13
a production Up near the clouds all the servers (can) go down

Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

  • Upload
    others

  • View
    11

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

a production

Up near the clouds all the servers (can) go down

Page 2: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

Il "vecchio" internet

Page 3: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

La rivoluzione cloud

?

Page 4: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

Il cloud computingRisorse IT fornite via internet on-demandcon pricing pay-as-you-go

Page 5: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

Cosa cambia?

On premises IaaS PaaS SaaS

Page 6: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

La sicurezza nel mondo cloud

modello di responsabilitàcondivisa

Page 7: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

Invention requires two things:the ability to try a lot of experiments,

and not having to live withthe collateral damage of failed experiments

Andy Jassy, CEO @ Amazon Web Services

Page 8: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

Quindi il cloud computingè la soluzione definitiva?

Page 9: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

Networking

Best practice:

- Network ACL

- Security Groups

Realtà:

- Ruleset vaghi

106 milioni di utenti esposti

Page 10: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

Scaling delle risorse computazionali

Cosa succede quando il fabbisogno scende?

Page 11: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

Simple Storage Service

Best practices:

- Bucket Policy

- Access Control List

Realtà:

- Configurazioni non sicure

14 milioni di utenti esposti

Page 12: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

Key Management

Realtà:

- Configurazioni non sicure

Page 13: Up near the clouds · WorkMail Amazon CloudWatch Administration & Security Analytics AWS Data Pipeline Networking Amazon vpc AWS AWSIAM AWS Trusted Advisor Amazon CloudFront AWS Config

Grazie per l'attenzione!

Luca Pezzolla / [email protected]