cloud insecurity summit - information security training · aws migration scaling security paved...

24
Cloud INsecurity Summit Case Study Will Bengtson @__muscles

Upload: others

Post on 22-May-2020

10 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Cloud INsecuritySummit

Case StudyWill Bengtson @__muscles

Page 2: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

● whoami● whoarewe● AWS migration● Scaling Security

○ Paved Road○ Delivery○ Tooling○ Self-service○ Partnerships○ Monitoring

● Questions?

Contents.

Page 3: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

whoami

Page 4: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Welcome to

In the heart of Silicon ValleySource of major technological innovation!Not a Tech Company!

Page 5: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

● 100M+ Subscribers● 1000s devices● World wide reach● 3 global regions● Global CDN● ⅓ of US Bandwidth at Peak● 100M+ hours of TV● Netflix Originals

Page 6: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

What makes Netflix cool and different? Our culture

- Freedom and Responsibility- Context not Control- Loosely Coupled yet Highly Aligned

See also: Netflix Culture Document on jobs.netflix.com

Page 7: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

100(0)’s of developers

1000’s of applications

100k+ instances

1000+ changes a day

Page 8: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

AWS Migration

Page 9: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Scaling

Page 10: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Security, the enabler!● Not a gatekeeper● Partner with developers● Abstract difficulties● Find faults before they are deployed● Find faults ASAP when they are deployed● Automate Everything

Page 11: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami
Page 12: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Paved Road

Page 13: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Delivery

Page 14: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Tooling

Page 15: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami
Page 16: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

● IAM○ Start with a generic template○ Take back what isn’t used

● Allow applications to do things themselves○ Attach Volume○ Attach ENI

● SSO as a service● mTLS as a service

Page 17: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Self-service

Page 18: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami
Page 19: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami
Page 20: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami
Page 21: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Partnerships

Page 22: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Monitoring

Page 23: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Thank you!

Page 24: Cloud INsecurity Summit - Information Security Training · AWS migration Scaling Security Paved Road Delivery Tooling Self-service Partnerships Monitoring Questions? Contents. whoami

Questions?

@__muscles