SlideShare a Scribd company logo
1 of 19
W A S H I N G T O N , D C | M A Y 2 3 - 2 5 , 2 0 2 2
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Transform your organization with
effective cloud management
S P O N S O R E D B Y K I O N
Brian Price
S E C 2 0 9 - S
CEO/Co-Founder
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Agenda
 The typical cloud management experience
 What is effective cloud management?
 The key to accelerating cloud results
 Security and compliance best practices
 AWS services to help you manage security and compliance
 Leveraging AWS partners to accelerate cloud management
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
The typical cloud
management
experience
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
The typical cloud
management
experience
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
The typical cloud
management
experience
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
The typical cloud
management
experience
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
• Siloed IT processes
• Misunderstood security and
compliance standards
• Long ATO processes
• Shift—and loss—
of financial control
• RESULT: friction
The typical cloud
management
experience
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What is effective cloud management?
The three principles of effective cloud management:
• Agile, but controlled, account provisioning
• Spend allocation, budget enforcement, and cost optimization
• Proactive and reactive controls for continuous compliance
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Realize that one-way doors are few
Do not fall prey to analysis paralysis: Most decisions you confront are
two-way doors
Assess where you are and what you have to determine to achieve
success
• Audit to determine where you align to a specific framework for
compliance. Your findings may surprise you—for good and bad
Success requires both preventative controls AND detection
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Consider your accreditation boundary
Rarely good enough when you consider your entire cloud service
provider as a boundary
Services, configuration, and applications:
• These build on each other
• If segmented correctly, they will expedite security and your ATO
process—without sacrificing time or impacting security
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Least privilege is best practice for a good reason
Very easy to overprovision access, forget who has access, and
remember to revoke access
Implement boundaries to prevent compromise:
• Use multiple accounts to limit blast radius
• Ensure accounts are tied into the corporate identity source
• Centralize accounts to simplify adding and removing
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Exemptions will be needed
There is no “one size fits all”
You need a flexible process that can grant rights to certain individuals
in certain roles on certain types of projects at certain times
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
• AWS Audit Manager
• AWS Config
conformance packs
• AWS Control Tower
• AWS Organizations
• AWS Security Hub
• AWS service control
policies
Leverage AWS
services to help
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS partners can help
• GitLab
• Splunk
• Telos
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Kion provides 360-degree compliance
Day 1 proactive guardrails to
enforce use of approved services,
configurations, and regions
On-demand or scheduled checks for
continual feedback to spot trends and
assess real-time compliance posture
Auto-remediation to fix
misconfigurations like public
resources, misconfigured security
groups, or abandoned access keys
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Visit in booth 419
Thank you!
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Brian Price
bprice@kion.io
© 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Please complete
the session survey
in the mobile app
Android iOS

More Related Content

Similar to AWS Cloud Management Security Compliance

AWS UK User Group Migrating 600 Databases - February 2023.pdf
AWS UK User Group Migrating 600 Databases - February 2023.pdfAWS UK User Group Migrating 600 Databases - February 2023.pdf
AWS UK User Group Migrating 600 Databases - February 2023.pdfMatt Houghton
 
Best Practices for Using AWS Credits
Best Practices for Using AWS CreditsBest Practices for Using AWS Credits
Best Practices for Using AWS CreditsTechSoup
 
Private Equity Technical Due Diligence Value Creation
Private Equity Technical Due Diligence Value CreationPrivate Equity Technical Due Diligence Value Creation
Private Equity Technical Due Diligence Value CreationTom Laszewski
 
Living the AWS Well Architected Framework
Living the AWS Well Architected FrameworkLiving the AWS Well Architected Framework
Living the AWS Well Architected FrameworkAdam Dillman
 
AWS Well-Architected: Build Better Architecture, Better Business
AWS Well-Architected: Build Better Architecture, Better BusinessAWS Well-Architected: Build Better Architecture, Better Business
AWS Well-Architected: Build Better Architecture, Better BusinessDevOps.com
 
Pop the hood: Using AWS resources to attest to security of the cloud - GRC310...
Pop the hood: Using AWS resources to attest to security of the cloud - GRC310...Pop the hood: Using AWS resources to attest to security of the cloud - GRC310...
Pop the hood: Using AWS resources to attest to security of the cloud - GRC310...Amazon Web Services
 
