SlideShare a Scribd company logo
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Chris Whalley - AWS Medical Security Team Lead
Mitsuhiro YANO - Senior Planner, Information Solution , Sysmex Corporation
November 29, 2016
SAC314
Common Considerations for Data
Integrity Controls in Healthcare
What to expect from the session
 Overview of Data Integrity in Healthcare
 Applying Data Integrity in GxP Medical Systems
 Top 10 Data Integrity Controls
Protected health
information
HIPAA*
Human subject
research data
IRB
Controlled access
genomic data
dbGaP
Part 11 electronic
records and electronic
signatures
GxP
Personal health
records
FTC
AWS Healthcare Security Assurance Scope
Customer
Content
PRIVACY
IntegrityAvailability
RISKS CONTROLS FOCUS
PRIVACY /
CONFIDENTIALITY
Loss of privacy,
unauthorized access,
theft
Encryption,
authentication, access
controls
Information security
INTEGRITY
Data is no longer
reliable or accurate,
fraud
Maker/checker, quality
assurance, audit logs
Operational controls
AVAILABILITY
Work disruption,
inability to make data-
driven decisions, loss of
user confidence,
regulator penalties
BCP plans and tests,
backup storage,
capacity planning
Business continuity
planning
Data Integrity in Healthcare and Life Sciences
Human safety decisions
based on data require that
the data be trustworthy.
Attributable
Legible
Contemporaneous
Original
Accurate
Scientific Data
Applies to:
 Business Process
 Software Application
Examples:
 pH of chemical solution is 6.6
 Severe reactions from new
drug product was significantly
reduced compared to old drug
product (p<0.001)
Define: Data
Computer Data
Applies to:
 Virtualized Infrastructure
 Infrastructure Software Tools
 Physical Infrastructure
Examples:
 5 (decimal) = 101 (binary)
 1 KB = 1,024 bytes
 File object SHA1 checksum:
B0FADEC093EEC1F0DA5695
A5106B5E845CF8E2E9
Regulator View on Data Integrity
Data was not reviewed & evaluated by your
firm when making batch release decisions
 Regulators published
5 new data integrity
guidance documents
in last 12 months
 In 2015, 79% of FDA
warning letters
involving data integrity
were issued to
international firms
Data Integrity Bits on a disk>
Applying Data Integrity Principles
Controls for Humans:
 Training for System Users &
Developers
 Policies & Procedures for…
o IT Purchasing
o DevSecOps &
Computer Validation
o Data Monitoring & ReviewApp
Virtual Infrastructure
AWS Products
System Users
Healthcare Protocol
Data 
Applying Data Integrity Principles
Controls for Machines:
 I/O checks between machines
and services
 Logging data access, use, and
modification
 Access controls
 Top 10 coming after systems
App
Virtual Infrastructure
AWS Products
System Users
Healthcare Protocol
Data 
Corporate Philosophy
Shaping the advancement
of healthcare
systematical + medics + x
Who are we?
Where do we operate?
Diagnosis /
Treatment
Interview/
Palpation
Complete
Recovery
Image Scanning
Respiratory
function testing
Ultrasonography
In-Vivo
Diagnostics
Blood testing
Immunochemistry
testing
Clinical chemistry
testing
etc.
In-Vitro
Diagnostics
etc.
Clinical Testing
Patient
room
Test equipment operable at bedside
minimizes patient discomfort
Operatin
g
room
Compact test equipment ready for
emergency tests during surgery
Examination
room
Examination (interview) and
testing performed simultaneously
Rapid confirmation of doctor’s diagnosis
Laborator
y
High-quality and efficient testing
Comprehensive analysis of patient’s blood
and urine
Sysmex at a Glance
20
40
60
0
50
100
150
200
250
'00 '05 '10 '15
Net Sales
Operating Income
Net Income
Net Sales (million $) Profits (million $)
28th
15.7%
23.6%
27.0%
25.7%
7.9%
Japan
Americas
AP
EMEA
China
Sales by Region
Missions - Information Solution Dep.
IT Headquarters
IT Strategy
Development
System Operation
On-going Support
User Requirements for Infrastructure
Follow-the-sun
Support
SecurityAgility
To leverage Cloud
Security Guideline
Understanding
Cloud Service
Check Sheet
Security Policy
AWS Assessment
Market Leader Listen to UsersLarge Community
Quality Complaint Management Project
Considerations for Infrastructure
Global Network Required Availability
Long Term
Data storage
Project Schedule
OND 15 JFM 16 AMJ 16 JAS 16 OND 16
Validation
Sandbox DEV VER / PROD
Feasibility Decision
Hardware Era Virtualization Era Cloud Era
Protocol-driven
manual activities
Procedure-driven
manual activities
Code-driven
automated activities
White Paper
AWS Reliability Study
ISO
27001
7.3 Support your ISMS by making people aware of their responsibilities
8.1 Carry out operational planning and control processes
9.1 Monitoring, measurement, analysis and evaluation
9.3 Management Review
6.3 Performing Maintenance and Checking Management
(1) The Operation Manager should have persons in charge
conduct maintenance, and record and retain its results.
“AWS Reference”
6.5 Backup and Restore
The Operation Manager should have the designated persons
designated conduct the following activities in accordance
with the Operations Management Code, etc
(1) Backup (2) Restore (3) Document and retain records
ISO
9001
4.2 Documentation requirements
4.2.1 General
4.2.2 Quality manual9.3 Management Review
5.3 Quality Policy
SOC1/2 Check upon NDA with AWS
“AWS Reference”
Common Rules
Suppli
er
A Lifecycle Model of Computerized Systems - Appendix 1
On-going Operation Management
Highly-reliable operations
Game Change
System Architecture / Validation Target
System Architecture / Validation Target
System Architecture / Validation Target
Validation Activities - Recap
IQ EffortOperation PlanningProcurement
Automation Support NeededLeverage Third-party Certificate
docomo
Cloud Package
AWS
Environment
Set-up
Validation
Activities
Document
Support
Special Thanks to
Key Learning and To move forward
Infrastructure
Choice
Listen to UsersLarge Community
With the latest available resources Eco-system Development More GxP friendly functions
Shaping the advancement
of healthcare
