AWS Worldwide Public Sector



Similar documents
Getting Started with SAP BI on AWS

Expand Your Infrastructure with the Elastic Cloud. Mark Ryland Chief Solutions Architect Jenn Steele Product Marketing Manager

AWS Security. Security is Job Zero! CJ Moses Deputy Chief Information Security Officer. AWS Gov Cloud Summit II

With Eversync s cloud data tiering, the customer can tier data protection as follows:

Famly ApS: Overview of Security Processes

Securing Amazon It s a Jungle Out There

Is it Time to Look at an Ektron Managed Cloud Strategy? Copyright 2014 Ektron, Inc.

Magento Enterprise Cloud Edition A Platform-as-a-Service for Your Business. Peter Sheldon VP Strategy, Magento Commerce

Amazon Web Services: Risk and Compliance July 2015

10 Considerations for a Cloud Procurement. Anthony Kelly Erick Trombley David DeBrandt Carina Veksler January 2015

SECURITY IS JOB ZERO. Security The Forefront For Any Online Business Bill Murray Director AWS Security Programs

Intermedia s Dedicated Exchange

Amazon Web Services: Risk and Compliance January 2013

Cloud Security. A Sales Guy Talks About DoD s Cautious Journey to the Public Cloud. Sean Curry Sales Executive, Aquilent

319 MANAGED HOSTING TECHNICAL DETAILS

Building Energy Security Framework

Anypoint Platform Cloud Security and Compliance. Whitepaper

Live Guide System Architecture and Security TECHNICAL ARTICLE

Simone Brunozzi, AWS Technology Evangelist, APAC. Fortress in the Cloud

CLOUD COMPUTING WITH AWS An INTRODUCTION. John Hildebrandt Solutions Architect ANZ

Using ArcGIS for Server in the Amazon Cloud

Agenda. - Introduction to Amazon s Cloud - How ArcGIS users adopt Amazon s Cloud - Why ArcGIS users adopt Amazon s Cloud - Examples

Security Essentials & Best Practices

VMware vcloud Air Security TECHNICAL WHITE PAPER

Amazon Web Services: Risk and Compliance July 2012

Amazon Web Services: Risk and Compliance January 2011

How Safe are you in your Cloud?

Securing the Microsoft Cloud Infrastructure. Reto Häni Chief Security Officer Microsoft Western Europe MEET SWISS INFOSEC!

DoD Cloud Computing Security Requirements Guide (SRG) Overview

Run SAP for Savings and Speed in the Cloud Presentation for ASUG, September 28, 2011

5 Critical Considerations for. Enterprise Cloud Backup

Securing Government Clouds Preparing for the Rainy Days

PATCH MANAGER what does it do?

Amazon Web Services Annual ALGIM Conference. Tim Dacombe-Bird Regional Sales Manager Amazon Web Services New Zealand

SOC on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for SOC on AWS

Security Practices, Architecture and Technologies

IIA Conference. September 18, Paige Needling Director, Global Information Security Recall, Inc.

How To Create A Walkme.Com Walkthrus.Com Website And Help With Your Website Or App On A Pc Or Mac Or Ipad (For Pc) Or Mac (For Mac) Or Ipa (For Ipa) Or Pc

Application Security Best Practices. Matt Tavis Principal Solutions Architect

Running Oracle Applications on AWS

What should go to the Cloud and When. What should NOT go to the Cloud and Why

Managing digital audio video court record in the age of HD video and YouTube. technology and privacy. Tony Douglass President, For The Record

Security Authorization Process Guide

Close-Up on Cloud Security Audit

Global Headquarters: 5 Speen Street Framingham, MA USA P F

Compliance in the Age of Cloud

Seeing Though the Clouds

AWS Benefits, Regions & Across. Paul Yung Head of Territory Development HK, Macau & TW pyung@amazon.com

Leveraging Cloud Services for Quicker Implementation and More Secure Automation Solutions

DLT Solutions and Amazon Web Services

Federal Risk and Authorization Management Program (FedRAMP)

Logz.io See the logz that matter

Enterprise Managed Cloud Computing at NASA. Karen Petraska NASA Office of the CIO Computing Services Service Office (CSSO) October 1, 2014

Data, Data, Who Has The Data?

Helping people make better decisions DATA SECURITY POLICY. Kiilakiventie 1, Oulu, Finland tel:

Oracle Cloud Update November 2, Eric Frank Oracle Sales Consultant. Copyright 2014 Oracle and/or its affiliates. All rights reserved.

Pega as a Service. Kim Singletary, Dir. Product Marketing Cloud Matt Yanchyshyn, Sr. Mgr., AWS Solutions Architect

Cloud models and compliance requirements which is right for you?

