aws security overview

17
AWS SECURITY OVERVIEW Anton Pogoryelyi DevOps TechLead @ Bazaarvoice

Upload: anton-pohorilyi

Post on 13-Apr-2017

30 views

Category:

Software


0 download

TRANSCRIPT

AWS SECURITY OVERVIEW

Anton PogoryelyiDevOps TechLead @ Bazaarvoice

AGENDA

• Security matters

• Shared security model

• AWS security features overview

• Security processes automation

SECURITY MATTERSFrom few $ to out of business stories

SHARED SECURITY MODELFor IaaS

SHARED SECURITY MODELFor PaaS

For SaaSSHARED SECURITY MODEL

AWS ASSURANCE PROGRAMShttp://aws.amazon.com/compliance/

KEY SECURITY FEATURES

VPCReduce your surface to protect

BASTIONProtect SSH/RDS access

with bastion host

SECURITY GROUPSMulti-tier architecture

IAMIAM Users/Groups/Roles

IAM TEMPORARY CREDENTIAL

SUsing IAM roles and temporary security credentials means you don't always have to manage long-term credentials and IAM users for each entity that requires access to a resource.

UNTRUSTED AMIhttps://aws.amazon.com/marketplace

SECURITY PROCESS

AUTOMATION• bastion configuration• IAM access• mandatory tags• cost alerts• repository checks

OUR BEAVERS

ARMY• Conformity Beaver –

resource tagging check• Janitor Beaver – unused

resources check• Security Beaver – security

best practices check• Miserly Beaver – cost

anomalies check

THANK YOUQuestions?