1. Use risk-based software design and testing
AWS features and controls Customer guidance
 AWS enables customers to retain
control of business process, data,
applications, and virtual
infrastructure
 AWS provides user-configurable
infrastructure software tools with
features to address a wide range of
data risks
 Use your risk assessment to
identify the impact of data integrity
risks to your product or service
 Use AWS documentation, support,
and partners to define the software
design and testing controls needed
to mitigate your risks
2. Restrict data access
AWS features and controls Customer guidance
 AWS implements physical
infrastructure access controls that
are validated by third-party auditors
 Review AWS audit reports
 Implement physical access
controls to your assets & user
environment
2. Restrict data access
AWS features and controls Customer guidance
 AWS provides data access control
features in infrastructure software
tools that are validated by third-
party auditors
 Implement your virtual
infrastructure access controls using
AWS features in IAM, Amazon
VPC, AWS Directory Service, and
other AWS products
 Implement your software access
controls using AWS SDKs
AWS Identity and
Access Management
AWS
SDKs
AWS Directory
Service
Amazon Virtual
Private Cloud (VPC)
3. Restrict audit trail access
AWS features and controls Customer guidance
 AWS implements physical
infrastructure access controls that
are validated by third-party auditors
 Review AWS audit reports
 Implement physical access
controls for your on-premises
infrastructure and mobile devices
 AWS provides audit trail access
control features in infrastructure
software tools like AWS CloudTrail
that are validated by third-party
auditors
 Review AWS audit reports
 Implement your virtual
infrastructure audit trail access
controls using AWS features in
IAM, VPC, Directory Service, and
other AWS products
 Implement your software audit trail
controls using AWS SDKs
4. Record data contemporaneously
AWS features and controls Customer guidance
 AWS provides time-stamped audit trail control
features in infrastructure software tools
 Enable virtual infrastructure audit
trail features in AWS products like
CloudTrail, CloudWatch, and Config
 AWS provides time zone control features in
infrastructure software tools
 Configure virtual infrastructure time
zone control features in AWS
products like RDS, EC2, and others
 AWS provides SDKs
 Implement software time-stamped
audit trails
 Synchronize software time-stamped
audit trails across time zones
 Ensure that software logic commits
data to storage at time of activity
5. Control blank paper forms
AWS features and controls Customer guidance
 AWS provides flexible, low-cost infrastructure
software tools and SDKs that enable rapid
development and testing of highly secure
software
 Replace paper forms with secure
electronic data capture software
6. Periodically review a sample of audit
trails, data, and metadata
AWS features and controls Customer guidance
 AWS provides infrastructure
software tools like AWS Lambda
and Amazon SNS that enable
customers to build continuous
monitoring solutions
 Define validation rules (functions)
and triggers (events) for data
 Define notification groups for failed
validations
 Implement validation functions,
events, and notification rules in
AWS products
 AWS Marketplace partners can
provide out-of-the-box solutions for
continuous monitoring of audit
trails, data, and metadata
 Find and try partner solutions in the
AWS Marketplace
7. Retention of full audit trails
AWS features and controls Customer guidance
 AWS provides infrastructure software tools
like CloudTrail and CloudWatch that produce
virtual infrastructure audit trails in a fully
portable format
 Review and revise record retention
schedule
 Configure CloudWatch and
CloudTrail
 Retain virtual infrastructure audit
trails wherever you want for as
long as you want
 AWS provides infrastructure software tools
like Amazon S3 and Amazon Glacier for
storage and retention of audit trails
 Configure and use storage tools for
virtual infrastructure and software
audit trails
8. Validate regulated software applications
AWS features and controls Customer guidance
 AWS certifies our infrastructure software tools
to commercial-off-the-shelf (COTS) product
standards
 Review AWS audit reports for ISO,
SOC, and NIST
 AWS provides features to create and enforce
“gold standard” virtualized infrastructure
resources
 Configure AWS features like EC2
AMIs and CloudFormation
Templates
 AWS provides features to automate creation
and error reporting of infrastructure resources
 Review and revise your
infrastructure qualification SOPs
 Configure AWS features like
CloudTrail
 AWS enables customers to retain control of
application SDLC
 Follow your existing software
validation process
9. Senior management is responsible for
implementing data governance
AWS features and controls Customer guidance
 AWS Partner Network and AWS Professional
Services provide consultations for data
governance and cloud adoption strategies
 Seek advice for your cloud
adoption plan
 AWS provides industry-specific case studies
and customer workshops
 Review case studies and attend
workshops with others in your
industry
 AWS offers online documentation, self-paced
training labs, in-person classes, and user
certification programs
 Provide your team with
opportunities to develop their cloud
competencies
10. Senior management should encourage
an open culture for reporting errors
AWS features and controls Customer guidance
 AWS provides information and training
resources about DevOps and DevSecOps
methodologies that encourage continuous
improvement
 Review our DevOps and
DevSecOps resources
 AWS operates an open culture for reporting
errors and continuous improvement
 Ask us how AWS teams work
together and use the Amazon
leadership principles to encourage
open culture for reporting errors
Thank you!
Remember to complete
your evaluations!
Related sessions

