SlideShare a Scribd company logo
© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Greg Share, Solutions Architect
April 12th, 2018
Governance @ Scale
Compliance Automation at AWS
Why are we here?
Common governance questions
• How do I determine the current state of all cloud users and their
access rights across the enterprise?
• How do I ensure adherence to IT budgets in a pay-per-use model
• How do I ensure deployments and operations are compliant with
relevant legal, regulatory, and/or contractual policies?
• How do I ensure security posture is enforced across accounts and
workloads?
• WITHOUT REDUCING THE AGILITY OF THE CLOUD
Typical enterprise AWS adoption
• In highly federated organizations,
AWS adoption flows from the
bottom up
• In parallel, central IT often begins
mirroring the on-premises
architecture in AWS
• Governance approach should:
• Meet organizational requirements
• Scale
• Allow direct use of approved AWS
services and APIs
Top down
adoption
Bottom up
adoption
Tradeoffs in AWS adoption approaches
Minimally encumbered AWS accounts
• Complete power of the AWS platform;
every feature available immediately
• Requires the building or buying a
solution that can manage many AWS
accounts
• Account provisioning and budget
enforcement @scale can be automated
• Uniform security controls and
operations
Service catalog/cloud broker approach
• Prescribes limited access to the AWS
platform based on catalog templates
or via middleware
• Suitable for meeting common
requirements of less-technical internal
users
• Doesn’t allow developers to access
cloud APIs
• Doesn’t provide enough value or
flexibility in large enterprises
What’s your challenge as AWS adoption grows?
Amazon
S3
Project 1 AWS Account
Amazon
EC2
Project 2 AWS Account
Amazon
S3
Amazon
EC2
Amazon
RDS
Stage 1
Specific Systems
Limited Accounts
Minimal Services
Stage 2
Numerous Systems
Multiple Accounts
Many Services
Amazon
S3
Project 1 AWS Account
Amazon
EC2
Amazon
VPC
Amazon
S3
Project 2 AWS Account
Amazon
EC2
Amazon
VPC
Amazon
EMR
Amazon
Kinesis
Amazon
Redshift
Project 3 AWS Account
Amazon
S3
Project 4 AWS
Account
Amazon
EC2
Project 5 AWS
Account
Amazon API
Gateway
Amazon
SQS
Amazon
WorkSpaces
Amazon
ECS
AWS
Lambda
AWS Elastic
BeanstalkAmazon
S3
Amazon
S3
Project 6 AWS
Account
Amazon
EC2
Amazon
EMR
Amazon
Kinesis
Amazon
VPC
Governance is not a “one size fits all”
Higher-impact workloads are
more likely to be managed by
central or departmental IT
groups and will have more
security controls.
Lower-impact workloads still
have basic security controls,
but can be issued freely to
end users for test,
development, or low impact
research and production
workloads.Low High
High
Low
Availability
Confidentiality
Three principles of governance@scale
Account management
• Standardize and streamline provisioning, maintenance, and access control
policies for many AWS accounts and workloads
Cost enforcement
• Ensure AWS accounts and workloads do not exceed budget
Compliance automation
• Provide continuous monitoring, configuration management, and enforce
security controls
So…what does this look like?
Projects
Management
Upper Management
Senior Leadership
Executive CXO
VP
Director
Manager Manager
Director
Manager
VP
Director
Manager Manager
Project 1
Project 2
Project 3 Project 5 Project 6
Project 7
Project 8
$
$
$ $$
$
$
$ $ $
$
$$
$
$
$
$
$
How you get this security visibility
Projects
Data Analyst
Management
Senior Leadership
Executive CXO
VP
Director
Analyst Analyst
Director
Analyst
VP
Director
Analyst Analyst
Project 1
Project 2
Project 3 Project 5 Project 6
Project 7
Project 8
P1:
P2:
P3:
P5:
P6:
P7:
P8:
25%:
0%:
75%:
0%:
35%:
65%:
Account management @scale
• Use a consolidated admin AWS account
• AWS Identity & Access Management (IAM) users live in this account
