AWS Integration
 
AWS
AWSAWS
AWS
 
AWSome Day Indonesia Keynote 2015
AWSome Day Indonesia Keynote 2015AWSome Day Indonesia Keynote 2015
AWSome Day Indonesia Keynote 2015
 

Viewers also liked

IT Governance - Amazon.com
IT Governance - Amazon.comIT Governance - Amazon.com
IT Governance - Amazon.comErick Prajogo
 
Governance framework for e commerce
Governance framework for e commerceGovernance framework for e commerce
Governance framework for e commerceSachet Koul
 
Transparency for effective it governance v1.0
Transparency for effective it governance v1.0Transparency for effective it governance v1.0
Transparency for effective it governance v1.0Ahmed Buhazza
 
CDO Vision: Data Governance Priorities
CDO Vision: Data Governance PrioritiesCDO Vision: Data Governance Priorities
CDO Vision: Data Governance PrioritiesDATAVERSITY
 
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)Amazon Web Services
 
Automating Compliance Defense in the Cloud - September 2016 Webinar Series
Automating Compliance Defense in the Cloud - September 2016 Webinar SeriesAutomating Compliance Defense in the Cloud - September 2016 Webinar Series
Automating Compliance Defense in the Cloud - September 2016 Webinar SeriesAmazon Web Services
 
Role of HR Manager
Role of HR ManagerRole of HR Manager
Role of HR ManagerCreativeHRM
 

Viewers also liked (8)

IT Governance - Amazon.com
IT Governance - Amazon.comIT Governance - Amazon.com
IT Governance - Amazon.com
 
Governance framework for e commerce
Governance framework for e commerceGovernance framework for e commerce
Governance framework for e commerce
 
Transparency for effective it governance v1.0
Transparency for effective it governance v1.0Transparency for effective it governance v1.0
Transparency for effective it governance v1.0
 
CDO Vision: Data Governance Priorities
CDO Vision: Data Governance PrioritiesCDO Vision: Data Governance Priorities
CDO Vision: Data Governance Priorities
 
Fdx[1]
Fdx[1]Fdx[1]
Fdx[1]
 
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
 
Automating Compliance Defense in the Cloud - September 2016 Webinar Series
Automating Compliance Defense in the Cloud - September 2016 Webinar SeriesAutomating Compliance Defense in the Cloud - September 2016 Webinar Series
Automating Compliance Defense in the Cloud - September 2016 Webinar Series
 
Role of HR Manager
Role of HR ManagerRole of HR Manager
Role of HR Manager
 

Similar to (ISM206) Modern IT Governance Through Transparency and Automation

AWS Public Sector Symposium 2014 Canberra | Compliance and Governance on the ...
AWS Public Sector Symposium 2014 Canberra | Compliance and Governance on the ...AWS Public Sector Symposium 2014 Canberra | Compliance and Governance on the ...
AWS Public Sector Symposium 2014 Canberra | Compliance and Governance on the ...Amazon Web Services
 
AWS Webcast - Understanding the AWS Security Model
AWS Webcast - Understanding the AWS Security ModelAWS Webcast - Understanding the AWS Security Model
AWS Webcast - Understanding the AWS Security ModelAmazon Web Services
 
Best Practices for Security at Scale
Best Practices for Security at ScaleBest Practices for Security at Scale
Best Practices for Security at ScaleAmazon Web Services
 
Blue Chip Tek Connect and Protect Presentation #3
Blue Chip Tek Connect and Protect Presentation #3Blue Chip Tek Connect and Protect Presentation #3
Blue Chip Tek Connect and Protect Presentation #3Kimberly Macias
 
Simplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing ZoneSimplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing ZoneAmazon Web Services
 
Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017Amazon Web Services
 
AWS re:Invent 2016: Automating and Scaling Infrastructure Administration with...
AWS re:Invent 2016: Automating and Scaling Infrastructure Administration with...AWS re:Invent 2016: Automating and Scaling Infrastructure Administration with...
AWS re:Invent 2016: Automating and Scaling Infrastructure Administration with...Amazon Web Services
 
