SlideShare a Scribd company logo
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Joe Kinsella, CTO & Founder, CloudHealth Technologies
Iain Caldwell, Head of Infrastructure, News UK & News Corp EMEA
November 30, 2016
DEV 306
News UK: Achieving Centralized
Governance Through Policy Management
Presenters
Joe Kinsella, CTO & Founder
CloudHealth Technologies
@joekinsella
Iain Caldwell, Head of Infrastructure
News UK & News Corp EMEA
@caldi100
What to expect from this session
• Overview of News Corp’s use of AWS
• Why governance is critical to cloud success
• How to drive a governance strategy
• 5 best practices
News Corp strategy
• CTO set objective to reduce data centre footprint and associated costs
• Host 75% of estate in the public cloud within next three years.
• News UK currently running at 69% aiming to make 75% by July 2017
• Before we started in 2011 we built our AWS Cloud data centre
• Ran a global application assessment for cloud readiness across all BUs
• Digital estate was the main contender for cloud – web-based
applications, mobile applications, test, and dev
• Migrate our enterprise systems to the cloud over past 2 years
• Traditional newspaper, finance, and monitoring applications etc.
News Corp on AWS
• 2K+ EC2 instances
• 750+ TB S3 storage
• 300+ RDS instances
• Utilizing broad set of AWS services –
Amazon Elastic Compute Cloud (EC2), Amazon Relational Database Service,
Amazon Redshift, Amazon VPC, AWS Direct Connect, Amazon Route 53, Amazon
WorkSpaces, AWS Storage Gateway, Amazon Simple Storage Service (S3),
Amazon Glacier, Amazon CloudFront, AWS CloudFormation, AWS Config, Amazon
CloudWatch, AWS Trusted Advisor
• Key management/support tools: CloudHealth, New Relic, Puppet,
Rundeck, and more…
Platform supports many news UK digital products
What is cloud governance?
• Process to ensure secure, effective,
& efficient use of IT resources
• Includes compliance to policies
& best practices
• Covers cost, security,
availability, performance, & usage
Governance needs…
• Brand protection
• Cost control
• Management of business risk
• Compliance to policies &
standards
Why governance matters: A balancing act
Agility drives…
• Quick time to market
• Innovation
• Flexibility
The challenge of cloud governance
• Rapid pace of change
• Powerful cloud services/features
• Consumption-based pricing
• IT often influencer/auditor, not owner
• Decentralized management
• Disparate management tools
• Requires integration of multiple products & sources of data
Common cloud governance issues – News Corp
• No tagging
• Reluctance to invest in Reserved Instances
• Reserved Instances underutilised
• No rightsizing
• ELB left unused
• EBS volumes left unattached
• RDS instances with no active connections
• S3 storage exponential growth
• PoC and dev environments created and left
• Not shutting dev environments down at night
The unique challenge to the enterprise
• Ownership increasingly distributed to lines of
business that increasingly:
• Control infrastructure supporting their
businesses
• Go “rogue” to get around IT and achieve
business agility
• Do not taking into account importance of
governance, compliance, risk management
• IT increasingly influencer/auditor instead of owner
Where to start
• Establish a strategy & obtain stakeholder buy-in
• Evaluate & implement tool strategy
• Identify deliverables by stakeholder
• Implement, rinse, & repeat
Establish strategy
• Implications of competing priorities
• Digital teams require agility – speed of
products to market, embrace innovation
• Enterprise teams need to control costs,
preserve security and adhere to
governance, attract and retain good people
• What’s needed from a people perspective
• Acquiring and maintaining talent
• A focus on cloud consumption & usage
• Develop best practices
• Cloud steward
Agility Governance
Team
lead
Operations
Finance Engineering
LOBs
• Business group definition & implementation
• Tagging, naming conventions, metadata, etc.
• Data integrations
• Cost, budget, assets, configuration,
performance, security
• Report definitions and delivery
• Policy definition and implementation
• Analysis, recommendations, & optimization
actions
• Capacity planning, modeling, & forecasting
• Service-level reporting
Cloud steward:
Responsible for ongoing cloud optimization & governance
OPERATIONS
Evaluate & implement tool strategy
• AWSGO - enforced 7 P.M. shutdowns/snooze/start
• Delete unattached volumes >=5 days
• CloudHealth – Cost management & policy management
• Consigliere – One view for all AWS accounts Trusted Advisor
• NewRelic - APM
• Rundeck - Orchestration
• Puppet - Configuration
• Slack integration
Confidential
CEO
Global CIO Eng
Eng DevOps IT Ops
Cloud
Ops
CFO
FP&A
Fin
Analyst
LOB A
Eng DevOps IT Ops
Cloud
Ops
LOB B
Eng DevOps IT Ops
Cloud
Ops
Product & Function
Production Web
Development App
QA DB
Staging Storage
P&L & Department
OPEX/COGS
Product
Function
Customer
Business Unit
Product
Function
Customers
Business Unit
Product
Function
Customers
Perspectives
Cost Pulse
Health Check Pulse
RI Utilization Pulse
Cost by Group
Usage by Reservation Type
Reservation Modifications
Usage by Instance Type
Instance Rightsizing
Volume Rightsizing
Cost Pulse
Health Check Pulse
RI Utilization Pulse
Cost by Group
Usage by Reservation Type
Cost Pulse
Health Check Pulse
RI Utilization Pulse
Cost by Group
Usage by Reservation Type
Reservation Modifications
Usage by Instance Type
Instance Rightsizing
Volume Rightsizing
Cost Pulse
Health Check Pulse
RI Utilization Pulse
Cost by Group
Usage by Reservation Type
Reservation Modifications
Usage by Instance Type
Instance Rightsizing
Volume Rightsizing
Subscription
s
Over Budget
Purchase Reservations
Modify Reservations
Underutilized Instances
Unattached Volumes
Snapshot Aging
Untagged Assets
Start / Stop Instances
Over Budget
Modify Reservations
Purchase RI’s
Cost Per Group
Over Budget
Purchase Reservations
Modify Reservations
Underutilized Instances
Unattached Volumes
Snapshot Aging
Untagged Assets
Start / Stop Instances
Over Budget
Purchase Reservations
Modify Reservations
Underutilized Instances
Unattached Volumes
Snapshot Aging
Untagged Assets
Start / Stop Instances
PoliciesStakeholders Identify deliverables by stakeholder
BestPractices
Rinse & repeat: Continued improvements
• Enforced tagging – EC2, RDS, ELB,
EBS & Auto Scaling groups – delete
new instance if not tagged <15mins
• Daily cleanup:
• Delete EC2 instances shut down
for >=5 days
• Delete ELB no traffic >=5 days
• Delete EC2 no traffic >=5 days
Governing cost management: The total picture
• Right-size our current estate
• Invested in Reserved Instances
• Decommissioned what we didn’t need
• Implemented automation where possible
- CloudFormation & Chef/Puppet for us
• Implemented good governance – tagging
and service transition, including change
control – in progress
• Use the AWS Trusted Advisor service
Governing security management: Key requirements
• Security groups - NACLs reviewed and
updated to allow specific access.
• IAM roles - Groups created and applied to
instance. Functions and actions restricted.
• Networking - All ports closed. Open only what
is required.
• Users not active in News are removed.
• Antivirus set up on EC2 Windows instances
automatically.
• IAM users audited and user access modified.
Success criteria: The key metrics
• Architectural – adherence to standards/controls
• Cost – efficiency & lifecycle management, TCO, ROI
• Asset – adherence to configuration standard
• Security – compliance to best-practice configuration
• Adoption – rate of adoption
What’s next for governance
We need the equivalent of DevOps for cloud management
• Processes
• Set of roles
• Tooling
• Shared standards
5 best practices
Empower a centralized owner that
delivers real value to stakeholders
Don’t give up on agility
Create partnerships with strategic
vendors
Establish high-value policies
Automate, automate, automate
Thank you!
Remember to complete
your evaluations!
Related Sessions
Confidential
Current Security Offering
▪ Default policy for monitoring for AWS
▪ Monitors access control, network
security, application security & logging
▪ Reports violations with
recommendations
▪ Security violation management
▪ Include / exclude resources
▪ Group-based targeting
▪ Fully customizable & extensible
(including actions via Lambda)
▪ Integrates with Health Check
▪ Approval workflow for custom actions
▪ Per instance port-level reporting
Security Policies for AWS
Security Monitoring
Security Recommendations

