Top Banner
AWS SECURITY OVERVIEW Anton Pogoryelyi DevOps TechLead @ Bazaarvoice
17

AWS Security Overview

Apr 13, 2017

Download

Software

Anton Pohorilyi
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: AWS Security Overview

AWS SECURITY OVERVIEW

Anton PogoryelyiDevOps TechLead @ Bazaarvoice

Page 2: AWS Security Overview

AGENDA

• Security matters

• Shared security model

• AWS security features overview

• Security processes automation

Page 3: AWS Security Overview

SECURITY MATTERSFrom few $ to out of business stories

Page 4: AWS Security Overview

SHARED SECURITY MODELFor IaaS

Page 5: AWS Security Overview

SHARED SECURITY MODELFor PaaS

Page 6: AWS Security Overview

For SaaSSHARED SECURITY MODEL

Page 7: AWS Security Overview

AWS ASSURANCE PROGRAMShttp://aws.amazon.com/compliance/

Page 8: AWS Security Overview

KEY SECURITY FEATURES

Page 9: AWS Security Overview

VPCReduce your surface to protect

Page 10: AWS Security Overview

BASTIONProtect SSH/RDS access

with bastion host

Page 11: AWS Security Overview

SECURITY GROUPSMulti-tier architecture

Page 12: AWS Security Overview

IAMIAM Users/Groups/Roles

Page 13: AWS Security Overview

IAM TEMPORARY CREDENTIAL

SUsing IAM roles and temporary security credentials means you don't always have to manage long-term credentials and IAM users for each entity that requires access to a resource.

Page 14: AWS Security Overview

UNTRUSTED AMIhttps://aws.amazon.com/marketplace

Page 15: AWS Security Overview

SECURITY PROCESS

AUTOMATION• bastion configuration• IAM access• mandatory tags• cost alerts• repository checks

Page 16: AWS Security Overview

OUR BEAVERS

ARMY• Conformity Beaver –

resource tagging check• Janitor Beaver – unused

resources check• Security Beaver – security

best practices check• Miserly Beaver – cost

anomalies check

Page 17: AWS Security Overview

THANK YOUQuestions?