Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS...

23
Secure Your New Public Cloud

Transcript of Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS...

Page 1: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Secure Your New Public Cloud

Page 2: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

21st Century IT Security

Cloud Security

Page 3: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Shared Responsibility Model

CUSTOMER DATA

PLATFORM & APPLICATION MANAGEMENT

OPPERATING SYSTEM, NETWORK, & FIREWALL CONFIGURATION

CLIENT-SIDE DATA ENCRYPTION & DATA INTEGRITY AUTHENTICATION

SERVER-SIDE ENCRYPTION(FILE SYSTEM AND/OR DATA)

NETWORK TRAFFIC PROTECTION(ENCRYPTION/INTEGRITY/IDENTITY)

OPTIONAL – OPAQUE DATA: 0S & 1S (IN TRANSIT/AT REST)

FOUNDATION SERVICES

AWS GLOBAL INFRASTRUCTURE

AWS

ENDP

OINT

S AWS IAM

CUSTOMER IAM

COMPUTE STORAGE DATABASES NETWORKING

REGIONS AVAILABILITY ZONES

EDGE LOCATIONS

Managed by AWS Customers

Managed by Amazon Web Services

Page 4: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Shared Responsibility Model

CUSTOMER DATA

PLATFORM & APPLICATION MANAGEMENT

OPPERATING SYSTEM, NETWORK, & FIREWALL CONFIGURATION

CLIENT-SIDE DATA ENCRYPTION & DATA INTEGRITY AUTHENTICATION

SERVER-SIDE ENCRYPTION(FILE SYSTEM AND/OR DATA)

NETWORK TRAFFIC PROTECTION(ENCRYPTION/INTEGRITY/IDENTITY)

OPTIONAL – OPAQUE DATA: 0S & 1S (IN TRANSIT/AT REST)

FOUNDATION SERVICES

AWS GLOBAL INFRASTRUCTURE

AWS

ENDP

OINT

S AWS IAM

CUSTOMER IAM

COMPUTE STORAGE DATABASES NETWORKING

REGIONS AVAILABILITY ZONES

EDGE LOCATIONS

Managed by AWS Customers

Managed by Amazon Web Services

Security IN the Cloud

Security OF the Cloud

Page 5: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

MORE VISIBILITYMORE CONTROL

MORE AUDITABILITYMORE AGILITY

Page 6: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Security is Visible

Who is accessing the resources?Who took what action?

§ When?§ From where?§ What did they do?§ Logs Logs Logs

Page 7: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.
Page 8: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.
Page 9: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

EVERYTHING IS AN API CALL.

Page 10: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

EVERYTHING GENERATES LOGS.

Page 11: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

TERABYTES OF LOGS A DAY…

Page 12: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

21st Century IT Security

Intelligent Security

Page 13: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Protect Sensitive Data: Macie

Page 14: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Protect Sensitive Data: Macie

Page 15: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

AWS Shield: Managed DDoS Protection

Page 16: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

CloudWatch Alert:More than 1,000

Open Connections to ELB from a single IP

Log an incident

WAF Rule: block source

Wait 1 hour

Remove WAF Rule

AWS WAF

AWS ELB

S3 Evidence Repository

ForensicsSave Logs

CloudWatch

Automated Incident Response: DDoS Attack

Page 17: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Intelligent Threat Detection: GuardDuty

Page 18: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Intelligent Threat Detection: GuardDuty

Page 19: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Cloud is Simply Better: Personal Data Protection & GDPR

Page 20: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Automated Incident Response: Infected Instance

Guard Duty Report: Instance ID

i-1234567890abcdef0

Log an incident

Isolate the Instance from the

network

Shut down instance

S3 Evidence Repository

Memory Dump

Disk Dump

Forensics

Page 21: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Establishing Secure Cloud Services

ISO 27001PCI/DSS

Personal Data Protection

CSP

Com

plia

nce,

Thre

at a

nd G

ap

Anal

ysis

Secu

rity

Stra

tegy

Desig

n

Secu

rity

Prog

ram

me

Desig

n

Secu

rity

Play

book

Impl

emen

tatio

n&

Test

ing

Secure & Compliant Cloud

Systems & Applications

Risk Management

Security Operations & Management

Legacy Cloud Systems &

Applications

Page 22: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

Cloud Security

ConsiderationsPREPARE

PREVENT

DETECT

RESPOND

Page 23: Secure Your New Public Cloud€¦ · S IAM M COMPUTE STORAGE DATABASES NETWORKING REGIONS AVAILABILITY ZONES EDGE LOCATIONS Managed by AWS Customers Managed by Amazon Web Services.

HeleCloud Company Overview

Maidenhead, UK1 Bell Street, Maidenhead, Berkshire, SL6 1BU, UK,

+44 20 3286 [email protected]

Thank you!

[email protected]