50
AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

Embed Size (px)

DESCRIPTION

Description: The Government faces the paramount challenge of building sensitive IT systems in the Cloud while maintaining stringent security requirements. Learn from the experts about using integrated security features available in AWS GovCloud (US) to make your mission workloads more secure and robust.

Citation preview

Page 1: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 2: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 3: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 4: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

TacticsAuditing

Incident response

Page 5: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Traditional Responsibility Model

You

Page 6: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Shared Responsibility Model

AWS You

Page 7: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Shared Responsibility Model

AWS You

Page 8: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Structure

Page 9: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Auditing

Page 10: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 11: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Requirements

Page 12: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Creating an audit trail, before

Page 13: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Creating an audit trail, after

Page 14: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Creating an audit trail, bonus

You get• Record of changes via AWS CloudTrail• Security control reporting via Deep Security’s API

Why it matters• Regular assurance controls are in place

Page 15: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 16: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 17: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 18: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 19: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

SANS incidence response process

Page 20: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

SANS incidence response process

Page 21: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Requirements

Page 22: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, before

Page 23: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, before

Page 24: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, before

Page 25: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, before

Page 26: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, before

Page 27: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, after

Page 28: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, after

Page 29: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, after

Page 30: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, after

Page 31: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, after

Page 32: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Incident response, bonus

Page 33: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 34: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 35: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Optimized response

Page 36: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Optimized response

Page 37: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Optimized response

Page 38: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Optimized response

Page 39: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Optimized response

Page 40: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Optimized response

Page 41: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Optimized response

Page 42: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Optimized response

Page 43: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Optimized response

Page 44: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Optimized response, requirements

Page 45: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 46: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 47: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 48: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 49: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Page 50: Security Features of AWS Services in AWS GovCloud (US) - AWS Symposium 2014 - Washington D.C

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

AWS Government, Education, and Nonprofits Symposium Washington, DC | June 24, 2014 - June 26, 2014

Thank YouMark Nunnikhoven

@marknca