• IAM users assume roles to access other AWS accounts
• Enforce MFA for role assumption
• Automate AWS account provisioning
• Eliminate slow, error-prone manual provisioning
• Ensure AWS accounts are actively managed
• Incentivizes users from using other methods (personal, school, etc.) for AWS
experimentation.
• Implement “single sign-on” through federation
• Use enterprise accelerators as a starting point
• Policy assignment to IAM users/groups/roles
• Consolidated admin baseline
• Target account baseline
Consolidated Admin
AWS Account
IAM users
users stack security
baseline
stack
Automate provisioning of target accounts
Target AWS Account
admin
role
billing
role
read
only role
baseline
stack
Target AWS Account
admin
role
billing
role
read
only role
baseline
stack
Target AWS Account
admin
role
billing
role
read
only role
baseline
stack
Key configuration points to baseline accounts
AWS CloudFormation
Leverage Enterprise Accelerator Compliance “Quick Starts”
Amazon
CloudWatch
AWS Config
Config Rules
AWS CloudTrail
CloudWatch
Events
Manual configuration
Root MFA
Alternate contacts
IAM
Managed
Policies
Roles
Security questions
Amazon
VPC
VPC peering
Flow logs
Cost enforcement @scale
• Use automation to map AWS accounts to org. structure
• Aligns with current budget process and cost alignments
• Use automation for cost management/enforcement
• Actual spend vs. budget projections decision makers.
• Allow management to increase budgets
• Turn off resources to preserve budget
• Use dynamic IAM policies to throttle usage when budget thresholds
are met
• Provide near-real time budget projections so
stakeholders are aware of current AWS spend
Cost enforcement @scale
Projects
Management
Upper Management
Senior Leadership
Executive CXO
VP
Director
Manager Manager
Director
Manager
VP
Director
Manager Manager
Project 1
Project 2
Project 3 Project 5 Project 6
Project 7
Project 8
$
$
$ $$
$
$
$$$$$
$$$$$
$ $ $$$$
$$$$$$ $$$$
$$$$$ $$$$
Cost enforcement @scale: metering
No alerts, no charge.
Smart agent won’t alert or charge when
instances are turned off to save money.
Seamlessly get logs and continue providing
protection when instances are turned back on.
OFF
ON
Compliance automation @scale
• Pre-approve standard security configurations to decrease RMF
efforts up to 50% and achieve faster ATOs (days vs. months/years)
• Automate deployment of accounts consistent with security policies
(NIST/HIPAA)
• Installing instance level account and security tools via Security Tools
• Pre-populate GRC tools with inherited and system specific controls
(ex Telos Xacta)
• Perform continuous monitoring with GRC tools and alert security
staff of configuration drift and/or vulnerabilities
• Send all AWS account log files to centralized data lake for security
analysis
Projects
Management
Upper Management
Senior Leadership
Executive CXO
VP
Director
Manager Manager
Director
Manager
VP
Director
Manager Manager
Project 1
Project 2
Project 3 Project 5 Project 6
Project 7
Project 8
Compliance automation @scale
Security automation @ scale
Recommendation scan: Policy tailored to governance and workload
Deployed with repeatable generic code
Implement policies dynamically at runtime based on
workload tags.
Security automation @scale
Where do I go from here?
• Build or buy a governance@scale solution that can grow with you.
• Professional Services can help facilitate the design and help
you build a solution based on your requirements.
• Partner Solutions are available (CloudTamer by Stratus
Solutions )
• Incorporate and automate security and operations management
tools into infrastructure provisioning
• If you can’t automate third-party products with AWS, then they aren’t
built for AWS
• Security needs to have parity for enabling visibility for this
governance model
Thank You
Greg Share, gshare@amazon.co.uk