More Related Content

What's hot

Partner webinar presentation aws pebble_treasure_data
Partner webinar presentation aws pebble_treasure_dataPartner webinar presentation aws pebble_treasure_data
Partner webinar presentation aws pebble_treasure_data
Treasure Data, Inc.
 
AWS re:Invent 2016: How Pitney Bowes is transforming their business in the cl...
AWS re:Invent 2016: How Pitney Bowes is transforming their business in the cl...AWS re:Invent 2016: How Pitney Bowes is transforming their business in the cl...
AWS re:Invent 2016: How Pitney Bowes is transforming their business in the cl...
Amazon Web Services
 

What's hot (20)

AWS re:Invent 2016: Zero to Google Chrome in 60 Minutes: Lightweight and Inex...
AWS re:Invent 2016: Zero to Google Chrome in 60 Minutes: Lightweight and Inex...AWS re:Invent 2016: Zero to Google Chrome in 60 Minutes: Lightweight and Inex...
AWS re:Invent 2016: Zero to Google Chrome in 60 Minutes: Lightweight and Inex...
 
Running Business Critical Workloads on AWS – Nam Je Cho
Running Business Critical Workloads on AWS – Nam Je ChoRunning Business Critical Workloads on AWS – Nam Je Cho
Running Business Critical Workloads on AWS – Nam Je Cho
 
What Organizational and Governance Changes Do I Need to Make Prior to Migrati...
What Organizational and Governance Changes Do I Need to Make Prior to Migrati...What Organizational and Governance Changes Do I Need to Make Prior to Migrati...
What Organizational and Governance Changes Do I Need to Make Prior to Migrati...
 
Born in the Cloud; Build it Like a Startup
Born in the Cloud; Build it Like a StartupBorn in the Cloud; Build it Like a Startup
Born in the Cloud; Build it Like a Startup
 
Tapping the cloud for real time data analytics
 Tapping the cloud for real time data analytics Tapping the cloud for real time data analytics
Tapping the cloud for real time data analytics
 
Partner webinar presentation aws pebble_treasure_data
Partner webinar presentation aws pebble_treasure_dataPartner webinar presentation aws pebble_treasure_data
Partner webinar presentation aws pebble_treasure_data
 
AWS re:Invent 2016: High Performance Cinematic Production in the Cloud (MAE304)
AWS re:Invent 2016: High Performance Cinematic Production in the Cloud (MAE304)AWS re:Invent 2016: High Performance Cinematic Production in the Cloud (MAE304)
AWS re:Invent 2016: High Performance Cinematic Production in the Cloud (MAE304)
 
AWS re:Invent 2016: Best practices for running enterprise workloads on AWS (E...
AWS re:Invent 2016: Best practices for running enterprise workloads on AWS (E...AWS re:Invent 2016: Best practices for running enterprise workloads on AWS (E...
AWS re:Invent 2016: Best practices for running enterprise workloads on AWS (E...
 
AWS re:Invent 2016: How Pitney Bowes is transforming their business in the cl...
AWS re:Invent 2016: How Pitney Bowes is transforming their business in the cl...AWS re:Invent 2016: How Pitney Bowes is transforming their business in the cl...
AWS re:Invent 2016: How Pitney Bowes is transforming their business in the cl...
 
AWS re:Invent 2016: Cloud Monitoring - Understanding, Preparing, and Troubles...
AWS re:Invent 2016: Cloud Monitoring - Understanding, Preparing, and Troubles...AWS re:Invent 2016: Cloud Monitoring - Understanding, Preparing, and Troubles...
AWS re:Invent 2016: Cloud Monitoring - Understanding, Preparing, and Troubles...
 
Cloud Economics and calculating CTO - AWSome Day Zurich 112016
Cloud Economics and calculating CTO - AWSome Day Zurich 112016Cloud Economics and calculating CTO - AWSome Day Zurich 112016
Cloud Economics and calculating CTO - AWSome Day Zurich 112016
 
AWS Summit Manila - Opening Keynote by Dr. Werner Vogels
AWS Summit Manila - Opening Keynote by Dr. Werner Vogels AWS Summit Manila - Opening Keynote by Dr. Werner Vogels
AWS Summit Manila - Opening Keynote by Dr. Werner Vogels
 
(BDT402) Delivering Business Agility Using AWS
(BDT402) Delivering Business Agility Using AWS(BDT402) Delivering Business Agility Using AWS
(BDT402) Delivering Business Agility Using AWS
 
