Top Banner
© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc. AWS Security Stephen E. Schmidt, Directeur de la Sécurité
83

AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

Apr 23, 2018

Download

Documents

buiquynh
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc.

AWS Security

Stephen E. Schmidt, Directeur de la Sécurité

Page 2: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

Different customer viewpoints on security

PR exec keep out of the news

CEO protect shareholder

value

CI{S}O preserve the

confidentiality, integrity

and availability of data

Page 3: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

Security is Our No.1 Priority Comprehensive Security Capabilities to Support Virtually Any Workload

PEOPLE &

PROCEDURES

NETWORK

SECURITY

PHYSICAL

SECURITY

PLATFORM

SECURITY

Page 4: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

SECURITY IS SHARED

Page 5: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

WHAT NEEDS

TO BE DONE

TO KEEP THE

SYSTEM SAFE

Page 6: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

WHAT

WE DO

WHAT YOU

HAVE TO DO

Page 7: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

SOC CONTROL OBJECTIVES

1. SECURITY ORGANIZATION

2. AMAZON USER ACCESS

3. LOGICAL SECURITY

4. SECURE DATA HANDLING

5. PHYSICAL SECURITY AND ENV. SAFEGUARDS

6. CHANGE MANAGEMENT

7. DATA INTEGRITY, AVAILABILITY AND REDUNDANCY

8. INCIDENT HANDLING

Page 8: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

YOUR DATA IS YOUR

MOST IMPORTANT ASSET IF YOUR DATA IS NOT SECURE, YOU’RE NOT SECURE

Page 9: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 10: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

CHANGES IN PRODUCTION

HAVE TO BE AUTHORIZED

Page 11: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

DEPLOYMENT PROCESS

HAS TO BE CONSTRAINED

Page 12: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

NETWORK SECURITY

Page 13: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

“GAME DAYS” INSERT ARTIFICIAL SECURITY INCIDENTS.

MEASURE SPEED OF DETECTION AND EXECUTION.

Page 14: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 15: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

EVERY CUSTOMER HAS ACCESS

TO THE SAME SECURITY

CAPABILITIES

CHOOSE WHAT’S RIGHT FOR YOUR BUSINESS

Page 16: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

“Based on our experience, I believe that we

can be even more secure in the AWS

cloud than in our own data centers”

Tom Soderstrom – CTO – NASA JPL

Page 17: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

AWS SECURITY OFFERS MORE

VISIBILITY

AUDITABILITY

CONTROL

Page 18: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

MORE VISIBILITY

Page 19: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

CAN YOU MAP YOUR NETWORK?

WHAT IS IN YOUR ENVIRONMENT

RIGHT NOW?

Page 20: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 21: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 22: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

TRUSTED ADVISOR

Page 23: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 24: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 25: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 26: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

MORE AUDITABILITY

Page 27: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 28: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 29: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

INTRODUCING

AWS CLOUDTRAIL

Page 30: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

You are making

API calls... On a growing set of

services around the

world…

CloudTrail is

continuously

recording API

calls…

And delivering

log files to you

Page 31: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

Security Analysis Use log files as an input into log management and analysis solutions to perform

security analysis and to detect user behavior patterns.

Track Changes to AWS Resources Track creation, modification, and deletion of AWS resources such as Amazon EC2

instances, Amazon VPC security groups and Amazon EBS volumes.

Troubleshoot Operational Issues Quickly identify the most recent changes made to resources in your environment.

Compliance Aid Easier to demonstrate compliance with internal policies and regulatory standards.

Page 32: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

‣ CloudTrail records API calls and

delivers a log file to your S3 bucket.

‣ Typically, delivers an event within 15

minutes of the API call.

‣ Log files are delivered approximately

every 5 minutes.

‣ Multiple partners offer integrated

solutions to analyze log files.