More Related Content

What's hot

How to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdfHow to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdf
Amazon Web Services
 
Security & Compliance
Security & ComplianceSecurity & Compliance
Security & Compliance
Amazon Web Services
 
AWS per la semplificazione del percorso di conformità al GDPR
AWS per la semplificazione del percorso di conformità al GDPRAWS per la semplificazione del percorso di conformità al GDPR
AWS per la semplificazione del percorso di conformità al GDPR
Amazon Web Services
 
Deep Dive - AWS Security by Design
Deep Dive - AWS Security by DesignDeep Dive - AWS Security by Design
Deep Dive - AWS Security by Design
Amazon Web Services
 
Enabling Compliance with EU Privacy Laws
Enabling Compliance with EU Privacy LawsEnabling Compliance with EU Privacy Laws
Enabling Compliance with EU Privacy Laws
Amazon Web Services
 
Managing Security on AWS
Managing Security on AWSManaging Security on AWS
Managing Security on AWS
Amazon Web Services
 
Building an Automated Security Fabric in AWS
Building an Automated Security Fabric in AWSBuilding an Automated Security Fabric in AWS
Building an Automated Security Fabric in AWS
Amazon Web Services
 
Enabling Compliance with GDPR on AWS.pdf
Enabling Compliance with GDPR on AWS.pdfEnabling Compliance with GDPR on AWS.pdf
Enabling Compliance with GDPR on AWS.pdf
Amazon Web Services
 
Best Practices for Encrypting Data on AWS
Best Practices for Encrypting Data on AWSBest Practices for Encrypting Data on AWS
Best Practices for Encrypting Data on AWS
Amazon Web Services
 
AWS Security Best Practices
AWS Security Best PracticesAWS Security Best Practices
AWS Security Best Practices
Aleksandr Maklakov
 
AWS Security Week: Security, Identity, & Compliance
AWS Security Week: Security, Identity, & ComplianceAWS Security Week: Security, Identity, & Compliance
AWS Security Week: Security, Identity, & Compliance
Amazon Web Services
 
AWS-Vizalytics-March-2018 2.pdf
AWS-Vizalytics-March-2018 2.pdfAWS-Vizalytics-March-2018 2.pdf
AWS-Vizalytics-March-2018 2.pdf
Amazon Web Services
 
The Perimeter Is Dead
The Perimeter Is DeadThe Perimeter Is Dead
The Perimeter Is Dead
Amazon Web Services
 
Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...
Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...
Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...
Amazon Web Services
 
McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...
McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...
McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...
Amazon Web Services
 
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Amazon Web Services
 
Top Cloud Security Myths - Dispelled! (SEC202-R1) - AWS re:Invent 2018
Top Cloud Security Myths - Dispelled! (SEC202-R1) - AWS re:Invent 2018Top Cloud Security Myths - Dispelled! (SEC202-R1) - AWS re:Invent 2018
Top Cloud Security Myths - Dispelled! (SEC202-R1) - AWS re:Invent 2018
Amazon Web Services
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
Amazon Web Services
 
Intro to AWS: Security
Intro to AWS: SecurityIntro to AWS: Security
Intro to AWS: Security
Amazon Web Services
 
AWS Storage Stage of Union
AWS Storage Stage of UnionAWS Storage Stage of Union
AWS Storage Stage of Union
Amazon Web Services
 

What's hot (20)

How to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdfHow to Implement a Well-Architected Security Solution.pdf
How to Implement a Well-Architected Security Solution.pdf
 
Security & Compliance
Security & ComplianceSecurity & Compliance
Security & Compliance
 
AWS per la semplificazione del percorso di conformità al GDPR
AWS per la semplificazione del percorso di conformità al GDPRAWS per la semplificazione del percorso di conformità al GDPR
AWS per la semplificazione del percorso di conformità al GDPR
 