Using real time big data analytics for competitive advantage
 Using real time big data analytics for competitive advantage Using real time big data analytics for competitive advantage
Using real time big data analytics for competitive advantage
 
Introducing Database Offerings on AWS - Technical 101
Introducing Database Offerings on AWS - Technical 101Introducing Database Offerings on AWS - Technical 101
Introducing Database Offerings on AWS - Technical 101
 
Welcome Keynote - AWS Summit Stockholm
Welcome Keynote - AWS Summit Stockholm Welcome Keynote - AWS Summit Stockholm
Welcome Keynote - AWS Summit Stockholm
 
From On-Premises to Cloud: Modernize Data Protection with Druva Phoenix and AWS
From On-Premises to Cloud:  Modernize Data Protection with Druva Phoenix and AWSFrom On-Premises to Cloud:  Modernize Data Protection with Druva Phoenix and AWS
From On-Premises to Cloud: Modernize Data Protection with Druva Phoenix and AWS
 
AWS re:Invent 2016: Storage State of the Union (STG201)
AWS re:Invent 2016: Storage State of the Union (STG201)AWS re:Invent 2016: Storage State of the Union (STG201)
AWS re:Invent 2016: Storage State of the Union (STG201)
 
AWS re:Invent 2016: Automating Cloud Management and Deployment for a Diverse ...
AWS re:Invent 2016: Automating Cloud Management and Deployment for a Diverse ...AWS re:Invent 2016: Automating Cloud Management and Deployment for a Diverse ...
AWS re:Invent 2016: Automating Cloud Management and Deployment for a Diverse ...
 
Application Migrations at Scale
Application Migrations at ScaleApplication Migrations at Scale
Application Migrations at Scale
 

Viewers also liked

Jazoon'12 Enterprise-wide Cloud Governance
Jazoon'12 Enterprise-wide Cloud GovernanceJazoon'12 Enterprise-wide Cloud Governance
Jazoon'12 Enterprise-wide Cloud Governance
Netcetera
 
Zinnov Media and Entertainment GSPR 2015
Zinnov Media and Entertainment GSPR 2015Zinnov Media and Entertainment GSPR 2015
Zinnov Media and Entertainment GSPR 2015
Zinnov
 
Accountability for Data Governance in the Cloud
Accountability for Data Governance in the CloudAccountability for Data Governance in the Cloud
Accountability for Data Governance in the Cloud
Massimo Felici
 

Viewers also liked (20)

AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
AWS re:Invent 2016: Governance Strategies for Cloud Transformation (WWPS302)
 
Governing in the Cloud
Governing in the CloudGoverning in the Cloud
Governing in the Cloud
 
Azure cloud governance deck
Azure cloud governance deckAzure cloud governance deck
Azure cloud governance deck
 
JetSweep & CloudHealth Tech: Journey to the Cloud
JetSweep & CloudHealth Tech: Journey to the CloudJetSweep & CloudHealth Tech: Journey to the Cloud
JetSweep & CloudHealth Tech: Journey to the Cloud
 
Jazoon'12 Enterprise-wide Cloud Governance
Jazoon'12 Enterprise-wide Cloud GovernanceJazoon'12 Enterprise-wide Cloud Governance
Jazoon'12 Enterprise-wide Cloud Governance
 
Cloud Governance Framework - Required Cloud Sourcing Capabilities
Cloud Governance Framework - Required Cloud Sourcing CapabilitiesCloud Governance Framework - Required Cloud Sourcing Capabilities
Cloud Governance Framework - Required Cloud Sourcing Capabilities
 
Best of re:Invent
Best of re:InventBest of re:Invent
Best of re:Invent
 
AWS re:Invent 2016: Case Study: How Startups like Mapbox, Ring, Hudl, and Oth...
AWS re:Invent 2016: Case Study: How Startups like Mapbox, Ring, Hudl, and Oth...AWS re:Invent 2016: Case Study: How Startups like Mapbox, Ring, Hudl, and Oth...
AWS re:Invent 2016: Case Study: How Startups like Mapbox, Ring, Hudl, and Oth...
 
