72
© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc. AWS Security Stephen E. Schmidt, Directeur de la Sécurité

AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

Embed Size (px)

DESCRIPTION

Morning Security keynote by Steven Schmidt

Citation preview

Page 1: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc.

AWS Security Stephen E. Schmidt, Directeur de la Sécurité

Page 2: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

Different customer viewpoints on security

PR exec keep out of the news

CEO protect shareholder

value

CI{S}O preserve the

confidentiality, integrity and availability of data

Page 3: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

Security is Our No.1 Priority Comprehensive Security Capabilities to Support Virtually Any Workload

PEOPLE & PROCEDURES

NETWORK SECURITY

PHYSICAL SECURITY

PLATFORM SECURITY

Page 4: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

SECURITY IS SHARED

Page 5: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

WHAT NEEDS TO BE DONE TO KEEP THE SYSTEM SAFE

Page 6: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

WHAT WE DO

WHAT YOU HAVE TO DO

Page 7: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

EVERY CUSTOMER HAS ACCESS TO THE SAME SECURITY

CAPABILITIES

CHOOSE WHAT’S RIGHT FOR YOUR BUSINESS

Page 8: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

“Based on our experience, I believe that we can be even more secure in the AWS cloud than in our own data centers”

Tom Soderstrom – CTO – NASA JPL

Page 9: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

AWS SECURITY OFFERS MORE

VISIBILITY AUDITABILITY

CONTROL

Page 10: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

MORE VISIBILITY

Page 11: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

CAN YOU MAP YOUR NETWORK?

WHAT IS IN YOUR ENVIRONMENT RIGHT NOW?

Page 12: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 13: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 14: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

TRUSTED ADVISOR

Page 15: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 16: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 17: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 18: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

MORE AUDITABILITY

Page 19: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 20: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

SECURITY CONTROL OBJECTIVES

1. SECURITY ORGANIZATION 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. PHYSICAL SECURITY AND ENV. SAFEGUARDS 6. CHANGE MANAGEMENT 7. DATA INTEGRITY, AVAILABILITY AND REDUNDANCY 8. INCIDENT HANDLING

Page 21: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 22: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

AWS CLOUDTRAIL

Page 23: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

You are making API calls...

On a growing set of services around the

world…

CloudTrail is continuously recording API

calls…

And delivering log files to you

Page 24: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

Security Analysis Use log files as an input into log management and analysis solutions to perform security analysis and to detect user behavior patterns.

Track Changes to AWS Resources Track creation, modification, and deletion of AWS resources such as Amazon EC2 instances, Amazon VPC security groups and Amazon EBS volumes.

Troubleshoot Operational Issues Quickly identify the most recent changes made to resources in your environment.

Compliance Aid Easier to demonstrate compliance with internal policies and regulatory standards.

Page 25: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

‣  CloudTrail records API calls and delivers a log file to your S3 bucket.

‣  Typically, delivers an event within 15 minutes of the API call.

‣  Log files are delivered approximately every 5 minutes.

‣  Multiple partners offer integrated solutions to analyze log files.

Page 26: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

LOGS OBTAINED, RETAINED, ANALYZED

Page 27: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 28: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 29: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

PROTECT YOUR LOGS WITH IAM ARCHIVE YOUR LOGS

Page 30: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 31: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 32: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

MORE CONTROL

Page 33: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

Defense in Depth Multi level security

•  Physical security of the data centers •  Network security •  System security •  Data security DATA

Page 34: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

AWS Security Delivers More Control & Granularity Customize the implementation based on your business needs

AWS CloudHSM

Defense in depth

Rapid scale for security

Automated checks with AWS Trusted Advisor

Fine grained access controls

Server side encryption

Multi-factor authentication

Dedicated instances

Direct connection, Storage Gateway

HSM-based key storage

AWS IAM

Amazon VPC

AWS Direct Connect

AWS Storage Gateway

Page 35: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

AWS STAFF ACCESS

‣  Staff vetting ‣  Staff has no logical access to customer instances ‣  Staff control-plane access limited & monitored

Bastion hosts, Least privileged model, Zoned data center access ‣  Business needs ‣  Separate PAMS

Page 36: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 37: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 38: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 39: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 40: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 41: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 42: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 43: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

LEAST PRIVILEGE PRINCIPLE CONFINE ROLES ONLY TO THE MATERIAL

REQUIRED TO DO SPECIFIC WORK

Page 44: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

MORE CONTROL ON IDENTITY & ACCESS

Page 45: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

USE AWS IAM IDENTITY & ACCESS MANAGEMENT

Page 46: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

CONTROL WHO CAN DO WHAT WITH YOUR AWS ACCOUNT

Page 47: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 48: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

AWS IAM: Recent Innovations Securely control access to AWS services and resources

•  Delegation –  Roles for Amazon EC2

–  Cross-account access

•  Powerful integrated permissions –  Resource level permissions: Amazon

EC2, Amazon RDS, Amazon DynamoDB, AWS CloudFormation

–  Access control policy variables

–  Policy Simulator

–  Enhanced IAM support: Amazon SWF, Amazon EMR, AWS Storage Gateway, AWS CloudFormation, Amazon Redshift, Elastic Beanstalk