AWS DATABASE USER GROUP - LAUNCH EVENT (LONDON) December 7, 2022 - COM311 Mi...
AWS DATABASE USER GROUP - LAUNCH EVENT (LONDON)  December 7, 2022 - COM311 Mi...AWS DATABASE USER GROUP - LAUNCH EVENT (LONDON)  December 7, 2022 - COM311 Mi...
AWS DATABASE USER GROUP - LAUNCH EVENT (LONDON) December 7, 2022 - COM311 Mi...Matt Houghton
 
COM311 Migrating 600 Databases To AWS
COM311 Migrating 600 Databases To AWS COM311 Migrating 600 Databases To AWS
COM311 Migrating 600 Databases To AWS Matt Houghton
 
엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...
엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...
엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...Amazon Web Services Korea
 
Achieving Continuous Compliance with CTP and AWS
Achieving Continuous Compliance with CTP and AWS Achieving Continuous Compliance with CTP and AWS
Achieving Continuous Compliance with CTP and AWS Amazon Web Services
 
Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...
Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...
Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...Amazon Web Services
 
Governance@scale - Governance of Multi-Account, Large-Scale AWS Environments ...
Governance@scale - Governance of Multi-Account, Large-Scale AWS Environments ...Governance@scale - Governance of Multi-Account, Large-Scale AWS Environments ...
Governance@scale - Governance of Multi-Account, Large-Scale AWS Environments ...Amazon Web Services
 
Security & Compliance in the Cloud
Security & Compliance in the CloudSecurity & Compliance in the Cloud
Security & Compliance in the CloudAmazon Web Services
 
reInvent reCap 2022
reInvent reCap 2022reInvent reCap 2022
reInvent reCap 2022CloudHesive
 
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech TalksDeep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech TalksAmazon Web Services
 
Private Equity Value Creation Carve Outs, Divestitures and mergers
Private Equity Value Creation Carve Outs, Divestitures and mergersPrivate Equity Value Creation Carve Outs, Divestitures and mergers
Private Equity Value Creation Carve Outs, Divestitures and mergersTom Laszewski
 
You've Decided to Buy Cloud Services, Now What? (WPS203) - AWS re:Invent 2018
You've Decided to Buy Cloud Services, Now What? (WPS203) - AWS re:Invent 2018You've Decided to Buy Cloud Services, Now What? (WPS203) - AWS re:Invent 2018
You've Decided to Buy Cloud Services, Now What? (WPS203) - AWS re:Invent 2018Amazon Web Services
 
Policy Verification and Enforcement at Scale with AWS (SEC320) - AWS re:Inven...
Policy Verification and Enforcement at Scale with AWS (SEC320) - AWS re:Inven...Policy Verification and Enforcement at Scale with AWS (SEC320) - AWS re:Inven...
Policy Verification and Enforcement at Scale with AWS (SEC320) - AWS re:Inven...Amazon Web Services
 
Generational shiftsRedefining Customer Experience And The Way To Insure
Generational shiftsRedefining Customer Experience And The Way To InsureGenerational shiftsRedefining Customer Experience And The Way To Insure
Generational shiftsRedefining Customer Experience And The Way To InsureAmazon Web Services
 
Hitchhiker's Guide to Cloud Ops
Hitchhiker's Guide to Cloud Ops Hitchhiker's Guide to Cloud Ops
Hitchhiker's Guide to Cloud Ops Amazon Web Services
 

Similar to AWS Cloud Management Security Compliance (20)

AWS UK User Group Migrating 600 Databases - February 2023.pdf
AWS UK User Group Migrating 600 Databases - February 2023.pdfAWS UK User Group Migrating 600 Databases - February 2023.pdf
AWS UK User Group Migrating 600 Databases - February 2023.pdf
 
Best Practices for Using AWS Credits
Best Practices for Using AWS CreditsBest Practices for Using AWS Credits
Best Practices for Using AWS Credits
 
Private Equity Technical Due Diligence Value Creation
Private Equity Technical Due Diligence Value CreationPrivate Equity Technical Due Diligence Value Creation
Private Equity Technical Due Diligence Value Creation
 
Living the AWS Well Architected Framework
Living the AWS Well Architected FrameworkLiving the AWS Well Architected Framework
Living the AWS Well Architected Framework
 
AWS Well-Architected: Build Better Architecture, Better Business
AWS Well-Architected: Build Better Architecture, Better BusinessAWS Well-Architected: Build Better Architecture, Better Business
AWS Well-Architected: Build Better Architecture, Better Business
 
Pop the hood: Using AWS resources to attest to security of the cloud - GRC310...
Pop the hood: Using AWS resources to attest to security of the cloud - GRC310...Pop the hood: Using AWS resources to attest to security of the cloud - GRC310...
Pop the hood: Using AWS resources to attest to security of the cloud - GRC310...
 