Esri Managed Cloud Services and FedRAMP

Clever Security Overview

How To Protect Your Cloud From Attack

FISMA Cloud GovDataHosting Service Portfolio

AWS Security & Compliance

RemoteApp Publishing on AWS

A COALFIRE PERSPECTIVE. Moving to the Cloud. NCHELP Spring Convention Panel May 2012

Cloud Security. DLT Solutions LLC June #DLTCloud

Enterprise IT in the Cloud How to accelerate your business and be an IT hero

DISA releases updated DoD Cloud Requirements What are the impacts? James Leach January 2015

ArcGIS Cloud Security Roadmap & Best Practices for Federal Agencies. Michael E. Young

DoD-Compliant Implementations in the AWS Cloud

Appendix C Pricing Index DIR Contract Number DIR-TSO-2724

December 8, Security Authorization of Information Systems in Cloud Computing Environments

Amazon Web Services (AWS) A Secure and Scalable Platform for Global Enterprises. Tim Bixler Sr. Manager, Solutions Architecture

Alfresco Enterprise on AWS: Reference Architecture

Global Headquarters: 5 Speen Street Framingham, MA USA P F

Cloud Security for Federal Agencies

ArcGIS Security Authorization Advancements

OWASP Chapter Meeting June Presented by: Brayton Rider, SecureState Chief Architect

Company Overview. Enterprise Cloud Solutions

Automating Cloud Security Control and Compliance Enforcement for PCI DSS 3.0

The Education Fellowship Finance Centralisation IT Security Strategy

Cloud Security Case Study Amazon Web Services. Ugo Piazzalunga Technical Manager, IT Security

Transcription:

15 Minute Introduction to AWS and Q&A April 2015 Mark Fox Sr. Manager DoD Sales

I love/hate relationship with the term cloud Now the IT norm Commercial Cloud should not be scary nor considered less secure Commercial Cloud enables (competitive advantage- eat your cake ) Agility- from nothing to massive to nothing in minutes, time to capability Increased cyber-security posture and insight Cost Savings- OPEX, pay for only what you use AWS delivers every customer their own private cloud enclave (VPC) within public commercially available infrastructure. AWS has been authorized and is being used by the US Gov t Civilian and DoD (NIPR) Intel Community via Community Cloud Region (TS SCI) A&D via AWS GovCloud ITAR Compliant Region Commercial Cloud leverages Shared Security/Responsibility BLUF

What sets AWS apart? Experience Building and managing cloud since 2006 Service Breadth & Depth 40+ services to support any cloud workload Pace of Innovation History of rapid, customer-driven releases Global Footprint 11 regions, 28 availability zones, 52 edge locations Pricing Philosophy 45 proactive price reductions to date Ecosystem 8,000+ SIs and ISVs; 2,000+ Marketplace products *as of July 31, 2014

Experience with Operational Reliability We are driven to remove any all causes of failure. Our goal is to make our operational performance indistinguishable from perfect. Over a decade building the world s most reliable, secure, scalable, and cost-effective infrastructure for over a million customers. Many of them with millions of their customers leveraging cloud. Service SLAs between 99.9% and 100% availability. Amazon S3 maintains a durability of 99.999999999%. Availability Zones fault line and flood plain isolated, separate ISP s and electric grid isolation to substantially reduce the chance of simultaneous failure. Promote High Availability (HA) model. 24/7 visibility into the real-time operational status of all services around the globe..

Experience with Cloud Security AWS provides the same, familiar approaches to security that companies have been using for decades with increased visibility, control, and auditability. ~1,000 consistent controls. Visibility View your entire infrastructure with a click Insight into your Virtual Private Cloud now and in the past Control You have sole authority on where data is stored Shared responsibility model Auditability 3 rd party validation Inherit/re-use SOC 1 / SOC 2 / SOC 3 SSAE 16 / ISAE 3402 PCI DSS Level 1 DIACAP & FISMA ISO 27001 / 9001 / 13485 ISO/TS 16949 FedRAMP (SM) FISMA HIPAA ITAR MPAA CSA FIPS 140-2 Based on our experience, I believe that we can be even more secure in the AWS cloud than in our own data centers. Tom Soderstrom, CTO, NASA JPL

Shared Security Responsibility AWS & Customers both have security/compliance obligations Applications & Data Logical assessment & accreditation boundaries Authorizations/Accreditations Managed by Customer OS Configuration of Your Virtual Private Cloud (VPC) Compliance in the Cloud Inherited by Customer as part of full stack ATO AWS Controls concrete up to hypervisor Managed by AWS Compliance of the Cloud

Notional Risk Acceptance Unclassified Risk Profile AO Decision Identify Cloud Service Provider (CSP) Offering (s) with DoD Provisional ATO (P-ATO) against mission data security requirements Select CSP after comparing risk profiles Reciprocity: maximize use of existing body of evidence (e.g. scope, testing, results, residual risk) Identify and resolve any additional testing requirements If risk is acceptable: Issue a Mission Owner ATO, explicitly reflecting acceptance of risk and liabilities in DoD P-ATO for system and mission. Mission ATO 22 MAR 2015 -- 1500 DISA SLIDE

AWS Worldwide Footprint

AWS GovCloud Characteristics GovCloud designed to handle CUI including ITAR Community Cloud: access controlled, US Persons for physical and logical access to the AWS infrastructure DoD Provisional Authorization for public and sensitive workloads (Impact Levels 4, 5 require NIPRnet connectivity) Physically Isolated Region (Oregon) 3 Availability Zones Separate Isolated Credential Database Logical Network Isolation all users run in Virtual Private Clouds (VPC) FIPS 140-2 Validated Hardware & Cryptographic Services for VPNs and AWS Service API End Points

Each day AWS adds the equivalent server capacity to power Amazon when it was a global, $7B enterprise (circa 2004)