More Related Content

What's hot

AWS Webcast - Understanding the AWS Security Model
AWS Webcast - Understanding the AWS Security ModelAWS Webcast - Understanding the AWS Security Model
AWS Webcast - Understanding the AWS Security Model
Amazon Web Services
 
AWS re:Invent 2016: AWS GovCloud (US) for Highly Regulated Workloads (WWPS301)
AWS re:Invent 2016: AWS GovCloud (US) for Highly Regulated Workloads (WWPS301)AWS re:Invent 2016: AWS GovCloud (US) for Highly Regulated Workloads (WWPS301)
AWS re:Invent 2016: AWS GovCloud (US) for Highly Regulated Workloads (WWPS301)
Amazon Web Services
 
AWS April Webinar Series - Security Best Practices: Compliance Beyond the Che...
AWS April Webinar Series - Security Best Practices: Compliance Beyond the Che...AWS April Webinar Series - Security Best Practices: Compliance Beyond the Che...
AWS April Webinar Series - Security Best Practices: Compliance Beyond the Che...
Amazon Web Services
 
AWS Governance Overview - Beach
AWS Governance Overview - BeachAWS Governance Overview - Beach
AWS Governance Overview - Beach
Amazon Web Services
 
Keynote: Future of IT - future of enterprise it Canada
Keynote: Future of IT - future of enterprise it CanadaKeynote: Future of IT - future of enterprise it Canada
Keynote: Future of IT - future of enterprise it Canada
Amazon Web Services
 
Session Sponsored by Trend Micro: 3 Secrets to Becoming a Cloud Security Supe...
Session Sponsored by Trend Micro: 3 Secrets to Becoming a Cloud Security Supe...Session Sponsored by Trend Micro: 3 Secrets to Becoming a Cloud Security Supe...
Session Sponsored by Trend Micro: 3 Secrets to Becoming a Cloud Security Supe...
Amazon Web Services
 
(SEC313) Security & Compliance at the Petabyte Scale
(SEC313) Security & Compliance at the Petabyte Scale(SEC313) Security & Compliance at the Petabyte Scale
(SEC313) Security & Compliance at the Petabyte Scale
Amazon Web Services
 
Getting Started with Managed Services | AWS Public Sector Summit 2016
Getting Started with Managed Services | AWS Public Sector Summit 2016Getting Started with Managed Services | AWS Public Sector Summit 2016
Getting Started with Managed Services | AWS Public Sector Summit 2016
Amazon Web Services
 
Breaking down the economics and tco of migrating to aws - Toronto
Breaking down the economics and tco of migrating to aws - TorontoBreaking down the economics and tco of migrating to aws - Toronto
Breaking down the economics and tco of migrating to aws - Toronto
Amazon Web Services
 
Security and Compliance
Security and ComplianceSecurity and Compliance
Security and Compliance
Amazon Web Services
 
Deep Dive on Amazon S3
Deep Dive on Amazon S3Deep Dive on Amazon S3
Deep Dive on Amazon S3
Amazon Web Services
 
FireEye: Seamless Visibility and Detection for the Cloud
FireEye: Seamless Visibility and Detection for the CloudFireEye: Seamless Visibility and Detection for the Cloud
FireEye: Seamless Visibility and Detection for the Cloud
Amazon Web Services
 
Hack-Proof Your Cloud: Responding to 2016 Threats | AWS Public Sector Summit ...
Hack-Proof Your Cloud: Responding to 2016 Threats | AWS Public Sector Summit ...Hack-Proof Your Cloud: Responding to 2016 Threats | AWS Public Sector Summit ...
Hack-Proof Your Cloud: Responding to 2016 Threats | AWS Public Sector Summit ...
Amazon Web Services
 
(SEC320) Leveraging the Power of AWS to Automate Security & Compliance
(SEC320) Leveraging the Power of AWS to Automate Security & Compliance(SEC320) Leveraging the Power of AWS to Automate Security & Compliance
(SEC320) Leveraging the Power of AWS to Automate Security & Compliance
Amazon Web Services
 
Compliance in the Cloud Using Security by Design
Compliance in the Cloud Using Security by DesignCompliance in the Cloud Using Security by Design
Compliance in the Cloud Using Security by Design
Amazon Web Services
 
Getting started with aws security toronto rs
Getting started with aws security toronto rsGetting started with aws security toronto rs
Getting started with aws security toronto rs
Amazon Web Services
 
Big Data adoption success using AWS Big Data Services - Pop-up Loft TLV 2017
Big Data adoption success using AWS Big Data Services - Pop-up Loft TLV 2017Big Data adoption success using AWS Big Data Services - Pop-up Loft TLV 2017
Big Data adoption success using AWS Big Data Services - Pop-up Loft TLV 2017
Amazon Web Services
 
Log Analytics with Amazon Elasticsearch Service - September Webinar Series
Log Analytics with Amazon Elasticsearch Service - September Webinar SeriesLog Analytics with Amazon Elasticsearch Service - September Webinar Series
Log Analytics with Amazon Elasticsearch Service - September Webinar Series
Amazon Web Services
 
Extending Datacenters to the Cloud: Connectivity Options and Considerations f...
Extending Datacenters to the Cloud: Connectivity Options and Considerations f...Extending Datacenters to the Cloud: Connectivity Options and Considerations f...
Extending Datacenters to the Cloud: Connectivity Options and Considerations f...
Amazon Web Services
 
(SEC203) Journey to Securing Time Inc's Move to the Cloud
(SEC203) Journey to Securing Time Inc's Move to the Cloud(SEC203) Journey to Securing Time Inc's Move to the Cloud
(SEC203) Journey to Securing Time Inc's Move to the Cloud
Amazon Web Services
 

What's hot (20)

AWS Webcast - Understanding the AWS Security Model
AWS Webcast - Understanding the AWS Security ModelAWS Webcast - Understanding the AWS Security Model
AWS Webcast - Understanding the AWS Security Model
 
AWS re:Invent 2016: AWS GovCloud (US) for Highly Regulated Workloads (WWPS301)
AWS re:Invent 2016: AWS GovCloud (US) for Highly Regulated Workloads (WWPS301)AWS re:Invent 2016: AWS GovCloud (US) for Highly Regulated Workloads (WWPS301)
AWS re:Invent 2016: AWS GovCloud (US) for Highly Regulated Workloads (WWPS301)
 
AWS April Webinar Series - Security Best Practices: Compliance Beyond the Che...
AWS April Webinar Series - Security Best Practices: Compliance Beyond the Che...AWS April Webinar Series - Security Best Practices: Compliance Beyond the Che...
AWS April Webinar Series - Security Best Practices: Compliance Beyond the Che...
 