AWS DATABASE USER GROUP - LAUNCH EVENT (LONDON) December 7, 2022 - COM311 Mi...
AWS DATABASE USER GROUP - LAUNCH EVENT (LONDON)  December 7, 2022 - COM311 Mi...AWS DATABASE USER GROUP - LAUNCH EVENT (LONDON)  December 7, 2022 - COM311 Mi...
AWS DATABASE USER GROUP - LAUNCH EVENT (LONDON) December 7, 2022 - COM311 Mi...
 
COM311 Migrating 600 Databases To AWS
COM311 Migrating 600 Databases To AWS COM311 Migrating 600 Databases To AWS
COM311 Migrating 600 Databases To AWS
 
엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...
엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...
엔터프라이즈의 효과적인 클라우드 도입을 위한 전략 및 적용 사례-신규진 프로페셔널 서비스 리드, AWS/고병률 데이터베이스 아키텍트, 삼성...
 
Achieving Continuous Compliance with CTP and AWS
Achieving Continuous Compliance with CTP and AWS Achieving Continuous Compliance with CTP and AWS
Achieving Continuous Compliance with CTP and AWS
 
Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...
Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...
Too Many Tools? How AWS Systems Manager Bridges Operational Models - AWS Summ...
 
Governance@scale - Governance of Multi-Account, Large-Scale AWS Environments ...
Governance@scale - Governance of Multi-Account, Large-Scale AWS Environments ...Governance@scale - Governance of Multi-Account, Large-Scale AWS Environments ...
Governance@scale - Governance of Multi-Account, Large-Scale AWS Environments ...
 
Security & Compliance in the Cloud
Security & Compliance in the CloudSecurity & Compliance in the Cloud
Security & Compliance in the Cloud
 
reInvent reCap 2022
reInvent reCap 2022reInvent reCap 2022
reInvent reCap 2022
 
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech TalksDeep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
 
Private Equity Value Creation Carve Outs, Divestitures and mergers
Private Equity Value Creation Carve Outs, Divestitures and mergersPrivate Equity Value Creation Carve Outs, Divestitures and mergers
Private Equity Value Creation Carve Outs, Divestitures and mergers
 
You've Decided to Buy Cloud Services, Now What? (WPS203) - AWS re:Invent 2018
You've Decided to Buy Cloud Services, Now What? (WPS203) - AWS re:Invent 2018You've Decided to Buy Cloud Services, Now What? (WPS203) - AWS re:Invent 2018
You've Decided to Buy Cloud Services, Now What? (WPS203) - AWS re:Invent 2018
 
Policy Verification and Enforcement at Scale with AWS (SEC320) - AWS re:Inven...
Policy Verification and Enforcement at Scale with AWS (SEC320) - AWS re:Inven...Policy Verification and Enforcement at Scale with AWS (SEC320) - AWS re:Inven...
Policy Verification and Enforcement at Scale with AWS (SEC320) - AWS re:Inven...
 
Generational shiftsRedefining Customer Experience And The Way To Insure
Generational shiftsRedefining Customer Experience And The Way To InsureGenerational shiftsRedefining Customer Experience And The Way To Insure
Generational shiftsRedefining Customer Experience And The Way To Insure
 
Hitchhiker's Guide to Cloud Ops
Hitchhiker's Guide to Cloud Ops Hitchhiker's Guide to Cloud Ops
Hitchhiker's Guide to Cloud Ops
 

Recently uploaded

Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersThousandEyes
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...HostedbyConfluent
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Patryk Bandurski
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationSafe Software
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsMaria Levchenko
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...shyamraj55
 

Recently uploaded (20)

Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
Transforming Data Streams with Kafka Connect: An Introduction to Single Messa...
 
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
Integration and Automation in Practice: CI/CD in Mule Integration and Automat...
 
