12
Amazon Web Services Shared Responsibility Model PPT by www.EndPointVault.com Security & Complian ce 1 2 3 4

Amazon AWS Shared Security Model

Embed Size (px)

DESCRIPTION

Understand how you can secure your digital assets that are stored in Amazon AWS. Get to know what is the Amazon responsibility of Amazon and what are your responsibility for completing the Shared Security Philosophy. Know what measures Amazon has taken to secure its cloud storage and premises. By insuring security and following the laid guidelines you can too insure the security of your data and instance that is hosted in Amazon cloud services.

Citation preview

Page 1: Amazon AWS Shared Security Model

Amazon Web ServicesShared Responsibility Model

PPT by www.EndPointVault.com

Security &

Compliance

1

2

3

4

Page 2: Amazon AWS Shared Security Model

Amazon AWS

Amazon offers scalable cloud computing platform to build, deploy and run wide range of application using their servers that are spread across the globe.

Page 3: Amazon AWS Shared Security Model

AWS Shared Security Model

Amazon AWSFacilitiesPhysical SecurityPhysical InfrastructureNetwork InfrastructureVirtualization Security

Amazon ClientOSApplicationSecurity GroupsOS FirewallNetwork ConfigurationAccount Management

Page 4: Amazon AWS Shared Security Model

Physical Security - AWS

AWS Facilities state of the art electronic surveillance system.

Authentication and Authorization is done using multi factor access control System.

Data centre is guarded by professionals in security domain.

Hardware are fully guarded and are destroyed before it leave the premise or data center.

Page 5: Amazon AWS Shared Security Model

Virtualization Security - AWS Security for instances or virtual server is provided on

multiple level to the user:

Host OS (Amazon) Guest OS (User Virtual Instance) Firewall Signed API calls

Each of these security measures are interdependent to provide the overall security and to prevent any unauthorized access to the database.

Page 6: Amazon AWS Shared Security Model

Host OS Security - AWS• Authorized administrator who needs to access the

management plane are required to pass through the multi-factor authentication before gaining access to the administration host.

• All such cases are logged and audited.

• Privileges are immediately revoked as soon as the work gets completed.

Page 7: Amazon AWS Shared Security Model

Guest OS Security - AWS

Though virtual instances are totally controlled by the user nevertheless Amazon still provides considerable amount of security to it.

https/SSL enabled login and Guest OS management.

Support for SSH (Secure Shell) network protocol for secure logging in Unix/Linux Instances.

Provides regular updates and patches for the Guest OS (Windows or Linux).

Further security can be easily enhanced by the instance

administrator by using services available in Amazon Marketplace.

Page 8: Amazon AWS Shared Security Model

Firewall Solution - AWS

• Amazon has created a robust firewall security mechanism where by default all the ports are in deny mode and the user explicitly open the ports to allow the inbound traffic.

• Firewall is guest OS independent and does not reply on the administrator instead, requires the users X.509 certificate and relevant key to authorize changes thus creating an extra layer of security.

Page 9: Amazon AWS Shared Security Model

Amazon Client Security Responsibility

• Create and manage groups and set security policy to insure data security and safety of your instance.

• Use of Virtual Private Network to ensure network safety and creating Access list to manage the inbound – outbound traffic from your instances.

• Setup VPN tunnel to your end for direct access of your instances.

Page 10: Amazon AWS Shared Security Model

Identity and Access Management• You can deny access to resources and services (EC2,

S3, Direct Connect, etc.) to those with minimum privileges.

• Use of multi-factor authentication for authorized access.

• API through Access ID/ Secret Key

Page 11: Amazon AWS Shared Security Model

Amazon Webinars:Security https://www.youtube.com/watch?v=IedaYaKsb-4Amazon AWS Foundationhttps://www.youtube.com/watch?v=Nf-m-dKJYMQ

De-Duplication Processhttp://www.endpointvault.com/de-dupe.html

Resources and further study

Page 12: Amazon AWS Shared Security Model

Use the Power of Cloud to Secure Your Datavisit http://www.endpointvault.com/