AWS Governance Overview - Beach
AWS Governance Overview - BeachAWS Governance Overview - Beach
AWS Governance Overview - Beach
 
Keynote: Future of IT - future of enterprise it Canada
Keynote: Future of IT - future of enterprise it CanadaKeynote: Future of IT - future of enterprise it Canada
Keynote: Future of IT - future of enterprise it Canada
 
Session Sponsored by Trend Micro: 3 Secrets to Becoming a Cloud Security Supe...
Session Sponsored by Trend Micro: 3 Secrets to Becoming a Cloud Security Supe...Session Sponsored by Trend Micro: 3 Secrets to Becoming a Cloud Security Supe...
Session Sponsored by Trend Micro: 3 Secrets to Becoming a Cloud Security Supe...
 
(SEC313) Security & Compliance at the Petabyte Scale
(SEC313) Security & Compliance at the Petabyte Scale(SEC313) Security & Compliance at the Petabyte Scale
(SEC313) Security & Compliance at the Petabyte Scale
 
Getting Started with Managed Services | AWS Public Sector Summit 2016
Getting Started with Managed Services | AWS Public Sector Summit 2016Getting Started with Managed Services | AWS Public Sector Summit 2016
Getting Started with Managed Services | AWS Public Sector Summit 2016
 
Breaking down the economics and tco of migrating to aws - Toronto
Breaking down the economics and tco of migrating to aws - TorontoBreaking down the economics and tco of migrating to aws - Toronto
Breaking down the economics and tco of migrating to aws - Toronto
 
Security and Compliance
Security and ComplianceSecurity and Compliance
Security and Compliance
 
Deep Dive on Amazon S3
Deep Dive on Amazon S3Deep Dive on Amazon S3
Deep Dive on Amazon S3
 
FireEye: Seamless Visibility and Detection for the Cloud
FireEye: Seamless Visibility and Detection for the CloudFireEye: Seamless Visibility and Detection for the Cloud
FireEye: Seamless Visibility and Detection for the Cloud
 
Hack-Proof Your Cloud: Responding to 2016 Threats | AWS Public Sector Summit ...
Hack-Proof Your Cloud: Responding to 2016 Threats | AWS Public Sector Summit ...Hack-Proof Your Cloud: Responding to 2016 Threats | AWS Public Sector Summit ...
Hack-Proof Your Cloud: Responding to 2016 Threats | AWS Public Sector Summit ...
 
(SEC320) Leveraging the Power of AWS to Automate Security & Compliance
(SEC320) Leveraging the Power of AWS to Automate Security & Compliance(SEC320) Leveraging the Power of AWS to Automate Security & Compliance
(SEC320) Leveraging the Power of AWS to Automate Security & Compliance
 
Compliance in the Cloud Using Security by Design
Compliance in the Cloud Using Security by DesignCompliance in the Cloud Using Security by Design
Compliance in the Cloud Using Security by Design
 
Getting started with aws security toronto rs
Getting started with aws security toronto rsGetting started with aws security toronto rs
Getting started with aws security toronto rs
 
Big Data adoption success using AWS Big Data Services - Pop-up Loft TLV 2017
Big Data adoption success using AWS Big Data Services - Pop-up Loft TLV 2017Big Data adoption success using AWS Big Data Services - Pop-up Loft TLV 2017
Big Data adoption success using AWS Big Data Services - Pop-up Loft TLV 2017
 
Log Analytics with Amazon Elasticsearch Service - September Webinar Series
Log Analytics with Amazon Elasticsearch Service - September Webinar SeriesLog Analytics with Amazon Elasticsearch Service - September Webinar Series
Log Analytics with Amazon Elasticsearch Service - September Webinar Series
 
Extending Datacenters to the Cloud: Connectivity Options and Considerations f...
Extending Datacenters to the Cloud: Connectivity Options and Considerations f...Extending Datacenters to the Cloud: Connectivity Options and Considerations f...
Extending Datacenters to the Cloud: Connectivity Options and Considerations f...
 
(SEC203) Journey to Securing Time Inc's Move to the Cloud
(SEC203) Journey to Securing Time Inc's Move to the Cloud(SEC203) Journey to Securing Time Inc's Move to the Cloud
(SEC203) Journey to Securing Time Inc's Move to the Cloud
 

Similar to AWS re:Invent 2016: Common Considerations for Data Integrity Controls in Healthcare (SEC314)

2016 AWS Life Sciences Day | New Jersey – July 26th, 2016
2016 AWS Life Sciences Day | New Jersey – July 26th, 20162016 AWS Life Sciences Day | New Jersey – July 26th, 2016
2016 AWS Life Sciences Day | New Jersey – July 26th, 2016
Amazon Web Services
 
2016 AWS Healthcare Days | Nashville, TN – May 3,2016
2016 AWS Healthcare Days | Nashville, TN – May 3,20162016 AWS Healthcare Days | Nashville, TN – May 3,2016
2016 AWS Healthcare Days | Nashville, TN – May 3,2016
Amazon Web Services
 
AWS re:Invent 2016: Chalk Talk: Applying Security-by-Design to Drive Complian...
AWS re:Invent 2016: Chalk Talk: Applying Security-by-Design to Drive Complian...AWS re:Invent 2016: Chalk Talk: Applying Security-by-Design to Drive Complian...
AWS re:Invent 2016: Chalk Talk: Applying Security-by-Design to Drive Complian...
Amazon Web Services
 
