(dvo206) how to securely scale teams, workloads, and budgets

24
© 2015, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Jim Hoover, Chief Information Security Officer Matt Yanchyshyn, Sr. Manager, Solutions Architecture Adam Boyle, Director of Product Management, Cloud Workload Security October 2015 DVO206 Lessons from a CISO How to Securely Scale Teams, Workloads, and Budgets

Upload: amazon-web-services

Post on 13-Jan-2017

637 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

© 2015, Amazon Web Services, Inc. or its Affiliates. All rights reserved.

Jim Hoover, Chief Information Security Officer

Matt Yanchyshyn, Sr. Manager, Solutions Architecture

Adam Boyle, Director of Product Management, Cloud Workload Security

October 2015

DVO206

Lessons from a CISOHow to Securely Scale Teams,

Workloads, and Budgets

Page 2: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Takeaways

Scale workload security

Level up security teams

Improve CxO visibility

Page 3: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Jim Hoover, CISO

Page 4: (DVO206) How to Securely Scale Teams, Workloads, and Budgets
Page 5: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

3,500+Customers in the cloud

8+ PBData in the Infor cloud

45m+Users

6300+Sites

Infor at Scale in the Cloud

Page 6: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Iron to APIs

Page 7: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Data Center Security Challenges

Lots of different groups

Lots of different tools

Nothing speaking the same language

Page 8: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

“Security in the Cloud” Concerns

Tools

Security controls

Compliance

Page 9: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

The Infor Security Stack in AWS Cloud

AWS cloud

Shared

responsibility

Compliance

Page 10: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Best Practices for Large-Scale Security

1. Segment your AWS environment

2. Control access and segregate duties

3. Monitor for unexpected behavior

Page 11: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Your organization

Project Teams Marketing

Business Units Reporting

Web &

Mobile

Dev / Test Analytics

Internal

Enterprise

Apps

Amazon S3

Amazon

Glacier

Storage/

Backup

Large-Scale Security Best Practice #1

Segment your AWS environment

Page 12: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

• Multi-factor authentication

• Federation and single sign-on

• Fine-grained access control

• Restrict human access

AWSaccount owner

Network management

Security management

Server management

Storage management

Large-Scale Security Best Practice #2

Control access, segregate duties

Page 13: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

• AWS CloudTrail• API and console usage

• AWS Config• Infrastructure history and changes

• Amazon CloudWatch• Resource metrics and log monitoring

• AWS Billing and Cost Management

Large-Scale Security Best Practice #3

Monitor for unexpected behavior

Page 14: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Team Works

Page 15: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Data Center Security Operations Challenges

Security team Application teams

Page 16: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Security Operations Skill Development

Security ops Cloud security DevOps

Page 17: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Security Operations in AWS Cloud

Cloud security DevOps Application teams

Page 18: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

AWS Security Rock Star Cookbook

1. AWS-specific security knowledge

• https://aws.amazon.com/security

2. Analytics: Threat intelligence; log analysis at scale

• https://aws.amazon.com/big-data

3. DevSecOps: The ability to quickly and continuously

respond to new threats as they emerge

• https://aws.amazon.com/training/course-descriptions/devops-

engineering

Page 19: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

CxO Visibility

Page 20: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

CxO Visibility at Scale

CISO CIO COO CFO

Page 21: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

In Summary

Simplicity & visibility = scale

SecOps: Do more with less

CxO: Visibility & compliance

Page 22: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Thank you!

Page 23: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Come see us at Booth #1004

http://aws.trendmicro.com

Page 24: (DVO206) How to Securely Scale Teams, Workloads, and Budgets

Remember to complete

your evaluations!