einführung „compliance mit aws" - aws security web day

14
Reading the AWS Compliance Framework Bertram Dorn Specialized Solutions Architect EMEA For Security and Compliance

Upload: aws-germany

Post on 16-Apr-2017

415 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Einführung „Compliance mit AWS" - AWS Security Web Day

Reading  the AWS  Compliance  FrameworkBertram  DornSpecialized Solutions  Architect EMEAFor Security  and Compliance

Page 2: Einführung „Compliance mit AWS" - AWS Security Web Day

Agenda:• Overview• ISO• SOC• Documents• A  Demo

Page 3: Einführung „Compliance mit AWS" - AWS Security Web Day

Certifications/Audits:  Overview

Page 4: Einführung „Compliance mit AWS" - AWS Security Web Day

Shared Responsibility

Cross-service Controls

Service-specific Controls

Managed by AWS

Managed by Customer

Security of the Cloud

Security in the Cloud

Cloud Service Provider Controls

Optimized Network/OS/App Controls

Request reports at:aws.amazon.com/compliance/#contact

ISO27000

ISO9001

Page 5: Einführung „Compliance mit AWS" - AWS Security Web Day

The main AWS Compliance Frameworks of todayCertificates: Programmes:

ISO9001

ISO27000

MPAA

Page 6: Einführung „Compliance mit AWS" - AWS Security Web Day

Point-­in-­time,  or  continuous  compliance  assessments?

ISO27001/27017

270189001

Page 7: Einführung „Compliance mit AWS" - AWS Security Web Day

Certifications/Audits:  Scope

Page 8: Einführung „Compliance mit AWS" - AWS Security Web Day

Scope

• By Service  (not  only Datacenter)• By Region• By Certification• Global• Scalable

Page 9: Einführung „Compliance mit AWS" - AWS Security Web Day

Certifications/Audits:  Demo  Scope

Page 10: Einführung „Compliance mit AWS" - AWS Security Web Day

Compliance  Mapping:  How to do  that

Page 11: Einführung „Compliance mit AWS" - AWS Security Web Day

Mapping

Page 12: Einführung „Compliance mit AWS" - AWS Security Web Day

Compliance  Mapping:  Demo

Page 13: Einführung „Compliance mit AWS" - AWS Security Web Day
Page 14: Einführung „Compliance mit AWS" - AWS Security Web Day

Thank  You