SHARING IS CARING
MAKING YOUR AWS CONFIGURATION
IMPROVEMENTS VISIBLE
petri.kallberg@nordcloud.com
28/05/2019
100% PUBLIC CLOUD
ABOUT NORDCLOUD
● 15 offices in 10 countries.
● Born in 2011 in the cloud.
● Cloud native infrastructure solutions & app.development.
● Appreciated by enterprises and startups in making digital
initiatives happen.
Our highly skilled organization includes 420+ cloud experts
with 200+ certifications and 200+ business and technical
accreditations. Growing ~40% yearly.
CLOUD COMPETENCE CENTER
“A Cloud Competence Centre is
a support function to increase
developer productivity and maintain
a consistent and secure cloud
platform.”
BACKGROUND
OF STAKEHOLDERS AND CONTRIBUTORS
BACKGROUND
BUILDER IS YOUR BEST FRIEND
BACKGROUND
“A Cloud Competence Centre is
a support function to increase
developer productivity…”
WHAT CLOUDSPLOIT?
CLOUDSPLOIT
• (SaaS) Security and configuration scanner.
• AWS & Azure coverage.
• Rules engine and remediation guides
are open-source, available in Github!
• How does this compare with ... ?
• AWS Inspector
• AWS Config
• AWS Trusted Advisor
DIY ARCHITECTURE
CLOUDSPLOIT
IT’S DEMO TIME …
SHARING IS SCARING
LESSONS LEARNED
/
CURRENTLY MISSING FEATURES
WHAT NEXT
• True multi-tenant data-store
and dashboard will come with
Elasticsearch Open Distro?
• Hiding false positives and
using tags to ”skip” resources.
• Big screen dashboard.
• More checks …
THAT’S ALL, FOLKS!

Sharing is Caring

  • 1.
    SHARING IS CARING MAKINGYOUR AWS CONFIGURATION IMPROVEMENTS VISIBLE petri.kallberg@nordcloud.com 28/05/2019
  • 2.
    100% PUBLIC CLOUD ABOUTNORDCLOUD ● 15 offices in 10 countries. ● Born in 2011 in the cloud. ● Cloud native infrastructure solutions & app.development. ● Appreciated by enterprises and startups in making digital initiatives happen. Our highly skilled organization includes 420+ cloud experts with 200+ certifications and 200+ business and technical accreditations. Growing ~40% yearly.
  • 3.
    CLOUD COMPETENCE CENTER “ACloud Competence Centre is a support function to increase developer productivity and maintain a consistent and secure cloud platform.” BACKGROUND
  • 4.
    OF STAKEHOLDERS ANDCONTRIBUTORS BACKGROUND
  • 5.
    BUILDER IS YOURBEST FRIEND BACKGROUND “A Cloud Competence Centre is a support function to increase developer productivity…”
  • 6.
    WHAT CLOUDSPLOIT? CLOUDSPLOIT • (SaaS)Security and configuration scanner. • AWS & Azure coverage. • Rules engine and remediation guides are open-source, available in Github! • How does this compare with ... ? • AWS Inspector • AWS Config • AWS Trusted Advisor
  • 7.
  • 8.
  • 9.
  • 10.
    CURRENTLY MISSING FEATURES WHATNEXT • True multi-tenant data-store and dashboard will come with Elasticsearch Open Distro? • Hiding false positives and using tags to ”skip” resources. • Big screen dashboard. • More checks …
  • 11.