Deep Dive - AWS Security by Design
Deep Dive - AWS Security by DesignDeep Dive - AWS Security by Design
Deep Dive - AWS Security by Design
 
Enabling Compliance with EU Privacy Laws
Enabling Compliance with EU Privacy LawsEnabling Compliance with EU Privacy Laws
Enabling Compliance with EU Privacy Laws
 
Managing Security on AWS
Managing Security on AWSManaging Security on AWS
Managing Security on AWS
 
Building an Automated Security Fabric in AWS
Building an Automated Security Fabric in AWSBuilding an Automated Security Fabric in AWS
Building an Automated Security Fabric in AWS
 
Enabling Compliance with GDPR on AWS.pdf
Enabling Compliance with GDPR on AWS.pdfEnabling Compliance with GDPR on AWS.pdf
Enabling Compliance with GDPR on AWS.pdf
 
Best Practices for Encrypting Data on AWS
Best Practices for Encrypting Data on AWSBest Practices for Encrypting Data on AWS
Best Practices for Encrypting Data on AWS
 
AWS Security Best Practices
AWS Security Best PracticesAWS Security Best Practices
AWS Security Best Practices
 
AWS Security Week: Security, Identity, & Compliance
AWS Security Week: Security, Identity, & ComplianceAWS Security Week: Security, Identity, & Compliance
AWS Security Week: Security, Identity, & Compliance
 
AWS-Vizalytics-March-2018 2.pdf
AWS-Vizalytics-March-2018 2.pdfAWS-Vizalytics-March-2018 2.pdf
AWS-Vizalytics-March-2018 2.pdf
 
The Perimeter Is Dead
The Perimeter Is DeadThe Perimeter Is Dead
The Perimeter Is Dead
 
Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...
Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...
Security at Scale: Security Hub and the Well Architected Framework - AWS Summ...
 
McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...
McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...
McAfee Skyhigh: Elevating Your AWS Security Posture (SEC307-S) - AWS re:Inven...
 
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
 
Top Cloud Security Myths - Dispelled! (SEC202-R1) - AWS re:Invent 2018
Top Cloud Security Myths - Dispelled! (SEC202-R1) - AWS re:Invent 2018Top Cloud Security Myths - Dispelled! (SEC202-R1) - AWS re:Invent 2018
Top Cloud Security Myths - Dispelled! (SEC202-R1) - AWS re:Invent 2018
 
Introduction to AWS Security
Introduction to AWS SecurityIntroduction to AWS Security
Introduction to AWS Security
 
Intro to AWS: Security
Intro to AWS: SecurityIntro to AWS: Security
Intro to AWS: Security
 
AWS Storage Stage of Union
AWS Storage Stage of UnionAWS Storage Stage of Union
AWS Storage Stage of Union
 

Similar to Governance at Scale

Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
Amazon Web Services
 
AWS re:Invent 2016: Reduce Your Blast Radius by Using Multiple AWS Accounts P...
AWS re:Invent 2016: Reduce Your Blast Radius by Using Multiple AWS Accounts P...AWS re:Invent 2016: Reduce Your Blast Radius by Using Multiple AWS Accounts P...
AWS re:Invent 2016: Reduce Your Blast Radius by Using Multiple AWS Accounts P...
Amazon Web Services
 
Serverless Security Automation | AWS Public Sector Summit 2017
Serverless Security Automation | AWS Public Sector Summit 2017Serverless Security Automation | AWS Public Sector Summit 2017
Serverless Security Automation | AWS Public Sector Summit 2017
Amazon Web Services
 
Benefits of Cloud Computing
Benefits of Cloud ComputingBenefits of Cloud Computing
Benefits of Cloud Computing
Amazon Web Services
 
AWS Landing Zone - Architecting Security and Governance
AWS Landing Zone - Architecting Security and GovernanceAWS Landing Zone - Architecting Security and Governance
AWS Landing Zone - Architecting Security and Governance
Akesh Patil
 