8 Elements of Multi-Cloud Security
8 Elements of Multi-Cloud Security8 Elements of Multi-Cloud Security
8 Elements of Multi-Cloud SecurityRightScale
 
Automated Compliance and Governance with AWS Config and AWS CloudTrail - June...
Automated Compliance and Governance with AWS Config and AWS CloudTrail - June...Automated Compliance and Governance with AWS Config and AWS CloudTrail - June...
Automated Compliance and Governance with AWS Config and AWS CloudTrail - June...Amazon Web Services
 
The Automation of Supervision Governance in the Cloud
The Automation of Supervision Governance in the CloudThe Automation of Supervision Governance in the Cloud
The Automation of Supervision Governance in the CloudAmazon Web Services
 
Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...
Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...
Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...Amazon Web Services
 
Security and Compliance Better on AWS_John Hildebrandt
Security and Compliance Better on AWS_John HildebrandtSecurity and Compliance Better on AWS_John Hildebrandt
Security and Compliance Better on AWS_John HildebrandtHelen Rogers
 
Modern Security and Compliance Through Automation
Modern Security and Compliance Through AutomationModern Security and Compliance Through Automation
Modern Security and Compliance Through AutomationAmazon Web Services
 
5 minutes on security
5 minutes on security5 minutes on security
5 minutes on securityCloudHesive
 
AWS Canberra WWPS Summit 2013 - AWS Governance and Security Overview
AWS Canberra WWPS Summit 2013 - AWS Governance and Security OverviewAWS Canberra WWPS Summit 2013 - AWS Governance and Security Overview
AWS Canberra WWPS Summit 2013 - AWS Governance and Security OverviewAmazon Web Services
 
AWS Finland User Group Meetup 2017-05-23
AWS Finland User Group Meetup 2017-05-23AWS Finland User Group Meetup 2017-05-23
AWS Finland User Group Meetup 2017-05-23Rolf Koski
 

Similar to (ISM206) Modern IT Governance Through Transparency and Automation (20)

AWS Public Sector Symposium 2014 Canberra | Compliance and Governance on the ...
AWS Public Sector Symposium 2014 Canberra | Compliance and Governance on the ...AWS Public Sector Symposium 2014 Canberra | Compliance and Governance on the ...
AWS Public Sector Symposium 2014 Canberra | Compliance and Governance on the ...
 
Benefits of Cloud Computing
Benefits of Cloud ComputingBenefits of Cloud Computing
Benefits of Cloud Computing
 
AWS Webcast - Understanding the AWS Security Model
AWS Webcast - Understanding the AWS Security ModelAWS Webcast - Understanding the AWS Security Model
AWS Webcast - Understanding the AWS Security Model
 
Governance at Scale
Governance at Scale Governance at Scale
Governance at Scale
 
Best Practices for Security at Scale
Best Practices for Security at ScaleBest Practices for Security at Scale
Best Practices for Security at Scale
 
Blue Chip Tek Connect and Protect Presentation #3
Blue Chip Tek Connect and Protect Presentation #3Blue Chip Tek Connect and Protect Presentation #3
Blue Chip Tek Connect and Protect Presentation #3
 
Simplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing ZoneSimplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing Zone
 
Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
 
AWS re:Invent 2016: Automating and Scaling Infrastructure Administration with...
AWS re:Invent 2016: Automating and Scaling Infrastructure Administration with...AWS re:Invent 2016: Automating and Scaling Infrastructure Administration with...
AWS re:Invent 2016: Automating and Scaling Infrastructure Administration with...
 
8 Elements of Multi-Cloud Security
8 Elements of Multi-Cloud Security8 Elements of Multi-Cloud Security
8 Elements of Multi-Cloud Security
 
Automated Compliance and Governance with AWS Config and AWS CloudTrail - June...
Automated Compliance and Governance with AWS Config and AWS CloudTrail - June...Automated Compliance and Governance with AWS Config and AWS CloudTrail - June...
Automated Compliance and Governance with AWS Config and AWS CloudTrail - June...
 