AWS re:Invent 2016: How Aptean uses AWS Marketplace storage solutions to back...
AWS re:Invent 2016: How Aptean uses AWS Marketplace storage solutions to back...AWS re:Invent 2016: How Aptean uses AWS Marketplace storage solutions to back...
AWS re:Invent 2016: How Aptean uses AWS Marketplace storage solutions to back...
 
AWS Governance Overview - Beach
AWS Governance Overview - BeachAWS Governance Overview - Beach
AWS Governance Overview - Beach
 
Zinnov Media and Entertainment GSPR 2015
Zinnov Media and Entertainment GSPR 2015Zinnov Media and Entertainment GSPR 2015
Zinnov Media and Entertainment GSPR 2015
 
Operating Your Production API
Operating Your Production APIOperating Your Production API
Operating Your Production API
 
Security and governance in the cloud
Security and governance in the cloudSecurity and governance in the cloud
Security and governance in the cloud
 
AWS re:Invent 2016: Modernizing Government in the Cloud in Highly Regulated E...
AWS re:Invent 2016: Modernizing Government in the Cloud in Highly Regulated E...AWS re:Invent 2016: Modernizing Government in the Cloud in Highly Regulated E...
AWS re:Invent 2016: Modernizing Government in the Cloud in Highly Regulated E...
 
Accountability for Data Governance in the Cloud
Accountability for Data Governance in the CloudAccountability for Data Governance in the Cloud
Accountability for Data Governance in the Cloud
 
AWS re:Invent Recap 2016 Taiwan part 2
AWS re:Invent Recap 2016 Taiwan part 2AWS re:Invent Recap 2016 Taiwan part 2
AWS re:Invent Recap 2016 Taiwan part 2
 
使用 Amazon Pinpoint 讓你的行動 App 更精準接觸客群
使用 Amazon Pinpoint 讓你的行動 App 更精準接觸客群使用 Amazon Pinpoint 讓你的行動 App 更精準接觸客群
使用 Amazon Pinpoint 讓你的行動 App 更精準接觸客群
 
AWS re:Invent 2016: Building the Future of DevOps with Amazon Web Services (D...
AWS re:Invent 2016: Building the Future of DevOps with Amazon Web Services (D...AWS re:Invent 2016: Building the Future of DevOps with Amazon Web Services (D...
AWS re:Invent 2016: Building the Future of DevOps with Amazon Web Services (D...
 
Visibility, Optimization & Governance for Cloud Services
Visibility, Optimization & Governance for Cloud ServicesVisibility, Optimization & Governance for Cloud Services
Visibility, Optimization & Governance for Cloud Services
 
Announcing Amazon Pinpoint - January 2017 AWS Online Tech Talks
Announcing Amazon Pinpoint - January 2017 AWS Online Tech TalksAnnouncing Amazon Pinpoint - January 2017 AWS Online Tech Talks
Announcing Amazon Pinpoint - January 2017 AWS Online Tech Talks
 

Similar to AWS re:Invent 2016: How News UK Centralized Cloud Governance Through Policy Management (DEV306)

Similar to AWS re:Invent 2016: How News UK Centralized Cloud Governance Through Policy Management (DEV306) (20)

Creating an Operating Model to enable a high frequency organization
Creating an Operating Model to enable a high frequency organizationCreating an Operating Model to enable a high frequency organization
Creating an Operating Model to enable a high frequency organization
 
Cloud Adoption Framework - Walking Deck (L100).pptx
Cloud Adoption Framework - Walking Deck (L100).pptxCloud Adoption Framework - Walking Deck (L100).pptx
Cloud Adoption Framework - Walking Deck (L100).pptx
 
AWS Enterprise Summit - AWS로 IT 운영 및 관리 재편하기 - 양승도
AWS Enterprise Summit -  AWS로 IT 운영 및 관리 재편하기 - 양승도AWS Enterprise Summit -  AWS로 IT 운영 및 관리 재편하기 - 양승도
AWS Enterprise Summit - AWS로 IT 운영 및 관리 재편하기 - 양승도
 
Cloud Service Provider in India | Cloud Solution and Consulting
Cloud Service Provider in India | Cloud Solution and ConsultingCloud Service Provider in India | Cloud Solution and Consulting
Cloud Service Provider in India | Cloud Solution and Consulting
 
IT Transformation with AWS
IT Transformation with AWSIT Transformation with AWS
IT Transformation with AWS
 