Page 33: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

LOGS

OBTAINED, RETAINED, ANALYZED

Page 34: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 35: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 36: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

PROTECT YOUR LOGS WITH IAM

ARCHIVE YOUR LOGS

Page 37: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 38: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 39: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

VULNERABILITY

& PENETRATION TESTING

Page 40: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

VULNERABILITY

& PENETRATION TESTING

Page 41: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

MORE CONTROL

Page 42: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

Defense in Depth Multi level security

• Physical security of the data centers

• Network security

• System security

• Data security

Page 43: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

AWS Security Delivers More Control & Granularity Customize the implementation based on your business needs

AWS

CloudHSM

Defense in depth

Rapid scale for security

Automated checks with AWS Trusted Advisor

Fine grained access controls

Server side encryption

Multi-factor authentication

Dedicated instances

Direct connection, Storage Gateway

HSM-based key storage

AWS IAM

Amazon VPC

AWS Direct

Connect

AWS Storage

Gateway

Page 44: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

AWS STAFF ACCESS

‣ Staff vetting

‣ Staff has no logical access to customer instances

‣ Staff control-plane access limited & monitored Bastion hosts, Least privileged model, Zoned data center access

‣ Business needs

‣ Separate PAMS

Page 45: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 46: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 47: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 48: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 49: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 50: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 51: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

MORE CONTROL

ON IDENTITY & ACCESS

Page 52: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

LEAST PRIVILEGE PRINCIPLE CONFINE ROLES ONLY TO THE MATERIAL

REQUIRED TO DO A SPECIFIC WORK

Page 53: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

USE AWS IAM IDENTITY & ACCESS MANAGEMENT

Page 54: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

CONTROL WHO CAN DO WHAT IN

YOUR AWS ACCOUNT

Page 55: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 56: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 57: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 58: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

AWS IAM: Recent Innovations Securely control access to AWS services and resources

• Delegation

– Roles for Amazon EC2

– Cross-account access

• Powerful integrated permissions

– Resource level permissions: Amazon EC2, Amazon RDS, Amazon DynamoDB, AWS CloudFormation

– Access control policy variables

– Policy Simulator

– Enhanced IAM support: Amazon SWF, Amazon EMR, AWS Storage Gateway, AWS CloudFormation, Amazon Redshift, Elastic Beanstalk

• Federation

– Web Identity Federation

– AD and Shibboleth examples

– Partner integrations

– Case study: Expedia

• Strong authentication

– MFA-protected API access

– Password policies

• Enhanced documentation and videos

Page 59: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

ACCESS TO

SERVICE APIs

Page 60: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

Amazon DynamoDB Fine Grained

Access Control

Directly and securely access application

data in Amazon DynamoDB

Specify access permissions at table, item

and attribute levels

With Web Identity Federation, completely

remove the need for proxy servers to

perform authorization

Page 61: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

MORE CONTROL

ON YOUR DATA

Page 62: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

MFA DELETE PROTECTION

Page 63: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 64: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

YOUR DATA STAYS

WHERE YOU PUT IT

Page 65: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely
Page 66: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

REDUNDANCY

& INTEGRITY CHECKS

Page 67: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

USE MULTIPLE AZs AMAZON S3

AMAZON DYNAMODB

AMAZON RDS MULTI-AZ

AMAZON EBS SNAPSHOTS

Page 68: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

DATA ENCRYPTION

CHOOSE WHAT’S RIGHT FOR YOU:

Automated – AWS manages encryption

Enabled – user manages encryption using AWS

Client-side – user manages encryption using their own mean

Page 69: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

AWS CloudHSM

Managed and monitored by AWS, but you

control the keys

Increase performance for applications that

use HSMs for key storage or encryption

Comply with stringent regulatory and

contractual requirements for key protection

EC2 Instance

AWS CloudHSM

AWS CloudHSM

Page 70: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

ENCRYPT YOUR DATA AWS CLOUDHSM

AMAZON S3 SSE

AMAZON GLACIER

AMAZON REDSHIFT

AMAZON RDS

Page 71: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc.

