+ All Categories
Home > Technology > Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Date post: 15-Jan-2015
Category:
Upload: amazon-web-services
View: 930 times
Download: 3 times
Share this document with a friend
Description:
Stephen Schmidt, AWS CISO and VP of Security Engineering, provides an overview of innovations in cloud security and the importance of security as an enabler for innovation in enterprises, but particularly in government and other highly regulated industries and segments.
Popular Tags:
50
Security in the Cloud Stephen E. Schmidt, Vice President, Security Engineering & Chief Information Security Officer AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014
Transcript
Page 1: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Security in the Cloud

Stephen E. Schmidt,

Vice President, Security Engineering &

Chief Information Security Officer

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 2: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

8th BirthdayLaunched on March 14th, 2006

Page 3: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Startups on AWS

Page 4: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Enterprises on AWS

Page 5: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Public Sector on AWS

Page 6: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

System Integrators on AWS

Page 7: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

ISVs on AWS

Page 8: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Why are enterprises & government adopting cloud computing and AWS so quickly?

Page 9: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

The primary reason enterprises &

governments are moving so quickly to

AWS and the cloud

#1: Agility

Page 10: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Why does agility matter?

Page 11: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Old World: Infrastructure in weeks

Enterprises & Government Can’t Afford to Be Slow

Page 12: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

A Culture of Innovation: Experiment Often & Fail Without Risk

Page 13: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Regions Availability Zones Content Delivery POPs

#2: Platform Breadth and Depth

Page 14: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

10 regions26 availability zones51 edge locations

It’s Not Just Having Services in a Couple of Regions…

Page 15: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Regions Availability Zones Content Delivery POPs

Storage GatewayS3 EBS Glacier Import/Export DynamoDB ElastiCache

StorageCompute Databases

RDS

MySQL, PostgreSQL

Oracle, SQL ServerElastic Load BalancerEC2 Auto Scaling

#2: Platform Breadth and Depth

Page 16: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Direct ConnectRoute 53

VPCNetworking

Regions Availability Zones Content Delivery POPs

Storage GatewayS3 EBS Glacier Import/Export DynamoDB ElastiCache

StorageCompute Databases

RDS

MySQL, PostgreSQL

Oracle, SQL ServerElastic Load BalancerEC2 Auto Scaling

#2: Platform Breadth and Depth

Page 17: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Direct ConnectRoute 53

VPCNetworking

Analytics

Data Pipeline

Redshift

EMRKinesis

SWFSNS SQS CloudSearchSES AppStreamCloudFront

Application Services

WorkSpaces

Regions Availability Zones Content Delivery POPs

Storage GatewayS3 EBS Glacier Import/Export DynamoDB ElastiCache

StorageCompute Databases

RDS

MySQL, PostgreSQL

Oracle, SQL ServerElastic Load BalancerEC2 Auto Scaling

#2: Platform Breadth and Depth

Page 18: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Management &AdministrationIAM CloudWatchCloudTrail APIs and SDKsManagement ConsoleCloud HSM Command Line Interface

Direct ConnectRoute 53

VPCNetworking

Analytics

Data Pipeline

Redshift

EMRKinesis

SWFSNS SQS CloudSearchSES AppStreamCloudFront

Application Services

WorkSpaces

Regions Availability Zones Content Delivery POPs

Storage GatewayS3 EBS Glacier Import/Export DynamoDB ElastiCache

StorageCompute Databases

RDS

MySQL, PostgreSQL

Oracle, SQL ServerElastic Load BalancerEC2 Auto Scaling

#2: Platform Breadth and Depth

Page 19: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Elastic Beanstalk for Java, Node.js, Python, Ruby, PHP and .Net

OpsWorks CloudFormationContainers & Deployment (PaaS)

Management &AdministrationIAM CloudWatchCloudTrail APIs and SDKsManagement ConsoleCloud HSM Command Line Interface

Direct ConnectRoute 53

VPC

Networking

Analytics

Data Pipeline

Redshift

EMRKinesis

SWFSNS SQS CloudSearchSES AppStreamCloudFront

Application Services

WorkSpaces

Regions Availability Zones Content Delivery POPs

Storage GatewayS3 EBS Glacier Import/Export DynamoDB ElastiCache

StorageCompute Databases

RDS

MySQL, PostgreSQL

Oracle, SQL ServerElastic Load BalancerEC2 Auto Scaling

#2: Platform Breadth and Depth

Page 20: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Technology Partners Consulting Partners AWS MarketplaceEcosystemElastic Beanstalk for Java, Node.js, Python, Ruby, PHP and .Net

OpsWorks CloudFormationContainers & Deployment (PaaS)

Management &AdministrationIAM CloudWatchCloudTrail APIs and SDKsManagement ConsoleCloud HSM Command Line Interface

Direct ConnectRoute 53

VPCNetworking

Analytics

Data Pipeline

Redshift

EMRKinesis

SWFSNS SQS CloudSearchSES AppStreamCloudFront

Application Services

WorkSpaces

Regions Availability Zones Content Delivery POPs

Storage GatewayS3 EBS Glacier Import/Export DynamoDB ElastiCache

StorageCompute Databases

RDS

MySQL, PostgreSQL

Oracle, SQL ServerElastic Load BalancerEC2 Auto Scaling

#2: Platform Breadth and Depth

Page 21: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Support CertificationTrainingProfessional Services