Phil Green - We're migrating to the cloud - Who needs service management
Phil Green - We're migrating to the cloud - Who needs service managementPhil Green - We're migrating to the cloud - Who needs service management
Phil Green - We're migrating to the cloud - Who needs service management
 
estrat AWS Cloud Breakfast
estrat AWS Cloud Breakfastestrat AWS Cloud Breakfast
estrat AWS Cloud Breakfast
 
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
Azure Cloud Adoption Framework + Governance - Sana Khan and Jay Kumar
 
Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016
Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016
Governance Strategies for Cloud Transformation | AWS Public Sector Summit 2016
 
B2 - Integrating on-premises workloads with AWS
B2 - Integrating on-premises workloads with AWSB2 - Integrating on-premises workloads with AWS
B2 - Integrating on-premises workloads with AWS
 
AWS re:Invent 2016: Start Your Cost Optimization Program: Learning from Intui...
AWS re:Invent 2016: Start Your Cost Optimization Program: Learning from Intui...AWS re:Invent 2016: Start Your Cost Optimization Program: Learning from Intui...
AWS re:Invent 2016: Start Your Cost Optimization Program: Learning from Intui...
 
Singlepoint AWS Well-Architected Review
Singlepoint AWS Well-Architected ReviewSinglepoint AWS Well-Architected Review
Singlepoint AWS Well-Architected Review
 
Accenture 2014 AWS re:Invent Enterprise Migration Breakout Session
Accenture 2014 AWS re:Invent Enterprise Migration Breakout SessionAccenture 2014 AWS re:Invent Enterprise Migration Breakout Session
Accenture 2014 AWS re:Invent Enterprise Migration Breakout Session
 
Deep Dive on Cloud Policies and Automation
Deep Dive on Cloud Policies and AutomationDeep Dive on Cloud Policies and Automation
Deep Dive on Cloud Policies and Automation
 
Building Your Cloud Strategy
Building Your Cloud StrategyBuilding Your Cloud Strategy
Building Your Cloud Strategy
 
Going Global with Itoc and AWS
Going Global with Itoc and AWS Going Global with Itoc and AWS
Going Global with Itoc and AWS
 
Prepare Your Enterprise Cloud Strategy for 2019: 7 Things to Think About Now
Prepare Your Enterprise Cloud Strategy for 2019: 7 Things to Think About NowPrepare Your Enterprise Cloud Strategy for 2019: 7 Things to Think About Now
Prepare Your Enterprise Cloud Strategy for 2019: 7 Things to Think About Now
 
Total cloud control with oracle enterprise manager 12c
Total cloud control with oracle enterprise manager 12cTotal cloud control with oracle enterprise manager 12c
Total cloud control with oracle enterprise manager 12c
 
Microsoft Cloud Adoption Framework for Azure: Governance Conversation
Microsoft Cloud Adoption Framework for Azure: Governance ConversationMicrosoft Cloud Adoption Framework for Azure: Governance Conversation
Microsoft Cloud Adoption Framework for Azure: Governance Conversation
 
Softchoice Discovery Series: Cloud Cost Governance
Softchoice Discovery Series: Cloud Cost GovernanceSoftchoice Discovery Series: Cloud Cost Governance
Softchoice Discovery Series: Cloud Cost Governance
 

More from Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Recently uploaded

Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
Safe Software
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
Bhaskar Mitra
 
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Peter Udo Diehl
 

Recently uploaded (20)

Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
 
Essentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with ParametersEssentials of Automations: Optimizing FME Workflows with Parameters
Essentials of Automations: Optimizing FME Workflows with Parameters
 
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
De-mystifying Zero to One: Design Informed Techniques for Greenfield Innovati...
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
 
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo DiehlFuture Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
Future Visions: Predictions to Guide and Time Tech Innovation, Peter Udo Diehl
 
Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...Designing Great Products: The Power of Design and Leadership by Chief Designe...
Designing Great Products: The Power of Design and Leadership by Chief Designe...
 
UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2
 
Exploring UiPath Orchestrator API: updates and limits in 2024 🚀
Exploring UiPath Orchestrator API: updates and limits in 2024 🚀Exploring UiPath Orchestrator API: updates and limits in 2024 🚀
Exploring UiPath Orchestrator API: updates and limits in 2024 🚀
 
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptxUnpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
 
Speed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in MinutesSpeed Wins: From Kafka to APIs in Minutes
Speed Wins: From Kafka to APIs in Minutes
 
Quantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIsQuantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIs
 
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
Unsubscribed: Combat Subscription Fatigue With a Membership Mentality by Head...
 