The Automation of Supervision Governance in the Cloud
The Automation of Supervision Governance in the CloudThe Automation of Supervision Governance in the Cloud
The Automation of Supervision Governance in the Cloud
 
Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...
Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...
Using AWS CloudTrail and AWS Config to Enhance the Governance and Compliance ...
 
Security and Compliance Better on AWS_John Hildebrandt
Security and Compliance Better on AWS_John HildebrandtSecurity and Compliance Better on AWS_John Hildebrandt
Security and Compliance Better on AWS_John Hildebrandt
 
Modern Security and Compliance Through Automation
Modern Security and Compliance Through AutomationModern Security and Compliance Through Automation
Modern Security and Compliance Through Automation
 
5 minutes on security
5 minutes on security5 minutes on security
5 minutes on security
 
AWS Canberra WWPS Summit 2013 - AWS Governance and Security Overview
AWS Canberra WWPS Summit 2013 - AWS Governance and Security OverviewAWS Canberra WWPS Summit 2013 - AWS Governance and Security Overview
AWS Canberra WWPS Summit 2013 - AWS Governance and Security Overview
 
Intro & Security Update
Intro & Security UpdateIntro & Security Update
Intro & Security Update
 
Security & Compliance (Part 2)
Security & Compliance (Part 2)Security & Compliance (Part 2)
Security & Compliance (Part 2)
 
AWS Finland User Group Meetup 2017-05-23
AWS Finland User Group Meetup 2017-05-23AWS Finland User Group Meetup 2017-05-23
AWS Finland User Group Meetup 2017-05-23
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Recently uploaded

Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfOrbitshub
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingEdi Saputra
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Zilliz
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 

Recently uploaded (20)

Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
Emergent Methods: Multi-lingual narrative tracking in the news - real-time ex...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 