Steve Seaney_AWS Control Tower - 2023 Midwest Community Day - Final.pptx
Steve Seaney_AWS Control Tower - 2023 Midwest Community Day - Final.pptxSteve Seaney_AWS Control Tower - 2023 Midwest Community Day - Final.pptx
Steve Seaney_AWS Control Tower - 2023 Midwest Community Day - Final.pptx
AWS Chicago
 
AWS Governance at Scale_AWSPSSummit_Singapore
AWS Governance at Scale_AWSPSSummit_SingaporeAWS Governance at Scale_AWSPSSummit_Singapore
AWS Governance at Scale_AWSPSSummit_Singapore
Amazon Web Services
 
(ISM206) Modern IT Governance Through Transparency and Automation
(ISM206) Modern IT Governance Through Transparency and Automation(ISM206) Modern IT Governance Through Transparency and Automation
(ISM206) Modern IT Governance Through Transparency and Automation
Amazon Web Services
 
(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS
(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS
(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS
Amazon Web Services
 
Security Architecture recommendations for your new AWS operation - Pop-up Lof...
Security Architecture recommendations for your new AWS operation - Pop-up Lof...Security Architecture recommendations for your new AWS operation - Pop-up Lof...
Security Architecture recommendations for your new AWS operation - Pop-up Lof...
Amazon Web Services
 
Cloud Governance and Provisioning Management using AWS Management Tools and S...
Cloud Governance and Provisioning Management using AWS Management Tools and S...Cloud Governance and Provisioning Management using AWS Management Tools and S...
Cloud Governance and Provisioning Management using AWS Management Tools and S...
Amazon Web Services
 
Simplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing ZoneSimplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing Zone
Amazon Web Services
 
Launch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
Launch AWS Faster using Automated Landing Zones - AWS Online Tech TalksLaunch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
Launch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
Amazon Web Services
 
ENT302 Deep Dive on AWS Management Tools and New Launches
ENT302 Deep Dive on AWS Management Tools and New LaunchesENT302 Deep Dive on AWS Management Tools and New Launches
ENT302 Deep Dive on AWS Management Tools and New Launches
Amazon Web Services
 
The Automation of Supervision Governance in the Cloud
The Automation of Supervision Governance in the CloudThe Automation of Supervision Governance in the Cloud
The Automation of Supervision Governance in the Cloud
Amazon Web Services
 
Track 5 Session 2_SEC01 多重帳戶安全策略與方針.pptx
Track 5 Session 2_SEC01 多重帳戶安全策略與方針.pptxTrack 5 Session 2_SEC01 多重帳戶安全策略與方針.pptx
Track 5 Session 2_SEC01 多重帳戶安全策略與方針.pptxAmazon Web Services
 
ENT302 Deep Dive on AWS Management Tools
ENT302 Deep Dive on AWS Management Tools ENT302 Deep Dive on AWS Management Tools
ENT302 Deep Dive on AWS Management Tools
Amazon Web Services
 
AWS 201 Webinar Series - Rightsizing and Cost Optimizing your Deployment
AWS 201 Webinar Series - Rightsizing and Cost Optimizing your DeploymentAWS 201 Webinar Series - Rightsizing and Cost Optimizing your Deployment
AWS 201 Webinar Series - Rightsizing and Cost Optimizing your Deployment
Amazon Web Services
 
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech TalksDeep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
Amazon Web Services
 
AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...
AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...
AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...
Amazon Web Services
 

Similar to Governance at Scale (20)

Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
Governance @ Scale: Compliance Automation in AWS | AWS Public Sector Summit 2017
 
AWS re:Invent 2016: Reduce Your Blast Radius by Using Multiple AWS Accounts P...
AWS re:Invent 2016: Reduce Your Blast Radius by Using Multiple AWS Accounts P...AWS re:Invent 2016: Reduce Your Blast Radius by Using Multiple AWS Accounts P...
AWS re:Invent 2016: Reduce Your Blast Radius by Using Multiple AWS Accounts P...
 