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...Transcript: Selling digital books in 2024: Insights from industry leaders - T...
Transcript: Selling digital books in 2024: Insights from industry leaders - T...
 
Demystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John StaveleyDemystifying gRPC in .Net by John Staveley
Demystifying gRPC in .Net by John Staveley
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 

AWS re:Invent 2016: How News UK Centralized Cloud Governance Through Policy Management (DEV306)

  • 1. © 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Joe Kinsella, CTO & Founder, CloudHealth Technologies Iain Caldwell, Head of Infrastructure, News UK & News Corp EMEA November 30, 2016 DEV 306 News UK: Achieving Centralized Governance Through Policy Management
  • 2. Presenters Joe Kinsella, CTO & Founder CloudHealth Technologies @joekinsella Iain Caldwell, Head of Infrastructure News UK & News Corp EMEA @caldi100
  • 3. What to expect from this session • Overview of News Corp’s use of AWS • Why governance is critical to cloud success • How to drive a governance strategy • 5 best practices
  • 4. News Corp strategy • CTO set objective to reduce data centre footprint and associated costs • Host 75% of estate in the public cloud within next three years. • News UK currently running at 69% aiming to make 75% by July 2017 • Before we started in 2011 we built our AWS Cloud data centre • Ran a global application assessment for cloud readiness across all BUs • Digital estate was the main contender for cloud – web-based applications, mobile applications, test, and dev • Migrate our enterprise systems to the cloud over past 2 years • Traditional newspaper, finance, and monitoring applications etc.
  • 5. News Corp on AWS • 2K+ EC2 instances • 750+ TB S3 storage • 300+ RDS instances • Utilizing broad set of AWS services – Amazon Elastic Compute Cloud (EC2), Amazon Relational Database Service, Amazon Redshift, Amazon VPC, AWS Direct Connect, Amazon Route 53, Amazon WorkSpaces, AWS Storage Gateway, Amazon Simple Storage Service (S3), Amazon Glacier, Amazon CloudFront, AWS CloudFormation, AWS Config, Amazon CloudWatch, AWS Trusted Advisor • Key management/support tools: CloudHealth, New Relic, Puppet, Rundeck, and more…
  • 6. Platform supports many news UK digital products
  • 7. What is cloud governance? • Process to ensure secure, effective, & efficient use of IT resources • Includes compliance to policies & best practices • Covers cost, security, availability, performance, & usage
  • 8. Governance needs… • Brand protection • Cost control • Management of business risk • Compliance to policies & standards Why governance matters: A balancing act Agility drives… • Quick time to market • Innovation • Flexibility
  • 9. The challenge of cloud governance • Rapid pace of change • Powerful cloud services/features • Consumption-based pricing • IT often influencer/auditor, not owner • Decentralized management • Disparate management tools • Requires integration of multiple products & sources of data
  • 10. Common cloud governance issues – News Corp • No tagging • Reluctance to invest in Reserved Instances • Reserved Instances underutilised • No rightsizing • ELB left unused • EBS volumes left unattached • RDS instances with no active connections • S3 storage exponential growth • PoC and dev environments created and left • Not shutting dev environments down at night
  • 11. The unique challenge to the enterprise • Ownership increasingly distributed to lines of business that increasingly: • Control infrastructure supporting their businesses • Go “rogue” to get around IT and achieve business agility • Do not taking into account importance of governance, compliance, risk management • IT increasingly influencer/auditor instead of owner
  • 12. Where to start • Establish a strategy & obtain stakeholder buy-in • Evaluate & implement tool strategy • Identify deliverables by stakeholder • Implement, rinse, & repeat
  • 13. Establish strategy • Implications of competing priorities • Digital teams require agility – speed of products to market, embrace innovation • Enterprise teams need to control costs, preserve security and adhere to governance, attract and retain good people • What’s needed from a people perspective • Acquiring and maintaining talent • A focus on cloud consumption & usage • Develop best practices • Cloud steward Agility Governance