Technology Partners Consulting Partners AWS MarketplaceEcosystemElastic Beanstalk for Java, Node.js, Python, Ruby, PHP and .Net

OpsWorks CloudFormationContainers & Deployment (PaaS)

Management &AdministrationIAM CloudWatchCloudTrail APIs and SDKsManagement ConsoleCloud HSM Command Line Interface

Direct ConnectRoute 53

VPCNetworking

Analytics

Data Pipeline

Redshift

EMRKinesis

SWFSNS SQS CloudSearchSES AppStreamCloudFront

Application Services

WorkSpaces

Regions Availability Zones Content Delivery POPs

Storage GatewayS3 EBS Glacier Import/Export DynamoDB ElastiCache

StorageCompute Databases

RDS

MySQL, PostgreSQL

Oracle, SQL ServerElastic Load BalancerEC2 Auto Scaling

#2: Platform Breadth and Depth

Page 22: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Security is Our No.1 PriorityComprehensive Security Capabilities to Support Virtually Any Workload

PEOPLE & PROCEDURES

NETWORK SECURITY

PHYSICAL SECURITY

PLATFORM SECURITY

Page 23: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

“[Enterprise customers are] skipping the years of early getting-their-feet-wet, and immediately jumping in with more significant projects, with more ambitious goals…”

Page 24: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

“Increasingly, organizations are asking what can’t go to the cloud, rather than what can…”

Page 25: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

“As 2014 dawns, we’re moving into an era of truly mainstream adoption of cloud…”

Page 26: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• SECURITY IS SHARED

Page 27: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

WHAT NEEDS TO BE DONE TO KEEP THE SYSTEM SAFE

Page 28: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

WHAT WE DO

FOR YOU

WHAT YOU DO YOURSELF

Page 29: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• EVERY CUSTOMER HAS ACCESS TO THE SAME SECURITY CAPABILITIES

• CHOOSE WHAT’S RIGHT FOR YOUR WORKLOAD

Page 30: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• CLOUD SECURITY OFFERS MORE

• VISIBILITY• AUDITABILITY• CONTROL

Page 31: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• MORE VISIBILITY

Page 32: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• CAN YOU MAP YOUR NETWORK?

• WHAT IS IN YOUR ENVIRONMENT RIGHT NOW?

Page 33: Security in the Cloud - AWS Symposium 2014 - Washington D.C.
Page 34: Security in the Cloud - AWS Symposium 2014 - Washington D.C.
Page 35: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• MORE AUDITABILITY

Page 36: Security in the Cloud - AWS Symposium 2014 - Washington D.C.
Page 37: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• SECURITY CONTROL OBJECTIVES

• 1. SECURITY ORGANIZATION• 2. AMAZON USER ACCESS• 3. LOGICAL SECURITY• 4. SECURE DATA HANDLING• 5. PHYSICAL SECURITY AND ENV. SAFEGUARDS• 6. CHANGE MANAGEMENT• 7. DATA INTEGRITY, AVAILABILITY AND REDUNDANCY• 8. INCIDENT HANDLING

Page 38: Security in the Cloud - AWS Symposium 2014 - Washington D.C.
Page 39: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• MORE CONTROL

Page 40: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

Defense in DepthMulti level security

• Physical security of the data centers• Network security• System security• Data security

DATA

Page 41: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• LEAST PRIVILEGE PRINCIPLE

• AT AWS

Page 42: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• LEAST PRIVILEGE PRINCIPLECONFINE ROLES ONLY TO THE MATERIALREQUIRED TO DO SPECIFIC WORK

Page 43: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• LEAST PRIVILEGE PRINCIPLESEPARATE NETWORKS FOR CORPORATE WORK VS. ACCESSING CUSTOMER DATA

Page 44: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• LEAST PRIVILEGE PRINCIPLEMUST HAVE A BUSINESS NEED-TO-KNOW ABOUT SENSITIVE INFORMATION LIKE DATACENTER LOCATIONS

Page 45: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• LEAST PRIVILEGE PRINCIPLEMUST HAVE A BUSINESS NEED-TO-KNOW IN ORDER TO ACCESS DATACENTERS

Page 46: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• SIMPLE SECURITY CONTROLSARE THE EASIEST TO GET RIGHT, EASIEST TO AUDIT, AND EASIEST TO ENFORCE

Page 47: Security in the Cloud - AWS Symposium 2014 - Washington D.C.
Page 48: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• IDC Survey

• Attitudes and Perceptions Around Security and Cloud Services• Nearly 60% of organizations agreed that CSPs [Cloud Service

Providers] provide better security than their own IT organization

• Source: IDC 2013 U.S. Cloud Security Survey• Doc #242836, September 2013

Page 49: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

• “Based on our experience, I believe that we can be even more secure in the AWS cloud than in our own data centers”

Tom Soderstrom – CTO – NASA JPL

Page 50: Security in the Cloud - AWS Symposium 2014 - Washington D.C.

AWS Security

Stephen E. Schmidt, Chief Information Security Officer

Thank You!


Recommended