24
© 2018 ITC Secure Dob Todorov, HeleCloud SECURING YOUR NEW PUBLIC CLOUD

SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

  • Upload
    others

  • View
    11

  • Download
    0

Embed Size (px)

Citation preview

Page 1: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

© 2018 ITC Secure

Dob Todorov, HeleCloud

SECURING YOUR NEW PUBLIC CLOUD

Page 2: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Secure Your New Public Cloud

Page 3: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

21st Century ITSecurity

Cloud Security

Page 4: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Shared Responsibility Model

CUSTOMERDATA

PLATFORM & APPLICATIONMANAGEMENT

OPPERATING SYSTEM, NETWORK, & FIREWALL CONFIGURATION

CLIENT-SIDE DATA ENCRYPTION & DATA INTEGRITYAUTHENTICATION

SERVER-SIDE ENCRYPTION (FILE SYSTEM AND/OR DATA)

NETWORK TRAFFIC PROTECTION (ENCRYPTION/INTEGRITY/IDENTITY)

OPTIONAL –OPAQUE DATA: 0S & 1S (IN TRANSIT/ATREST)

FOUNDATIONSERVICES

AWS GLOBALINFRASTRUCTURE

AW

S EN

DP

OIN

TS

AWS

IAMCU

STOM

ERIAM

COMPUTE STORAGE DATABASES NETWORKING

REGIONSAVAILABILITY

ZONESEDGE

LOCATIONS

Managed by AWSCustomers

Managed byAmazon WebServices

Page 5: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Shared Responsibility Model

CUSTOMER DATA

PLATFORM & APPLICATIONMANAGEMENT

OPPERATING SYSTEM, NETWORK, & FIREWALL CONFIGURATION

CLIENT-SIDE DATA ENCRYPTION & DATA INTEGRITYAUTHENTICATION

SERVER-SIDE ENCRYPTION (FILE SYSTEM AND/OR DATA)

NETWORK TRAFFIC PROTECTION (ENCRYPTION/INTEGRITY/IDENTITY)

OPTIONAL –OPAQUE DATA: 0S & 1S (IN TRANSIT/ATREST)

FOUNDATIONSERVICES

AWS GLOBALINFRASTRUCTURE

AW

S EN

DP

OIN

TS

AWS

IAMCU

STOM

ERIAM

COMPUTE STORAGE DATABASES NETWORKING

REGIONSAVAILABILITY

ZONESEDGE

LOCATIONS

Managed by AWSCustomers

Managed byAmazon WebServices

Security IN theCloud

Security OF theCloud

Page 6: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

MORE VISIBILITY MORE CONTROL

MORE AUDITABILITY MOREAGILITY

Page 7: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Security is Visible

Who is accessing the resources?

Who took what action?

▪ When?

▪ From where?

▪ What did they do?

▪ Logs Logs Logs

Page 8: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA
Page 9: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA
Page 10: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

EVERYTHING IS AN APICALL.

Page 11: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

EVERYTHING GENERATESLOGS.

Page 12: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

TERABYTES OF LOGS ADAY…

Page 13: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

21st Century ITSecurity

Intelligent Security

Page 14: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Protect Sensitive Data: Macie

Page 15: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Protect Sensitive Data: Macie

Page 16: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

AWS Shield: Managed DDoSProtection

Page 17: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

CloudWatch Alert: More than 1,000

Open Connections to ELB from a single IP

Log an incident

WAF Rule: block source

Wait 1hour

Remove WAFRule

AWSWAF

AWSELB

S3 Evidence Repository

ForensicsSave Logs

CloudWatch

Automated Incident Response: DDoS Attack

Page 18: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Intelligent Threat Detection: GuardDuty

Page 19: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Intelligent Threat Detection: GuardDuty

Page 20: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Cloud is Simply Better: PersonalData Protection & GDPR

Page 21: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Automated Incident Response: Infected Instance

Guard DutyReport:Instance ID

i-1234567890abcdef0

Log an incident

Isolate the Instance from the

network

Shut down instance

S3 Evidence Repository

MemoryDump

Disk Dump

Forensics

Page 22: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Establishing Secure Cloud Services

ISO27001 PCI/DSS

PersonalData Protection

CSP

Com

plia

nce,

Th

reat

and

Gap

A

naly

sis

Secu

rity

St

rate

gyD

esig

n

Secu

rity

P

rogr

amm

e

Des

ign

Secu

rity

P

layb

oo

k

Imp

lem

en

tati

on

&Te

stin

g

Secure &

Compliant Cloud

Systems &

Applications

Risk

Management

Security

Operations &

Management

Legacy Cloud

Systems &

Applications

Page 23: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

Cloud

SecurityConsiderations

PREPARE

PREVENT

DETECT

RESPOND

Page 24: SECURING YOUR NEW PUBLIC CLOUD - ITC Secure ......SECURING YOUR NEW PUBLIC CLOUD Secure Your New Public Cloud 21st Century IT Security Cloud Security Shared Responsibility Model CUSTOMERDATA

HeleCloud Company Overview

Maidenhead, UK1Bell Street, Maidenhead, Berkshire, SL6 1BU,UK,

+44 20 [email protected]

Thank you!

[email protected]