Serverless Security Automation | AWS Public Sector Summit 2017
Serverless Security Automation | AWS Public Sector Summit 2017Serverless Security Automation | AWS Public Sector Summit 2017
Serverless Security Automation | AWS Public Sector Summit 2017
 
Benefits of Cloud Computing
Benefits of Cloud ComputingBenefits of Cloud Computing
Benefits of Cloud Computing
 
AWS Landing Zone - Architecting Security and Governance
AWS Landing Zone - Architecting Security and GovernanceAWS Landing Zone - Architecting Security and Governance
AWS Landing Zone - Architecting Security and Governance
 
Steve Seaney_AWS Control Tower - 2023 Midwest Community Day - Final.pptx
Steve Seaney_AWS Control Tower - 2023 Midwest Community Day - Final.pptxSteve Seaney_AWS Control Tower - 2023 Midwest Community Day - Final.pptx
Steve Seaney_AWS Control Tower - 2023 Midwest Community Day - Final.pptx
 
AWS Governance at Scale_AWSPSSummit_Singapore
AWS Governance at Scale_AWSPSSummit_SingaporeAWS Governance at Scale_AWSPSSummit_Singapore
AWS Governance at Scale_AWSPSSummit_Singapore
 
(ISM206) Modern IT Governance Through Transparency and Automation
(ISM206) Modern IT Governance Through Transparency and Automation(ISM206) Modern IT Governance Through Transparency and Automation
(ISM206) Modern IT Governance Through Transparency and Automation
 
(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS
(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS
(ISM315) How to Quantify TCO & Increase Business Value Gains Using AWS
 
Security Architecture recommendations for your new AWS operation - Pop-up Lof...
Security Architecture recommendations for your new AWS operation - Pop-up Lof...Security Architecture recommendations for your new AWS operation - Pop-up Lof...
Security Architecture recommendations for your new AWS operation - Pop-up Lof...
 
Cloud Governance and Provisioning Management using AWS Management Tools and S...
Cloud Governance and Provisioning Management using AWS Management Tools and S...Cloud Governance and Provisioning Management using AWS Management Tools and S...
Cloud Governance and Provisioning Management using AWS Management Tools and S...
 
Simplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing ZoneSimplify & Standardise your migration to AWS with a Migration Landing Zone
Simplify & Standardise your migration to AWS with a Migration Landing Zone
 
Launch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
Launch AWS Faster using Automated Landing Zones - AWS Online Tech TalksLaunch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
Launch AWS Faster using Automated Landing Zones - AWS Online Tech Talks
 
ENT302 Deep Dive on AWS Management Tools and New Launches
ENT302 Deep Dive on AWS Management Tools and New LaunchesENT302 Deep Dive on AWS Management Tools and New Launches
ENT302 Deep Dive on AWS Management Tools and New Launches
 
The Automation of Supervision Governance in the Cloud
The Automation of Supervision Governance in the CloudThe Automation of Supervision Governance in the Cloud
The Automation of Supervision Governance in the Cloud
 
Track 5 Session 2_SEC01 多重帳戶安全策略與方針.pptx
Track 5 Session 2_SEC01 多重帳戶安全策略與方針.pptxTrack 5 Session 2_SEC01 多重帳戶安全策略與方針.pptx
Track 5 Session 2_SEC01 多重帳戶安全策略與方針.pptx
 
ENT302 Deep Dive on AWS Management Tools
ENT302 Deep Dive on AWS Management Tools ENT302 Deep Dive on AWS Management Tools
ENT302 Deep Dive on AWS Management Tools
 
AWS 201 Webinar Series - Rightsizing and Cost Optimizing your Deployment
AWS 201 Webinar Series - Rightsizing and Cost Optimizing your DeploymentAWS 201 Webinar Series - Rightsizing and Cost Optimizing your Deployment
AWS 201 Webinar Series - Rightsizing and Cost Optimizing your Deployment
 
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech TalksDeep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
 
AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...
AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...
AWS re:Invent 2016: Enabling Enterprise Migrations: Creating an AWS Landing Z...
 