AWS re:Invent 2016: Continuous Compliance in the AWS Cloud for Regulated Life...
AWS re:Invent 2016: Continuous Compliance in the AWS Cloud for Regulated Life...AWS re:Invent 2016: Continuous Compliance in the AWS Cloud for Regulated Life...
AWS re:Invent 2016: Continuous Compliance in the AWS Cloud for Regulated Life...
Amazon Web Services
 
Mark Johnson's AWS Chicago Healthcare Slides - 2016
Mark Johnson's AWS Chicago Healthcare Slides - 2016Mark Johnson's AWS Chicago Healthcare Slides - 2016
Mark Johnson's AWS Chicago Healthcare Slides - 2016
AWS Chicago
 
Webinar: How to Ace Your SaaS-based EDC System Validation for Sponsors and CROs
Webinar: How to Ace Your SaaS-based EDC System Validation for Sponsors and CROsWebinar: How to Ace Your SaaS-based EDC System Validation for Sponsors and CROs
Webinar: How to Ace Your SaaS-based EDC System Validation for Sponsors and CROs
Statistics & Data Corporation
 
How ServiceChannel Automated Their AWS Environment with Puppet
 How ServiceChannel Automated Their AWS Environment with Puppet How ServiceChannel Automated Their AWS Environment with Puppet
How ServiceChannel Automated Their AWS Environment with Puppet
Amazon Web Services
 
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
Amazon Web Services
 
Emerging IT Trends and Innovation Concepts.pptx
Emerging IT Trends and Innovation Concepts.pptxEmerging IT Trends and Innovation Concepts.pptx
Emerging IT Trends and Innovation Concepts.pptx
Roshni814224
 
AWS Shared Responsibility Model & Compliance Program Overview
AWS Shared Responsibility Model & Compliance Program OverviewAWS Shared Responsibility Model & Compliance Program Overview
AWS Shared Responsibility Model & Compliance Program Overview
Amazon Web Services
 
(SEC310) Keeping Developers and Auditors Happy in the Cloud
(SEC310) Keeping Developers and Auditors Happy in the Cloud(SEC310) Keeping Developers and Auditors Happy in the Cloud
(SEC310) Keeping Developers and Auditors Happy in the Cloud
Amazon Web Services
 
Streamlining Application Development with AWS Service Catalog (DEV328) - AWS ...
Streamlining Application Development with AWS Service Catalog (DEV328) - AWS ...Streamlining Application Development with AWS Service Catalog (DEV328) - AWS ...
Streamlining Application Development with AWS Service Catalog (DEV328) - AWS ...
Amazon Web Services
 
How to Secure Genomic Data in the Cloud
How to Secure Genomic Data in the CloudHow to Secure Genomic Data in the Cloud
How to Secure Genomic Data in the Cloud
Monica Rut Avellino
 
Automating Compliance Defense in the Cloud - September 2016 Webinar Series
Automating Compliance Defense in the Cloud - September 2016 Webinar SeriesAutomating Compliance Defense in the Cloud - September 2016 Webinar Series
Automating Compliance Defense in the Cloud - September 2016 Webinar Series
Amazon Web Services
 
AWS Security Hub
AWS Security HubAWS Security Hub
AWS Security Hub
Amazon Web Services
 
How MediaMath Turbo-charged DevOps with AWS and CloudCheckr
How MediaMath Turbo-charged DevOps with AWS and CloudCheckrHow MediaMath Turbo-charged DevOps with AWS and CloudCheckr
How MediaMath Turbo-charged DevOps with AWS and CloudCheckr
Amazon Web Services
 
Clireo eTMF Solution by arivis
Clireo eTMF Solution by arivisClireo eTMF Solution by arivis
Clireo eTMF Solution by arivis
Tricia Campbell - McQuarrie
 
AWS Webcast - Top 3 Ways to Improve Web App Security
AWS Webcast - Top 3 Ways to Improve Web App SecurityAWS Webcast - Top 3 Ways to Improve Web App Security
AWS Webcast - Top 3 Ways to Improve Web App Security
Amazon Web Services
 
DevOps at Scale: How Datadog is using AWS and PagerDuty to Keep Pace with Gr...
DevOps at Scale:  How Datadog is using AWS and PagerDuty to Keep Pace with Gr...DevOps at Scale:  How Datadog is using AWS and PagerDuty to Keep Pace with Gr...
DevOps at Scale: How Datadog is using AWS and PagerDuty to Keep Pace with Gr...
Amazon Web Services
 
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
Amazon Web Services
 

Similar to AWS re:Invent 2016: Common Considerations for Data Integrity Controls in Healthcare (SEC314) (20)

2016 AWS Life Sciences Day | New Jersey – July 26th, 2016
2016 AWS Life Sciences Day | New Jersey – July 26th, 20162016 AWS Life Sciences Day | New Jersey – July 26th, 2016
2016 AWS Life Sciences Day | New Jersey – July 26th, 2016
 
2016 AWS Healthcare Days | Nashville, TN – May 3,2016
2016 AWS Healthcare Days | Nashville, TN – May 3,20162016 AWS Healthcare Days | Nashville, TN – May 3,2016
2016 AWS Healthcare Days | Nashville, TN – May 3,2016
 
AWS re:Invent 2016: Chalk Talk: Applying Security-by-Design to Drive Complian...
AWS re:Invent 2016: Chalk Talk: Applying Security-by-Design to Drive Complian...AWS re:Invent 2016: Chalk Talk: Applying Security-by-Design to Drive Complian...
AWS re:Invent 2016: Chalk Talk: Applying Security-by-Design to Drive Complian...
 
AWS re:Invent 2016: Continuous Compliance in the AWS Cloud for Regulated Life...
AWS re:Invent 2016: Continuous Compliance in the AWS Cloud for Regulated Life...AWS re:Invent 2016: Continuous Compliance in the AWS Cloud for Regulated Life...
AWS re:Invent 2016: Continuous Compliance in the AWS Cloud for Regulated Life...
 