(ISM206) Modern IT Governance Through Transparency and Automation

  • 1. © 2015, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Mark Ryland (markry@), Director of Solutions Architecture, WWPS Alan Halachmi (halachmi@), Principal Solutions Architect, WWPS October 2015 ISM206 Modern IT Governance Through Transparency and Automation
  • 2. IT governance: high-level definition • “The leadership, organizational structures, and processes to ensure that the organization's IT sustains and extends the organization's strategies and objectives.” →IT Governance Institute
  • 3. Where does governance sit? • Part of a larger complex of GRC(S): governance, risk management, compliance/security • Compliance (policy) and security (implementation) are shared responsibilities on AWS • Risk management (balancing of risks and benefits) is a strategic requirement and responsibility • Governance: high level category encompassing all required policies and practices that assure safe and sane usage of IT • Governance is your responsibility, with help from AWS tools and capabilities
  • 4. Key governance questions • What do I have? • How it is performing? • Who is controlling it? • What is it costing me? • Is it secure and compliant? • Are changes occurring with the right processes and protections?
  • 5. AWS and governance • AWS capabilities and services provide key building blocks for systems that answer these questions • Better answers than ever before in traditional infrastructure • Integration challenges remain, but don’t be constrained by on-prem systems when leveraging the cloud
  • 6. What do I have? • Describe* calls provide comprehensive lists of all resources (for example, aws ec2 describe-instances) • AWS Config provides graph-based integration, time- based insights • (Building a comprehensive, accurate configuration DB on- premises is practically impossible) • AWS Config Rules to evaluate changes and respond • Partner ecosystem adds more value, richer capabilities • Theme: AWS provides data feeds, anyone can build tooling
  • 7. How is it performing? • Services emit metrics into Amazon CloudWatch • Accessible through console, CLI, API • Alerting and alarming on all metrical data • Amazon CloudWatch Logs integrates OS and app log data • AWS Elastic Search automates the pooling, querying, and visualization of CW Logs • Rich integration of both CW and CWL w/ Simple Notification Service • AWS Trusted Advisor (TA) for dashboard and alerts for under- utilization, security, availability issues • Rich integration into third-party monitoring platforms from AWS partners
  • 8. Who is controlling it? • Powerful, fine-grained AWS Identity and Access Management (IAM) capabilities • Authentication and authorization • Reporting and analysis • Rich integration to enterprise identity systems through SAML or directly into Active Directory • Tagging for authorization, administration, billing
  • 9. Cost transparency and control • Everything billed by hour, gigabyte, etc. • Billing data updated ~4x per day • Programmatic access to all billing data linked to user-created resource tags • Cost Explorer and other tooling • CloudWatch tools/alarms for billing data • AWS MarketPlace helps with software license management challenges
  • 10. Secure and compliant?... • … Are changes occurring with the right processes and protections? • AWS infrastructure: yes • See frequently updated third-party audits • Customer usage: get to yes like never before • Great tools and building blocks to build the right models, processes, and automation
  • 11. Tools and building blocks • Trusted Advisor displays obvious (possible) issues • CloudWatch (Logs), VPC Flow Logs, Amazon S3 logs, Elastic Load Balancing logs • AWS Elasticsearch Service for managed search, analysis, visualization • AWS CloudTrail, Config, and Config Rules, Inspector • VPC peering (including cross-account) • Identity federation and cross-account role-based access • AWS Service Catalog/AWS CloudFormation for repeatable processes • GoldBase: pre-audited layers w/ automation framework for completely compliant environments (demo coming)
  • 12. Customer’s horizontal shared responsibility • Mission teams control their own infrastructure (VPCs, instances, Amazon Machine Images (AMIs), databases, S3 buckets, etc.) • Central GRC/security team has audit and control rights over core infrastructure along with “shared security & compliance services” • Best of both worlds: agility benefits of mission-driven “shadow IT,” governance/security benefits of central IT control
  • 13. Concretely: Managed Services Organization (MSO) • Central team providing shared services: • Account creation and AWS IAM provisioning/setup • Identity management, federation endpoints • Core networking security and IAM policies • Golden OS images (AMIs), associated IAM limits • Central auditing services • CloudTrail, Config, security log management • Incident response/forensics services • Cost alarm/review/auditing services
  • 14. Demo: scenario • Development Team requires: • Direct access to AWS Management Console • On-demand provisioning of dev environments • Login credentials for running instances • Support for continuous integration and deployment • Company requires: • Adherence to approved reference architectures • Auditability of activities within the account and instances • Visibility to resources used and network traffic flow • Control of the account, VPCs, and instances
  • 15. Demo: automating governance • Company creates a Managed Services Organization (MSO) • Delivers the implementation piece of the governance puzzle • Provides automated, self-service delivery of approved architectures • Maintains centralized control of accounts, security oversight • Leverages AWS GoldBase
  • 18. Automate, automate, automate • Programmable infrastructure changes everything! • Service Catalog, AWS CloudFormation, APIs for everything at the infrastructure level • For apps, AWS Elastic Beanstalk, AWS OpsWorks, AWS CodeDeploy, AWS CodePipeline • Visibility and control via • Manage everything (including security and compliance) using SDL from a source code repository • Security and compliance baked in to your continuous integration/continuous deployment pipeline
  • 19. It’s happening! • Not a pipe dream, but a growing reality at enterprises and agencies around the globe • Even security-conscious government agencies like USA Dept of Homeland Security (Citizenship and Immigration Services) • Mark Schwartz, CIO: https://youtu.be/QwHVlJtqhaI • DevOps and CI/CD on the AWS cloud providing dev/ops CI/CD agility with baked-in governance and security benefits
  • 20. Relevant upcoming sessions • SEC314: AWS Config: Using Visibility to Improve Governance over Configuration Changes to Your ResourcesSEC318: AWS CloudTrail Deep Dive • SEC403: Timely Security Alerts and Analytics: Diving into AWS CloudTrail Events by Using Apache Spark on Amazon EMR • SEC321: AWS for the Enterprise—Implementing Policy, Governance, and Security for Enterprise Workloads • SEC307: A Progressive Journey Through AWS IAM Federation Options: From Roles to SAML to Custom Identity Brokers • SEC316: Harden Your Architecture with Security Incident Response Simulations (SIRS) • DVO206L: Lessons from a CISO: How to Securely Scale Teams, Workloads, and Budgets
  • 21. Thank you! Mark Ryland (markry@amazon.com) Alan Halachmi (halachmi@amazon.com)