More from Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
Amazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
Amazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
Amazon Web Services
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Amazon Web Services
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
Amazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
Amazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Amazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
Amazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Amazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Governance at Scale

  • 1. © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Greg Share, Solutions Architect April 12th, 2018 Governance @ Scale Compliance Automation at AWS
  • 2. Why are we here?
  • 3. Common governance questions • How do I determine the current state of all cloud users and their access rights across the enterprise? • How do I ensure adherence to IT budgets in a pay-per-use model • How do I ensure deployments and operations are compliant with relevant legal, regulatory, and/or contractual policies? • How do I ensure security posture is enforced across accounts and workloads? • WITHOUT REDUCING THE AGILITY OF THE CLOUD
  • 4. Typical enterprise AWS adoption • In highly federated organizations, AWS adoption flows from the bottom up • In parallel, central IT often begins mirroring the on-premises architecture in AWS • Governance approach should: • Meet organizational requirements • Scale • Allow direct use of approved AWS services and APIs Top down adoption Bottom up adoption
  • 5. Tradeoffs in AWS adoption approaches Minimally encumbered AWS accounts • Complete power of the AWS platform; every feature available immediately • Requires the building or buying a solution that can manage many AWS accounts • Account provisioning and budget enforcement @scale can be automated • Uniform security controls and operations Service catalog/cloud broker approach • Prescribes limited access to the AWS platform based on catalog templates or via middleware • Suitable for meeting common requirements of less-technical internal users • Doesn’t allow developers to access cloud APIs • Doesn’t provide enough value or flexibility in large enterprises
  • 6. What’s your challenge as AWS adoption grows? Amazon S3 Project 1 AWS Account Amazon EC2 Project 2 AWS Account Amazon S3 Amazon EC2 Amazon RDS Stage 1 Specific Systems Limited Accounts Minimal Services Stage 2 Numerous Systems Multiple Accounts Many Services Amazon S3 Project 1 AWS Account Amazon EC2 Amazon VPC Amazon S3 Project 2 AWS Account Amazon EC2 Amazon VPC Amazon EMR Amazon Kinesis Amazon Redshift Project 3 AWS Account Amazon S3 Project 4 AWS Account Amazon EC2 Project 5 AWS Account Amazon API Gateway Amazon SQS Amazon WorkSpaces Amazon ECS AWS Lambda AWS Elastic BeanstalkAmazon S3 Amazon S3 Project 6 AWS Account Amazon EC2 Amazon EMR Amazon Kinesis Amazon VPC
  • 7. Governance is not a “one size fits all” Higher-impact workloads are more likely to be managed by central or departmental IT groups and will have more security controls. Lower-impact workloads still have basic security controls, but can be issued freely to end users for test, development, or low impact research and production workloads.Low High High Low Availability Confidentiality
  • 8. Three principles of governance@scale Account management • Standardize and streamline provisioning, maintenance, and access control policies for many AWS accounts and workloads Cost enforcement • Ensure AWS accounts and workloads do not exceed budget Compliance automation • Provide continuous monitoring, configuration management, and enforce security controls
  • 9. So…what does this look like? Projects Management Upper Management Senior Leadership Executive CXO VP Director Manager Manager Director Manager VP Director Manager Manager Project 1 Project 2 Project 3 Project 5 Project 6 Project 7 Project 8 $ $ $ $$ $ $ $ $ $ $ $$ $ $ $ $ $
  • 10. How you get this security visibility Projects Data Analyst Management Senior Leadership Executive CXO VP Director Analyst Analyst Director Analyst VP Director Analyst Analyst Project 1 Project 2 Project 3 Project 5 Project 6 Project 7 Project 8 P1: P2: P3: P5: P6: P7: P8: 25%: 0%: 75%: 0%: 35%: 65%:
  • 11. Account management @scale • Use a consolidated admin AWS account • AWS Identity & Access Management (IAM) users live in this account • IAM users assume roles to access other AWS accounts • Enforce MFA for role assumption • Automate AWS account provisioning • Eliminate slow, error-prone manual provisioning • Ensure AWS accounts are actively managed • Incentivizes users from using other methods (personal, school, etc.) for AWS experimentation. • Implement “single sign-on” through federation • Use enterprise accelerators as a starting point • Policy assignment to IAM users/groups/roles • Consolidated admin baseline • Target account baseline
  • 12. Consolidated Admin AWS Account IAM users users stack security baseline stack Automate provisioning of target accounts Target AWS Account admin role billing role read only role baseline stack Target AWS Account admin role billing role read only role baseline stack Target AWS Account admin role billing role read only role baseline stack
  • 13. Key configuration points to baseline accounts AWS CloudFormation Leverage Enterprise Accelerator Compliance “Quick Starts” Amazon CloudWatch AWS Config Config Rules AWS CloudTrail CloudWatch Events Manual configuration Root MFA Alternate contacts IAM Managed Policies Roles Security questions Amazon VPC VPC peering Flow logs
  • 14. Cost enforcement @scale • Use automation to map AWS accounts to org. structure • Aligns with current budget process and cost alignments • Use automation for cost management/enforcement • Actual spend vs. budget projections decision makers. • Allow management to increase budgets • Turn off resources to preserve budget • Use dynamic IAM policies to throttle usage when budget thresholds are met • Provide near-real time budget projections so stakeholders are aware of current AWS spend
  • 15. Cost enforcement @scale Projects Management Upper Management Senior Leadership Executive CXO VP Director Manager Manager Director Manager VP Director Manager Manager Project 1 Project 2 Project 3 Project 5 Project 6 Project 7 Project 8 $ $ $ $$ $ $ $$$$$ $$$$$ $ $ $$$$ $$$$$$ $$$$ $$$$$ $$$$
  • 16. Cost enforcement @scale: metering No alerts, no charge. Smart agent won’t alert or charge when instances are turned off to save money. Seamlessly get logs and continue providing protection when instances are turned back on. OFF ON
  • 17. Compliance automation @scale • Pre-approve standard security configurations to decrease RMF efforts up to 50% and achieve faster ATOs (days vs. months/years) • Automate deployment of accounts consistent with security policies (NIST/HIPAA) • Installing instance level account and security tools via Security Tools • Pre-populate GRC tools with inherited and system specific controls (ex Telos Xacta) • Perform continuous monitoring with GRC tools and alert security staff of configuration drift and/or vulnerabilities • Send all AWS account log files to centralized data lake for security analysis
  • 18. Projects Management Upper Management Senior Leadership Executive CXO VP Director Manager Manager Director Manager VP Director Manager Manager Project 1 Project 2 Project 3 Project 5 Project 6 Project 7 Project 8 Compliance automation @scale
  • 19. Security automation @ scale Recommendation scan: Policy tailored to governance and workload Deployed with repeatable generic code
  • 20. Implement policies dynamically at runtime based on workload tags. Security automation @scale
  • 21. Where do I go from here? • Build or buy a governance@scale solution that can grow with you. • Professional Services can help facilitate the design and help you build a solution based on your requirements. • Partner Solutions are available (CloudTamer by Stratus Solutions ) • Incorporate and automate security and operations management tools into infrastructure provisioning • If you can’t automate third-party products with AWS, then they aren’t built for AWS • Security needs to have parity for enabling visibility for this governance model
  • 22. Thank You Greg Share, gshare@amazon.co.uk