Mark Johnson's AWS Chicago Healthcare Slides - 2016
Mark Johnson's AWS Chicago Healthcare Slides - 2016Mark Johnson's AWS Chicago Healthcare Slides - 2016
Mark Johnson's AWS Chicago Healthcare Slides - 2016
 
Webinar: How to Ace Your SaaS-based EDC System Validation for Sponsors and CROs
Webinar: How to Ace Your SaaS-based EDC System Validation for Sponsors and CROsWebinar: How to Ace Your SaaS-based EDC System Validation for Sponsors and CROs
Webinar: How to Ace Your SaaS-based EDC System Validation for Sponsors and CROs
 
How ServiceChannel Automated Their AWS Environment with Puppet
 How ServiceChannel Automated Their AWS Environment with Puppet How ServiceChannel Automated Their AWS Environment with Puppet
How ServiceChannel Automated Their AWS Environment with Puppet
 
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
(SEC311) Architecting for End-to-End Security in the Enterprise | AWS re:Inve...
 
Emerging IT Trends and Innovation Concepts.pptx
Emerging IT Trends and Innovation Concepts.pptxEmerging IT Trends and Innovation Concepts.pptx
Emerging IT Trends and Innovation Concepts.pptx
 
AWS Shared Responsibility Model & Compliance Program Overview
AWS Shared Responsibility Model & Compliance Program OverviewAWS Shared Responsibility Model & Compliance Program Overview
AWS Shared Responsibility Model & Compliance Program Overview
 
(SEC310) Keeping Developers and Auditors Happy in the Cloud
(SEC310) Keeping Developers and Auditors Happy in the Cloud(SEC310) Keeping Developers and Auditors Happy in the Cloud
(SEC310) Keeping Developers and Auditors Happy in the Cloud
 
Streamlining Application Development with AWS Service Catalog (DEV328) - AWS ...
Streamlining Application Development with AWS Service Catalog (DEV328) - AWS ...Streamlining Application Development with AWS Service Catalog (DEV328) - AWS ...
Streamlining Application Development with AWS Service Catalog (DEV328) - AWS ...
 
How to Secure Genomic Data in the Cloud
How to Secure Genomic Data in the CloudHow to Secure Genomic Data in the Cloud
How to Secure Genomic Data in the Cloud
 
Automating Compliance Defense in the Cloud - September 2016 Webinar Series
Automating Compliance Defense in the Cloud - September 2016 Webinar SeriesAutomating Compliance Defense in the Cloud - September 2016 Webinar Series
Automating Compliance Defense in the Cloud - September 2016 Webinar Series
 
AWS Security Hub
AWS Security HubAWS Security Hub
AWS Security Hub
 
How MediaMath Turbo-charged DevOps with AWS and CloudCheckr
How MediaMath Turbo-charged DevOps with AWS and CloudCheckrHow MediaMath Turbo-charged DevOps with AWS and CloudCheckr
How MediaMath Turbo-charged DevOps with AWS and CloudCheckr
 
Clireo eTMF Solution by arivis
Clireo eTMF Solution by arivisClireo eTMF Solution by arivis
Clireo eTMF Solution by arivis
 
AWS Webcast - Top 3 Ways to Improve Web App Security
AWS Webcast - Top 3 Ways to Improve Web App SecurityAWS Webcast - Top 3 Ways to Improve Web App Security
AWS Webcast - Top 3 Ways to Improve Web App Security
 
DevOps at Scale: How Datadog is using AWS and PagerDuty to Keep Pace with Gr...
DevOps at Scale:  How Datadog is using AWS and PagerDuty to Keep Pace with Gr...DevOps at Scale:  How Datadog is using AWS and PagerDuty to Keep Pace with Gr...
DevOps at Scale: How Datadog is using AWS and PagerDuty to Keep Pace with Gr...
 
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
How Splunk and AWS Enabled End-to-End Visibility for PagerDuty and Bolstered ...
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
Amazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
Amazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
Amazon Web Services
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Amazon Web Services
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
Amazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
Amazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Amazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
Amazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Amazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Recently uploaded

UI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentationUI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentation
Wouter Lemaire
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
panagenda
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
shyamraj55
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
Jason Packer
 
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
saastr
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Malak Abu Hammad
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
Hiroshi SHIBATA
 
Operating System Used by Users in day-to-day life.pptx
Operating System Used by Users in day-to-day life.pptxOperating System Used by Users in day-to-day life.pptx
Operating System Used by Users in day-to-day life.pptx
Pravash Chandra Das
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
panagenda
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
Zilliz
 
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
saastr
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
Zilliz
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
tolgahangng
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
kumardaparthi1024
 
Nordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptxNordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptx
MichaelKnudsen27
 
Taking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdfTaking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdf
ssuserfac0301
 
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdfNunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
flufftailshop
 
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdfMonitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Tosin Akinosho
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
Zilliz
 
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdfHow to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
Chart Kalyan
 

Recently uploaded (20)

UI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentationUI5 Controls simplified - UI5con2024 presentation
UI5 Controls simplified - UI5con2024 presentation
 
HCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAUHCL Notes and Domino License Cost Reduction in the World of DLAU
HCL Notes and Domino License Cost Reduction in the World of DLAU
 
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with SlackLet's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
Let's Integrate MuleSoft RPA, COMPOSER, APM with AWS IDP along with Slack
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
 
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
Deep Dive: AI-Powered Marketing to Get More Leads and Customers with HyperGro...
 
