Updating Security Operations For The Cloud

36

Transcript of Updating Security Operations For The Cloud

Page 1: Updating Security Operations For The Cloud
Page 2: Updating Security Operations For The Cloud

@marknca

Page 3: Updating Security Operations For The Cloud

Strategy

Tactics

Page 4: Updating Security Operations For The Cloud

Traditional Responsibility Model

You

Page 5: Updating Security Operations For The Cloud

AWS You

Shared Responsibility Model

Page 6: Updating Security Operations For The Cloud

AWS

Facilities Physical Network Virtualization Layer

You

Shared Responsibility Model

Page 7: Updating Security Operations For The Cloud

Monitoring Forensics

4 pillars of practice

Page 8: Updating Security Operations For The Cloud
Page 9: Updating Security Operations For The Cloud
Page 10: Updating Security Operations For The Cloud
Page 11: Updating Security Operations For The Cloud

SANS incident response process

Page 12: Updating Security Operations For The Cloud

SANS incident response process

Page 13: Updating Security Operations For The Cloud

Business point of view

Page 14: Updating Security Operations For The Cloud

Incident response before

Server

Analyze Repair Improve

Replacement

Page 15: Updating Security Operations For The Cloud

Incident response after

Instance

Analyze Repair Improve

Replacement

Page 16: Updating Security Operations For The Cloud

Advantages

Page 17: Updating Security Operations For The Cloud

In action…

Page 18: Updating Security Operations For The Cloud
Page 19: Updating Security Operations For The Cloud

Optimized response

Page 20: Updating Security Operations For The Cloud

Optimized response

Instance

Script

Analyze

Improve

API

Replacement

Page 21: Updating Security Operations For The Cloud
Page 22: Updating Security Operations For The Cloud
Page 23: Updating Security Operations For The Cloud
Page 24: Updating Security Operations For The Cloud

Business point of view

Page 25: Updating Security Operations For The Cloud

Creating an audit trail before

Servers

Change Record Storage Logs

Firewall / IPS

Page 26: Updating Security Operations For The Cloud

Creating an audit trail before

Instances

Change Record

Central Management

Logs

AWS Services

Page 27: Updating Security Operations For The Cloud
Page 28: Updating Security Operations For The Cloud

In action…

Page 29: Updating Security Operations For The Cloud
Page 30: Updating Security Operations For The Cloud
Page 31: Updating Security Operations For The Cloud
Page 32: Updating Security Operations For The Cloud
Page 33: Updating Security Operations For The Cloud
Page 34: Updating Security Operations For The Cloud
Page 35: Updating Security Operations For The Cloud
Page 36: Updating Security Operations For The Cloud

Please give us your feedback on this presentation

#reinvent