Axway, Cloud and Security

David FIGINI, VP Cloud Managed Services EMEA

Page 72: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

• 11,000 customers

• 100 countries

• 332,5M € revenue in 2013

• 1,700+ employees

• HQ in Phoenix, AZ USA

• Offices in 19 countries

Governing the flow of data

DATA FLOW GOVERNANCE

Page 73: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

Axway Cloud and AWS

• Start Quickly

• Everywhere

• No initial cost

• Pay per use

• Scale up and down

• No commitment

• Repeatable

• Reliable

• Secure

VPC (Virtual Private

Cloud) – Privatization for Cloud components.

Data centers (zones) - Tier IV and compliant with all major third-party certifications.

Storage – 99.999999999 durability

Database – Multizone configuration

Elastic Load Balancers – Zone independence

VPN – AWS Direct Connect provides dedicated private networking for increased bandwidth and reliability.

EC2 Instances – Elastic computing

Cloud Formation – Reliable delivery from Web Services

Applications – Designed for no single points of failure and non-repudiation.

All services are monitored through a centralized location utilizing, SES, SNS, Cloud Watch, Nagios, etc.

Page 74: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

Axway Cloud threat mitigation

Architecture and Datacenter Vulnerabilities

Service Platform Availability

Information Confidentiality and Integrity Loss

Decrease in Functional Performance

Human Activities

• Multi AZ Auto-Scaling groups Very High Availability

• Solution deployed by Axway OS Patch

management

• Data encryption at rest and for communications

• Backup policy based on snapshots

Data loss and confidentiality

• Access to environments is centralized and all activity is tracked Human activity

• Security and monitoring tools (Ossec, syslog, Nagios, CloudWatch, …)

• Splunk to receive, process and present security events

Real time monitoring

Page 75: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

Axway Cloud security architecture

• SOC1 Type 2 certification achieved in March

• ISO27001 Beginning of 2015

Management

Solution

Access

Control

Axway data center

Amazon

Route 53

Axway

workforce VPN

Elastic Load

Balancing

Supervision

Monitoring

& Security

tools

VPC peering

Solution

Elastic Load

Balancing

VPC peering

Monitoring

& Security

data

Acc

ess

CloudWatch Amazon SES

Auto Scaling group

AZ #1

AZ #2

Auto Scaling group

AZ #1

AZ #2

CloudTrail

Page 76: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

• Axway governs the flow of data in the Cloud

• Axway Cloud is based on a strong AWS partnership

• Security = AWS + Axway + Processes+ People

Takeaways from Axway

Page 77: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc.

Axway, Cloud and Security

David FIGINI, VP Cloud Managed Services EMEA

Merci !

Page 78: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

MORE AUDITABILITY

MORE VISIBILITY

MORE CONTROL

Page 79: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

“Based on our experience, I believe that we

can be even more secure in the AWS

cloud than in our own data centers”

Tom Soderstrom – CTO – NASA JPL

Page 80: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

AWS.AMAZON.COM / SECURITY

Page 81: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

AWS SECURITY WHITEPAPERS

RISK & COMPLIANCE

AUDITING SECURITY CHECKLIST

SECURITY PROCESSES

SECURITY BEST PRACTICES

Page 82: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

AWS MARKETPLACE

SECURITY SOLUTIONS

Page 83: AWS Security - Amazon Web Servicesaws-de-media.s3.amazonaws.com/images/summit-berlin/Learn-11.30... · 2. AMAZON USER ACCESS 3. LOGICAL SECURITY 4. SECURE DATA HANDLING 5. ... Securely

© 2014 Amazon.com, Inc. and its affiliates. All rights reserved. May not be copied, modified, or distributed in whole or in part without the express consent of Amazon.com, Inc.

AWS Security

Stephen E. Schmidt, Directeur de la Sécurité

Merci !