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdfUnlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
Unlock the Future of Search with MongoDB Atlas_ Vector Search Unleashed.pdf
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
 
Operating System Used by Users in day-to-day life.pptx
Operating System Used by Users in day-to-day life.pptxOperating System Used by Users in day-to-day life.pptx
Operating System Used by Users in day-to-day life.pptx
 
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAUHCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
HCL Notes und Domino Lizenzkostenreduzierung in der Welt von DLAU
 
Generating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and MilvusGenerating privacy-protected synthetic data using Secludy and Milvus
Generating privacy-protected synthetic data using Secludy and Milvus
 
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
 
Programming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup SlidesProgramming Foundation Models with DSPy - Meetup Slides
Programming Foundation Models with DSPy - Meetup Slides
 
Serial Arm Control in Real Time Presentation
Serial Arm Control in Real Time PresentationSerial Arm Control in Real Time Presentation
Serial Arm Control in Real Time Presentation
 
GenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizationsGenAI Pilot Implementation in the organizations
GenAI Pilot Implementation in the organizations
 
Nordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptxNordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptx
 
Taking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdfTaking AI to the Next Level in Manufacturing.pdf
Taking AI to the Next Level in Manufacturing.pdf
 
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdfNunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
Nunit vs XUnit vs MSTest Differences Between These Unit Testing Frameworks.pdf
 
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdfMonitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdf
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
 
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdfHow to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
How to Interpret Trends in the Kalyan Rajdhani Mix Chart.pdf
 

AWS re:Invent 2016: Common Considerations for Data Integrity Controls in Healthcare (SEC314)

