best practice public cloud security

13
Best Practice: Public Cloud Security Joel Friedman Chief Technology and Security Officer, Datapipe

Upload: jason-singh

Post on 11-Jan-2017

263 views

Category:

Technology


3 download

TRANSCRIPT

BestPractice:PublicCloudSecurityJoelFriedmanChiefTechnologyandSecurityOfficer,Datapipe

Cloudsecurityispartofyourwidersecuritystrategy

DATACENTERASASERVICE

COLOCATION CLOUDCOMPUTING

INFRASTRUCTUREASASERVICE

MANAGEDSERVICES

GLOBALFACILITIES

2

3

ONPREMISE COLOCATION HYBRIDCLOUD PUBLICCLOUD

LOW APPETITEFORRISK HIGH

3pillarsofcloudsecurity

4

Platform Security

Instance Security

Governance

DatapipeAccessControlModuleforAWS(DACMA)

• ClientsretainownershipoftheirAWSrootaccountcredentials

• DoesnotrequireDatapipeaccesstotheclientaccountkeys

• Providesanadditionalsecuritylayerforenterpriseclients

• RequiresnoextrastepsoncesetupandreducestheriskofdisruptionofserviceordatabreachduetounauthorizedaccessofanAWSenvironmentfromsupportpersonnel

5

HowDACMAworks

6

BrowserorApplication

DATAPIPE

1UseraccessesCMS

DatapipeCloudManagementSystem(CMS)

Signinwithtoken

SSO 2

AWSPLATFORM

DatapipeAWSAccount

EmployeeIAM EmployeeIAM…

EmployeeIAM

DatapipeRole

AWSManagementConsole

5

KeyVaultTokenSeeds APIKeys

Retrieve AWSlogindata

4

“Client”AWSAccount

STS

5

5

6

LDAP

Retrievedepartmentattributes

3

DatapipeSupportPersonnelAWSrolebasedpermissionspassedviaLDAP

Governance:SystemLifecycle

Monitoring/Queuing Event

Auto Scaling

Server Images

New Instance

Code Repository

Elastic LoadBalancer

Configuration Management

Web Zone

Security Console

Role Registration

Policy Maintainer

11

• Securitycontroldeploymentintegrateddirectly intothesystemlifecycle

• Appropriatecontrolsautomaticallydeployedduringserverpersonalizationprocess

• Puppet,user-data,customservertemplatesallusedinconjunctiontofacilitatedynamicsystemdeployments

DatapipeSecurityApproach

8

Completeendtoendassessmentandmanagement

Datapipe Security Controls

Physical Controls

Technical Controls

Administrative Controls

Bestofbreedsecuritypartnersatyourfingertips

10

Andacompletesetofcomplianceservices

• Industry-leadingcompliantsolutions optimizedfor:

• WegobeyondtherequirementsdictatedbyHIPAA,PCIDSS,SOXandFISMA

• Ourgoalistoensureacontinuous compliance record thatreaffirmsthesecurityandintegrityofyourorganization

• Ourstaffarehighlyskilledwithindustrysecuritycertificationsincluding:CISSP,CISA,CISM,CCSK,MCSE:Security,PCIISA,C|EH,C|CISO,ISO27001LeadAuditor,andSecurity+Certifications

11

HEALTHCARE E-COMMERCE GOVERNMENT FINANCIALSERVICES

Mitigatetheriskinvolvedwithhybriddeployments

1. Securitymanagementbycloudsecurityexperts2. Securitybestpracticesdeployedtoreducerisk3. Securityintegrationwiththesystemlifecycle4. Innovationwithinthecloudsecurityarena

12

Questions

JoelFriedmanChiefTechnologyandSecurityOfficer,Datapipe