© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Introduction to the APN Technical
Baseline Review
A Primer on Core AWS Best Practices for Promoting Customer Success
Mansi Vaghela, Partner Solutions Architect
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
What is the technical baseline review?
Free APN benefit
Core AWS best practices
One-on-one engagement
Successful customer outcomes
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Baseline Benefits
APN Advanced Tier requirement
APN programs prerequisite
Better customer outcomes
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Workload Types
Hosted and
managed
workloads
Customer-
deployed
workloads
Other workloads
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
APN Technical Baseline process
Request
Collect
details Review Remediate
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
APN Technical Baseline process
Request
Collect
details Review Remediate
Submit a request for a Technical Baseline Review through the APN
Partner Central portal
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
APN Technical Baseline process
Request
Collect
details Review Remediate
Answer questions and provide additional solution details, including an
architecture diagram, via email
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
APN Technical Baseline process
Request
Collect
details Review Remediate
Discuss your architecture and operations during a 1-hour Amazon
Chime call
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
APN Technical Baseline process
Request
Collect
details Review Remediate
Update your systems to address any identified issues
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Download the checklist
https://aws.amazon.com/partners/technical
-baseline-review
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Baseline requirements for hosted and
managed workloads
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
AWS Premium Support level
24x7x365 access to tech support and use case-specific
architectural guidance
Enable AWS Business Support (or greater) on all AWS
production accounts
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
AWS Communications
Set Operations, Billing, and Security contacts
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Root Account Usage
Protect root account
credentials
Do not assign
access keys to the
root account
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Manage IAM Access Properly
Least privilege policies
Multi-factor authentication
Rotate credentials
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Audit and logging
Enable AWS CloudTrail on all AWS accounts and in every
AWS Region
Store all CloudTrail logs in a separate administrative domain
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Test account
AWS CloudTrail
Production account
AWS CloudTrail
Development account
AWS CloudTrail
Audit account
Logs bucket
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Backup and Recovery
Back up data
regularly
Test recovery
Amazon RDS
Amazon S3
AWS DynamoDB
Snapshot
Replication
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Disaster recovery (DR)
How do you define disaster ?
Time
Disaster
Data loss Downtime
Recovery point objective Recovery time objective
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Amazon S3 Bucket Access
Secure S3 Buckets
Monitor if they become public
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Partner SaaS account Customer account
AWS Security Token
Service (AWS STS)
Amazon CloudWatchAWS Lambda
Amazon DynamoDB
Cross-account access with roles
IAM role
ARN
Temporary
credentials
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Personally identifiable information &
personal health information
Encrypt in transit and at rest
Log all access
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Regulatory Compliance Standards
PCI DSS
HIPAA
FedRAMP
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Customer-deployed Workloads
The APN Partner provides prescriptive
deployment guidance to the customer through
a published customer deployment guide.
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
https://aws.amazon.com
/partners/technical-
baseline-review
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Request a Technical Baseline Review
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Request a Technical Baseline Review
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Request a Technical Baseline Review
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Key Take-Aways
• Free APN benefit available to you
• Highly educational one-on-one engagement with an AWS Partner
Solutions Architect
• AWS best practices are fundamental for delivering successful outcomes
for your customers
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark
Thank you!

Mansi Vaghela [AWS] | Introduction to the APN Technical Baseline Review | InfluxDays Virtual Experience NA 2020

  • 1.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Introduction to the APN Technical Baseline Review A Primer on Core AWS Best Practices for Promoting Customer Success Mansi Vaghela, Partner Solutions Architect
  • 2.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark What is the technical baseline review? Free APN benefit Core AWS best practices One-on-one engagement Successful customer outcomes
  • 3.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Baseline Benefits APN Advanced Tier requirement APN programs prerequisite Better customer outcomes
  • 4.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Workload Types Hosted and managed workloads Customer- deployed workloads Other workloads
  • 5.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark APN Technical Baseline process Request Collect details Review Remediate
  • 6.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark APN Technical Baseline process Request Collect details Review Remediate Submit a request for a Technical Baseline Review through the APN Partner Central portal
  • 7.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark APN Technical Baseline process Request Collect details Review Remediate Answer questions and provide additional solution details, including an architecture diagram, via email
  • 8.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark APN Technical Baseline process Request Collect details Review Remediate Discuss your architecture and operations during a 1-hour Amazon Chime call
  • 9.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark APN Technical Baseline process Request Collect details Review Remediate Update your systems to address any identified issues
  • 10.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Download the checklist https://aws.amazon.com/partners/technical -baseline-review
  • 11.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Baseline requirements for hosted and managed workloads
  • 12.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark AWS Premium Support level 24x7x365 access to tech support and use case-specific architectural guidance Enable AWS Business Support (or greater) on all AWS production accounts
  • 13.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark AWS Communications Set Operations, Billing, and Security contacts
  • 14.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Root Account Usage Protect root account credentials Do not assign access keys to the root account
  • 15.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Manage IAM Access Properly Least privilege policies Multi-factor authentication Rotate credentials
  • 16.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Audit and logging Enable AWS CloudTrail on all AWS accounts and in every AWS Region Store all CloudTrail logs in a separate administrative domain
  • 17.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Test account AWS CloudTrail Production account AWS CloudTrail Development account AWS CloudTrail Audit account Logs bucket
  • 18.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Backup and Recovery Back up data regularly Test recovery Amazon RDS Amazon S3 AWS DynamoDB Snapshot Replication
  • 19.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Disaster recovery (DR) How do you define disaster ? Time Disaster Data loss Downtime Recovery point objective Recovery time objective
  • 20.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Amazon S3 Bucket Access Secure S3 Buckets Monitor if they become public
  • 21.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Partner SaaS account Customer account AWS Security Token Service (AWS STS) Amazon CloudWatchAWS Lambda Amazon DynamoDB Cross-account access with roles IAM role ARN Temporary credentials
  • 22.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Personally identifiable information & personal health information Encrypt in transit and at rest Log all access
  • 23.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Regulatory Compliance Standards PCI DSS HIPAA FedRAMP
  • 24.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Customer-deployed Workloads The APN Partner provides prescriptive deployment guidance to the customer through a published customer deployment guide.
  • 25.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark https://aws.amazon.com /partners/technical- baseline-review
  • 26.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Request a Technical Baseline Review
  • 27.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Request a Technical Baseline Review
  • 28.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Request a Technical Baseline Review
  • 29.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Key Take-Aways • Free APN benefit available to you • Highly educational one-on-one engagement with an AWS Partner Solutions Architect • AWS best practices are fundamental for delivering successful outcomes for your customers
  • 30.
    © 2020, AmazonWeb Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential and Trademark Thank you!