  • 14. Team lead Operations Finance Engineering LOBs • Business group definition & implementation • Tagging, naming conventions, metadata, etc. • Data integrations • Cost, budget, assets, configuration, performance, security • Report definitions and delivery • Policy definition and implementation • Analysis, recommendations, & optimization actions • Capacity planning, modeling, & forecasting • Service-level reporting Cloud steward: Responsible for ongoing cloud optimization & governance OPERATIONS
  • 15. Evaluate & implement tool strategy • AWSGO - enforced 7 P.M. shutdowns/snooze/start • Delete unattached volumes >=5 days • CloudHealth – Cost management & policy management • Consigliere – One view for all AWS accounts Trusted Advisor • NewRelic - APM • Rundeck - Orchestration • Puppet - Configuration • Slack integration
  • 16. Confidential CEO Global CIO Eng Eng DevOps IT Ops Cloud Ops CFO FP&A Fin Analyst LOB A Eng DevOps IT Ops Cloud Ops LOB B Eng DevOps IT Ops Cloud Ops Product & Function Production Web Development App QA DB Staging Storage P&L & Department OPEX/COGS Product Function Customer Business Unit Product Function Customers Business Unit Product Function Customers Perspectives Cost Pulse Health Check Pulse RI Utilization Pulse Cost by Group Usage by Reservation Type Reservation Modifications Usage by Instance Type Instance Rightsizing Volume Rightsizing Cost Pulse Health Check Pulse RI Utilization Pulse Cost by Group Usage by Reservation Type Cost Pulse Health Check Pulse RI Utilization Pulse Cost by Group Usage by Reservation Type Reservation Modifications Usage by Instance Type Instance Rightsizing Volume Rightsizing Cost Pulse Health Check Pulse RI Utilization Pulse Cost by Group Usage by Reservation Type Reservation Modifications Usage by Instance Type Instance Rightsizing Volume Rightsizing Subscription s Over Budget Purchase Reservations Modify Reservations Underutilized Instances Unattached Volumes Snapshot Aging Untagged Assets Start / Stop Instances Over Budget Modify Reservations Purchase RI’s Cost Per Group Over Budget Purchase Reservations Modify Reservations Underutilized Instances Unattached Volumes Snapshot Aging Untagged Assets Start / Stop Instances Over Budget Purchase Reservations Modify Reservations Underutilized Instances Unattached Volumes Snapshot Aging Untagged Assets Start / Stop Instances PoliciesStakeholders Identify deliverables by stakeholder BestPractices
  • 17. Rinse & repeat: Continued improvements • Enforced tagging – EC2, RDS, ELB, EBS & Auto Scaling groups – delete new instance if not tagged <15mins • Daily cleanup: • Delete EC2 instances shut down for >=5 days • Delete ELB no traffic >=5 days • Delete EC2 no traffic >=5 days
  • 18. Governing cost management: The total picture • Right-size our current estate • Invested in Reserved Instances • Decommissioned what we didn’t need • Implemented automation where possible - CloudFormation & Chef/Puppet for us • Implemented good governance – tagging and service transition, including change control – in progress • Use the AWS Trusted Advisor service
  • 19. Governing security management: Key requirements • Security groups - NACLs reviewed and updated to allow specific access. • IAM roles - Groups created and applied to instance. Functions and actions restricted. • Networking - All ports closed. Open only what is required. • Users not active in News are removed. • Antivirus set up on EC2 Windows instances automatically. • IAM users audited and user access modified.
  • 20. Success criteria: The key metrics • Architectural – adherence to standards/controls • Cost – efficiency & lifecycle management, TCO, ROI • Asset – adherence to configuration standard • Security – compliance to best-practice configuration • Adoption – rate of adoption
  • 21. What’s next for governance We need the equivalent of DevOps for cloud management • Processes • Set of roles • Tooling • Shared standards
  • 22. 5 best practices Empower a centralized owner that delivers real value to stakeholders Don’t give up on agility Create partnerships with strategic vendors Establish high-value policies Automate, automate, automate
  • 26. Confidential Current Security Offering ▪ Default policy for monitoring for AWS ▪ Monitors access control, network security, application security & logging ▪ Reports violations with recommendations ▪ Security violation management ▪ Include / exclude resources ▪ Group-based targeting ▪ Fully customizable & extensible (including actions via Lambda) ▪ Integrates with Health Check ▪ Approval workflow for custom actions ▪ Per instance port-level reporting Security Policies for AWS Security Monitoring Security Recommendations