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry InnovationBeyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
Beyond Boundaries: Leveraging No-Code Solutions for Industry Innovation
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
Neo4j - How KGs are shaping the future of Generative AI at AWS Summit London ...
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
Pigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping ElbowsPigging Solutions Piggable Sweeping Elbows
Pigging Solutions Piggable Sweeping Elbows
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
Automating Business Process via MuleSoft Composer | Bangalore MuleSoft Meetup...
 

AWS Cloud Management Security Compliance

  • 1. W A S H I N G T O N , D C | M A Y 2 3 - 2 5 , 2 0 2 2
  • 2. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Transform your organization with effective cloud management S P O N S O R E D B Y K I O N Brian Price S E C 2 0 9 - S CEO/Co-Founder
  • 3. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Agenda  The typical cloud management experience  What is effective cloud management?  The key to accelerating cloud results  Security and compliance best practices  AWS services to help you manage security and compliance  Leveraging AWS partners to accelerate cloud management
  • 4. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. The typical cloud management experience
  • 5. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. The typical cloud management experience
  • 6. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. The typical cloud management experience
  • 7. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. The typical cloud management experience
  • 8. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. • Siloed IT processes • Misunderstood security and compliance standards • Long ATO processes • Shift—and loss— of financial control • RESULT: friction The typical cloud management experience
  • 9. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. What is effective cloud management? The three principles of effective cloud management: • Agile, but controlled, account provisioning • Spend allocation, budget enforcement, and cost optimization • Proactive and reactive controls for continuous compliance
  • 10. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Realize that one-way doors are few Do not fall prey to analysis paralysis: Most decisions you confront are two-way doors Assess where you are and what you have to determine to achieve success • Audit to determine where you align to a specific framework for compliance. Your findings may surprise you—for good and bad Success requires both preventative controls AND detection
  • 11. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Consider your accreditation boundary Rarely good enough when you consider your entire cloud service provider as a boundary Services, configuration, and applications: • These build on each other • If segmented correctly, they will expedite security and your ATO process—without sacrificing time or impacting security
  • 12. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Least privilege is best practice for a good reason Very easy to overprovision access, forget who has access, and remember to revoke access Implement boundaries to prevent compromise: • Use multiple accounts to limit blast radius • Ensure accounts are tied into the corporate identity source • Centralize accounts to simplify adding and removing
  • 13. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Exemptions will be needed There is no “one size fits all” You need a flexible process that can grant rights to certain individuals in certain roles on certain types of projects at certain times
  • 14. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. • AWS Audit Manager • AWS Config conformance packs • AWS Control Tower • AWS Organizations • AWS Security Hub • AWS service control policies Leverage AWS services to help
  • 15. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS partners can help • GitLab • Splunk • Telos
  • 16. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Kion provides 360-degree compliance Day 1 proactive guardrails to enforce use of approved services, configurations, and regions On-demand or scheduled checks for continual feedback to spot trends and assess real-time compliance posture Auto-remediation to fix misconfigurations like public resources, misconfigured security groups, or abandoned access keys
  • 17. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Visit in booth 419
  • 18. Thank you! © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Brian Price bprice@kion.io
  • 19. © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved. Please complete the session survey in the mobile app Android iOS