•  Federation –  Web Identity Federation

–  AD and Shibboleth examples

–  Partner integrations

–  Case study: Expedia

•  Strong authentication –  MFA-protected API access

–  Password policies

•  Enhanced documentation and videos

Page 49: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

ACCESS TO SERVICE APIs

Page 50: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

Amazon DynamoDB Fine Grained Access Control

Directly and securely access application data in Amazon DynamoDB Specify access permissions at table, item and attribute levels With Web Identity Federation, completely remove the need for proxy servers to perform authorization

Page 51: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

MORE CONTROL OF YOUR DATA

Page 52: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

MFA DELETE PROTECTION

Page 53: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 54: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

YOUR DATA STAYS WHERE YOU PUT IT

Page 55: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security
Page 56: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

USE MULTIPLE AZs AMAZON S3

AMAZON DYNAMODB AMAZON RDS MULTI-AZ

AMAZON EBS SNAPSHOTS

Page 57: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

DATA ENCRYPTION

CHOOSE WHAT’S RIGHT FOR YOU: Automated – AWS manages encryption

Enabled – user manages encryption using AWS Client-side – user manages encryption using their own mean

Page 58: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

AWS CloudHSM

Managed and monitored by AWS, but you control the keys

Increase performance for applications that use HSMs for key storage or encryption

Comply with stringent regulatory and contractual requirements for key protection

EC2 Instance

AWS CloudHSM

AWS CloudHSM

Page 59: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

ENCRYPT YOUR DATA AWS CLOUDHSM AMAZON S3 SSE

AMAZON GLACIER AMAZON REDSHIFT

AMAZON RDS …

Page 60: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc.

Axway, Cloud and Security David FIGINI, VP Cloud Managed Services EMEA

Page 61: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

•  11,000 customers •  100 countries •  332,5M € revenue in 2013 •  1,700+ employees •  HQ in Phoenix, AZ USA •  Offices in 19 countries

Governing the flow of data

DATA FLOW GOVERNANCE

Page 62: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

Axway Cloud and AWS •  Start Quickly •  Everywhere •  No initial cost •  Pay per use •  Scale up and down •  No commitment •  Repeatable •  Reliable •  Secure

VPC (Virtual Private Cloud) – Privatization for Cloud components.

Data centers (zones) - Tier IV and compliant with all major third-party certifications.

Storage – 99.999999999 durability

Database – Multizone configuration

Elastic Load Balancers – Zone independence

VPN – AWS Direct Connect provides dedicated private networking for increased bandwidth and reliability.

EC2 Instances – Elastic computing

Cloud Formation – Reliable delivery from Web Services

Applications – Designed for no single points of failure and non-repudiation.

All services are monitored through a centralized location utilizing, SES, SNS, Cloud Watch, Nagios, etc.

Page 63: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

Axway Cloud threat mitigation

Architecture and Datacenter Vulnerabilities

Service Platform Availability

Information Confidentiality and Integrity Loss Decrease in Functional Performance

Human Activities

• Multi AZ Auto-Scaling groups Very High Availability

• Solution deployed by Axway OS Patch management

• Data encryption at rest and for communications

• Backup policy based on snapshots

Data loss and confidentiality

• Access to environments is centralized and all activity is tracked Human activity

• Security and monitoring tools (Ossec, syslog, Nagios, CloudWatch, …)

• Splunk to receive, process and present security events

Real time monitoring

Page 64: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

Axway Cloud security architecture

•  SOC1 Type 2 certification achieved in March •  ISO27001 Beginning of 2015

Management

Solution

Access Control

Axway data center Amazon Route 53

Axway workforce VPN

Elastic Load Balancing

Supervision

Monitoring & Security

tools

VPC peering

Solution

Elastic Load Balancing

VPC peering

Monitoring & Security

data

Access

CloudWatch Amazon SES

Auto Scaling group

AZ #1

AZ #2

Auto Scaling group

AZ #1

AZ #2 CloudTrail

Page 65: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

•  Axway governs the flow of data in the Cloud

•  Axway Cloud is based on a strong AWS partnership

•  Security = AWS + Axway + Processes+ People

Takeaways from Axway

Page 66: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc.

Axway, Cloud and Security David FIGINI, VP Cloud Managed Services EMEA

Merci !

Page 67: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

MORE AUDITABILITY MORE VISIBILITY MORE CONTROL

Page 68: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

IDC Survey Attitudes and Perceptions Around Security and Cloud Services Nearly 60% of organizations agreed that CSPs [Cloud Service Providers] provide better security than their own IT organization

Source: IDC 2013 U.S. Cloud Security Survey Doc #242836, September 2013

Page 69: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

AWS.AMAZON.COM / SECURITY

Page 70: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

AWS SECURITY WHITEPAPERS

RISK & COMPLIANCE

AUDITING SECURITY CHECKLIST

SECURITY PROCESSES

SECURITY BEST PRACTICES

Page 71: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

AWS MARKETPLACE SECURITY SOLUTIONS

Page 72: AWS Paris Summit 2014 - Keynote Stephen Schmidt - AWS Security

© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc.

AWS Security Stephen E. Schmidt, Directeur de la Sécurité

Merci !