  • 1. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Chris Whalley - AWS Medical Security Team Lead Mitsuhiro YANO - Senior Planner, Information Solution , Sysmex Corporation November 29, 2016 SAC314 Common Considerations for Data Integrity Controls in Healthcare
  • 2. What to expect from the session  Overview of Data Integrity in Healthcare  Applying Data Integrity in GxP Medical Systems  Top 10 Data Integrity Controls
  • 3. Protected health information HIPAA* Human subject research data IRB Controlled access genomic data dbGaP Part 11 electronic records and electronic signatures GxP Personal health records FTC AWS Healthcare Security Assurance Scope Customer Content PRIVACY IntegrityAvailability
  • 4. RISKS CONTROLS FOCUS PRIVACY / CONFIDENTIALITY Loss of privacy, unauthorized access, theft Encryption, authentication, access controls Information security INTEGRITY Data is no longer reliable or accurate, fraud Maker/checker, quality assurance, audit logs Operational controls AVAILABILITY Work disruption, inability to make data- driven decisions, loss of user confidence, regulator penalties BCP plans and tests, backup storage, capacity planning Business continuity planning
  • 5. Data Integrity in Healthcare and Life Sciences Human safety decisions based on data require that the data be trustworthy. Attributable Legible Contemporaneous Original Accurate
  • 6. Scientific Data Applies to:  Business Process  Software Application Examples:  pH of chemical solution is 6.6  Severe reactions from new drug product was significantly reduced compared to old drug product (p<0.001) Define: Data Computer Data Applies to:  Virtualized Infrastructure  Infrastructure Software Tools  Physical Infrastructure Examples:  5 (decimal) = 101 (binary)  1 KB = 1,024 bytes  File object SHA1 checksum: B0FADEC093EEC1F0DA5695 A5106B5E845CF8E2E9
  • 7. Regulator View on Data Integrity Data was not reviewed & evaluated by your firm when making batch release decisions  Regulators published 5 new data integrity guidance documents in last 12 months  In 2015, 79% of FDA warning letters involving data integrity were issued to international firms
  • 8. Data Integrity Bits on a disk>
  • 9. Applying Data Integrity Principles Controls for Humans:  Training for System Users & Developers  Policies & Procedures for… o IT Purchasing o DevSecOps & Computer Validation o Data Monitoring & ReviewApp Virtual Infrastructure AWS Products System Users Healthcare Protocol Data 
  • 10. Applying Data Integrity Principles Controls for Machines:  I/O checks between machines and services  Logging data access, use, and modification  Access controls  Top 10 coming after systems App Virtual Infrastructure AWS Products System Users Healthcare Protocol Data 
  • 11.
  • 12. Corporate Philosophy Shaping the advancement of healthcare systematical + medics + x
  • 14. Where do we operate? Diagnosis / Treatment Interview/ Palpation Complete Recovery Image Scanning Respiratory function testing Ultrasonography In-Vivo Diagnostics Blood testing Immunochemistry testing Clinical chemistry testing etc. In-Vitro Diagnostics etc. Clinical Testing Patient room Test equipment operable at bedside minimizes patient discomfort Operatin g room Compact test equipment ready for emergency tests during surgery Examination room Examination (interview) and testing performed simultaneously Rapid confirmation of doctor’s diagnosis Laborator y High-quality and efficient testing Comprehensive analysis of patient’s blood and urine
  • 15. Sysmex at a Glance 20 40 60 0 50 100 150 200 250 '00 '05 '10 '15 Net Sales Operating Income Net Income Net Sales (million $) Profits (million $) 28th 15.7% 23.6% 27.0% 25.7% 7.9% Japan Americas AP EMEA China Sales by Region
  • 16. Missions - Information Solution Dep. IT Headquarters IT Strategy Development System Operation On-going Support
  • 17. User Requirements for Infrastructure Follow-the-sun Support SecurityAgility
  • 18. To leverage Cloud Security Guideline Understanding Cloud Service Check Sheet Security Policy
  • 19. AWS Assessment Market Leader Listen to UsersLarge Community
  • 21. Considerations for Infrastructure Global Network Required Availability Long Term Data storage
  • 22. Project Schedule OND 15 JFM 16 AMJ 16 JAS 16 OND 16 Validation Sandbox DEV VER / PROD Feasibility Decision Hardware Era Virtualization Era Cloud Era Protocol-driven manual activities Procedure-driven manual activities Code-driven automated activities
  • 24. ISO 27001 7.3 Support your ISMS by making people aware of their responsibilities 8.1 Carry out operational planning and control processes 9.1 Monitoring, measurement, analysis and evaluation 9.3 Management Review 6.3 Performing Maintenance and Checking Management (1) The Operation Manager should have persons in charge conduct maintenance, and record and retain its results. “AWS Reference” 6.5 Backup and Restore The Operation Manager should have the designated persons designated conduct the following activities in accordance with the Operations Management Code, etc (1) Backup (2) Restore (3) Document and retain records ISO 9001 4.2 Documentation requirements 4.2.1 General 4.2.2 Quality manual9.3 Management Review 5.3 Quality Policy SOC1/2 Check upon NDA with AWS
  • 25. “AWS Reference” Common Rules Suppli er A Lifecycle Model of Computerized Systems - Appendix 1
  • 27. System Architecture / Validation Target
  • 28. System Architecture / Validation Target
  • 29. System Architecture / Validation Target
  • 30. Validation Activities - Recap IQ EffortOperation PlanningProcurement Automation Support NeededLeverage Third-party Certificate
  • 32. Key Learning and To move forward Infrastructure Choice Listen to UsersLarge Community With the latest available resources Eco-system Development More GxP friendly functions
  • 34. 1. Use risk-based software design and testing AWS features and controls Customer guidance  AWS enables customers to retain control of business process, data, applications, and virtual infrastructure  AWS provides user-configurable infrastructure software tools with features to address a wide range of data risks  Use your risk assessment to identify the impact of data integrity risks to your product or service  Use AWS documentation, support, and partners to define the software design and testing controls needed to mitigate your risks
  • 35. 2. Restrict data access AWS features and controls Customer guidance  AWS implements physical infrastructure access controls that are validated by third-party auditors  Review AWS audit reports  Implement physical access controls to your assets & user environment
  • 36. 2. Restrict data access AWS features and controls Customer guidance  AWS provides data access control features in infrastructure software tools that are validated by third- party auditors  Implement your virtual infrastructure access controls using AWS features in IAM, Amazon VPC, AWS Directory Service, and other AWS products  Implement your software access controls using AWS SDKs AWS Identity and Access Management AWS SDKs AWS Directory Service Amazon Virtual Private Cloud (VPC)
  • 37. 3. Restrict audit trail access AWS features and controls Customer guidance  AWS implements physical infrastructure access controls that are validated by third-party auditors  Review AWS audit reports  Implement physical access controls for your on-premises infrastructure and mobile devices  AWS provides audit trail access control features in infrastructure software tools like AWS CloudTrail that are validated by third-party auditors  Review AWS audit reports  Implement your virtual infrastructure audit trail access controls using AWS features in IAM, VPC, Directory Service, and other AWS products  Implement your software audit trail controls using AWS SDKs
  • 38. 4. Record data contemporaneously AWS features and controls Customer guidance  AWS provides time-stamped audit trail control features in infrastructure software tools  Enable virtual infrastructure audit trail features in AWS products like CloudTrail, CloudWatch, and Config  AWS provides time zone control features in infrastructure software tools  Configure virtual infrastructure time zone control features in AWS products like RDS, EC2, and others  AWS provides SDKs  Implement software time-stamped audit trails  Synchronize software time-stamped audit trails across time zones  Ensure that software logic commits data to storage at time of activity
  • 39. 5. Control blank paper forms AWS features and controls Customer guidance  AWS provides flexible, low-cost infrastructure software tools and SDKs that enable rapid development and testing of highly secure software  Replace paper forms with secure electronic data capture software
  • 40. 6. Periodically review a sample of audit trails, data, and metadata AWS features and controls Customer guidance  AWS provides infrastructure software tools like AWS Lambda and Amazon SNS that enable customers to build continuous monitoring solutions  Define validation rules (functions) and triggers (events) for data  Define notification groups for failed validations  Implement validation functions, events, and notification rules in AWS products  AWS Marketplace partners can provide out-of-the-box solutions for continuous monitoring of audit trails, data, and metadata  Find and try partner solutions in the AWS Marketplace
  • 41. 7. Retention of full audit trails AWS features and controls Customer guidance  AWS provides infrastructure software tools like CloudTrail and CloudWatch that produce virtual infrastructure audit trails in a fully portable format  Review and revise record retention schedule  Configure CloudWatch and CloudTrail  Retain virtual infrastructure audit trails wherever you want for as long as you want  AWS provides infrastructure software tools like Amazon S3 and Amazon Glacier for storage and retention of audit trails  Configure and use storage tools for virtual infrastructure and software audit trails
  • 42. 8. Validate regulated software applications AWS features and controls Customer guidance  AWS certifies our infrastructure software tools to commercial-off-the-shelf (COTS) product standards  Review AWS audit reports for ISO, SOC, and NIST  AWS provides features to create and enforce “gold standard” virtualized infrastructure resources  Configure AWS features like EC2 AMIs and CloudFormation Templates  AWS provides features to automate creation and error reporting of infrastructure resources  Review and revise your infrastructure qualification SOPs  Configure AWS features like CloudTrail  AWS enables customers to retain control of application SDLC  Follow your existing software validation process
  • 43. 9. Senior management is responsible for implementing data governance AWS features and controls Customer guidance  AWS Partner Network and AWS Professional Services provide consultations for data governance and cloud adoption strategies  Seek advice for your cloud adoption plan  AWS provides industry-specific case studies and customer workshops  Review case studies and attend workshops with others in your industry  AWS offers online documentation, self-paced training labs, in-person classes, and user certification programs  Provide your team with opportunities to develop their cloud competencies
  • 44. 10. Senior management should encourage an open culture for reporting errors AWS features and controls Customer guidance  AWS provides information and training resources about DevOps and DevSecOps methodologies that encourage continuous improvement  Review our DevOps and DevSecOps resources  AWS operates an open culture for reporting errors and continuous improvement  Ask us how AWS teams work together and use the Amazon leadership principles to encourage open culture for reporting errors