Editor's Notes

  1. Welcome everyone! It is great to see so many faces once again back here in DC for the AWS Summit. My name is Brian Price, CEO and Co-Founder at Kion and today I’m excited to share some ways that you can help your organization with effective cloud management. Over the past six years, Kion has worked with dozens of federal government agencies and higher education institutions to help them apply cloud management and governance practices to accelerate their journey in the cloud. Today, I’ll talk a little about some of the cloud security and compliance lessons we’ve seen and we’ve learned.
  2. First, I’ll share a story to highlight some of the typical experiences that happen inside of most organizations when managing the cloud. Then, I’ll introduce the idea of effective cloud management and how to best accelerate cloud adoption. We will dive into some security and compliance best practices to help navigate through some one way doors and last, I’ll share some specific AWS services along with partner solutions that can help.
  3. Let me paint a picture for you… You are running a cloud PMO or cloud operations team and you get a request from Jim for a new AWS account for this brand new app that his team is building. What happens? Typically, that one request spawns many tickets – in you are in the federal government, the first may be to your cloud reseller to provision the new account, the next may go to your security team to turn on some baseline services like CloudTrail, CloudWatch, Guard Duty. Then a ticket goes to the identity team to create IAM users and roles, configure SSO and apply baseline IAM policies. After that your networking team sets up and configures the VPC and security groups. Then probably after about 3 more tickets to 3 separate teams, you are able to reach back to Jim and say – HERE. YOU. GO.
  4. But before that request can be closed, Jim sends you another request. “I needed to be able to connect to on-prem infrastructure and I can’t actually create any EC2 instances in the account.” Ohh….right….that networking requirement wasn’t in the original request…and somehow, we missed the fact that the platform team didn’t share AMIs from our AMI factory with the account. So fire off two more tickets, and oh yeah…Bob who is the only person on the networking team that understands how the heck to correctly setup a VPC had to leave for the day to pick up his sick kid from school…after all, we are still dealing with COVID. So you can’t get back to Jim untill the next day and then maybe…if your lucky…they can get to work.
  5. Fast forward a week and in your morning email, you notice in your daily report of the cloud accounts that have been flagged for violating a security or compliance check that there’s Jim’s account you just provisioned last week. He is using Amazon Kendra to try to make a search capability easy in his app but he did this in a GOVCLOUD ACCOUNT! Doesn’t he know better! Why would he ever do that? That service not been approved by the JAB to run FedRAMP HIGH workloads! He will never get an ATO doing things like that. Jim should know better. You pick up the phone, try calling Jim. Explain the situation. Walk him through how to tear down the infrastructure he and his team spent the past week on. Whew! Crisis avoided!
  6. And then a week later in your morning email, you notice in your daily report of the cloud accounts that have been flagged for exceeding a budget, there’s Jim’s account again. He spent $50,000 in the past 2 weeks…no wait…past two days! How? Why? Doesn’t he know that until his app is given a green light, he only has $5,000 to spend. What the heck?!?! Call Jim up. Explain the situation. Oh you forgot that you left that cluster up over the weekend. Well he is in trouble.
  7. And this happens. Over and over and over again. Not just with Jim’s accounts. But also with John’s, Jerry’s, Jason’s, Jessica’s, Jamie’s. And somehow we aren’t innovating fast enough or hitting those cloud adoption milestones that the CIO asked us to reach. Wonder why? How many people here can relate to this? All of these things in this example like siloed IT processes, misunderstood security and compliance standards, long ATO processes, the shift of financial control to engineers all result in friction if cloud management is adopted in the same way as IT has been managed for decades despite cloud being vastly different.
  8. Now let’s look at a different approach…what if we re-invent cloud management to enable an organization to move faster. What if we make those processes more cloud-like, more self-service, with more context to empower folks like Jim to do more and wait less. Effective cloud management enables you to focus on your mission. The three principals of effective cloud management rely on agile, but controlled, self service account provisioning, budget and spend visibility, allocation and enforcement with the cost optimization context and proactive and reactive controls to help ensure security and compliance standards are met all the time since cloud infrastructure can be very dynamic. Today, I’m going to focus on security and compliance best practices; however, each of these principals are interrelated and have to be working together to enable effective cloud management.
  9. Now I’d like to share some lessons learned we have seen working with many groups that can hopefully help you develop an effective cloud management approach for your organization that helps you go farther and faster in the cloud.
  10. But to get there, let’s talk about one way and two way doors in in cloud management and governance. Whether you are new or experienced managing cloud environments, you are likely going to make some mistakes. But don’t let the fear of making a mistake stop you from making a decision. There are only a few one way doors in designing your cloud management strategy…that is decisions that once you make, it is difficult to unwind and change. As a technical example, setting up your centralized auditing and logging as part of your landing zone through a service like AWS Control Tower is an important first step and one-way door to make sure you have the full provenance of actions that happen inside of all the AWS accounts across your organization. Waiting until you have the full set of preventative controls implemented to achieve a compliance standard isn’t as we find its important and easier to run some detective checks against those standards to get a picture of how far off you are to prevent progress. This will be back and forth anyway as most regulations tend to change and get updated from time to time. But let’s talk a little more about 3 specific one-way doors you need to consider:
  11. First, a really important one is to think through your accreditation boundaries. We have seen some agencies take a carte blanche approach and get an ATO for the entirety of AWS so that any workload can fall under this but doesn’t give you much granularity or flexibility when something needs to change. Others have taken almost the opposite approach and try to achieve ATOs for each and every application that they need to support in a one off capacity. There is a balance in the middle where the ATO boundary should be designed as layers of a cake where the bottom layer is baseline controls satisfied by AWS, such as the physical controls and core services like IAM, then on top of that layer, there are controls satisfied by other shared services that are offered to all tenants, and then, going all the way to the top, there is only a small layer that each application owner need to satisfy based on the unique requirements of their workload. This is a much more agile and adaptive approach that makes it easier to build templates and adjust as requirements change. This also makes a much more streamlined and efficient ATO process that can yield quicker accredidtions.
  12. Next, its important to think through how to implement least privilege. It is very easy to over provision access, forget who has access and remember to revoke access. While most organizations we support today have moved to role-based federation using centralized identities, especially with how easy it is to get started with a service like AWS SSO that now supports using CloudFormation Templates, its important to get this setup right from the very beginning and automate it as much as possible so that it doesn’t become a pain to configure for each workload. I’ll hit here briefly on the importance of a multi-account strategy, that is to use multiple AWS accounts for specific workloads because they help limit the financial and security blast radius if there is an incident that happens. This is critical especially as it relates to least privilege so that you can quickly adjust permissions in specific roles across specific types of accounts if the underlying IAM policies were overly permissive or some other incident happens.
  13. Last but certainly not least, it is impossible to plan for every possible scenario for every workload like Jim’s new app that needs to run in the cloud. As I mentioned in the first one-way door around accreditation boundaries, taking a one-size fits all approach is destined to fail because it won’t offer enough flexibility as your organization matures its cloud usage. You need to think through how you plan on providing exemptions to established security baselines, weather that is the need to use a service like Amazon Kendra that hasn’t officially achieved its JAB approval for FedRAMP High. Maybe it is based on where the application lives in the organization, or its type…if it is internal or external facing. Its also important to think through who has the authority to approve the exemption and how to keep other guardrails in place despite accepting the risk of certain configurations.
  14. The great news is that AWS offers a ton of services that can help implement these best practices to ensure you build effective cloud management. AWS Audit manager helps you document and assess your current compliance status in preparation for security audits as part of your ATO process. AWS Config Conformance Packs provide ways you can check your AWS environment to check and remediate security findings AWS Control Tower offers the ability to deploy a Landing Zone to setup a multi-account environment AWS Organizations helps you create and manage AWS accounts in commercial and GovCloud regions AWS Security Hub brings together multiple AWS services, like Audit Manager, and Config to help you see and take action on your current security posture And last but not least AWS Service Control Policies help provide preventative guardrails that can be deployed within AWS Organizations to ensure parts of your organization don’t do something they shouldn’t based on their compliance status and can be configured to move accounts that require exemptions into separate OUs that allow services.
  15. These native services can be extended with AWS partner solutions like GitLab that can serve as the source code repository and shared services to version control all of your security control policies, Infrastructure as Code like CloudFormation Templates Splunk that can aggregate audit and logging information across your AWS and other cloud environments to bring you a total picture of your organization’s on-prem and cloud-based security posture And Telos Xacta which can further automate and extend the RMF process to your organizations technical and non-technical security professionals This is just to name a few solutions that really can help.
  16. And if you need some help connecting these pieces, especially in a way that works across your AWS commercial, GovCloud, SC2S, C2S and even other cloud providers, Kion is here to help. Our cloud enablement platform provides a giant easy button to help assemble these cloud native services provided by AWS and others along with other AWS partner solutions in a way that helps restore the experience that cloud should be in the enterprise. In today’s session, we have focused a lot on security and compliance. Out-of-the-box, our platform ships with over 4500 checks that map back to nearly 2 dozen regulatory frameworks to help easily satisfy the technical controls required. And the automation possible within Kion helps make sure its easy to provide the right controls and give the right context to folks like Jim to help them build better applications.
  17. So putting this all together…what if instead of Jim just putting a request in, he had the ability to create his own AWS accounts and end-to-end automation sets them up in a matter of minutes, with the right controls to help achieve FedRAMP High compliance and adhere to his budget. And he and his team get the information they need to take action proactively on their own, instead of getting a call when something happens. Waiting for cloud, security and network operations goes from days or weeks to minutes, context is provided, control is restored, friction is removed and the experience of the enterprise cloud can finally drive innovation. If the topics today resonate with some of the challenges you are looking to solve in your team, please stop by our booth, number 419, in the expo hall this afternoon to meet some of the Kioneers that can help you on your journey or visit our website at kion dot i-o and let us know how we can help.