SlideShare a Scribd company logo
1 of 31
S U M M I T
SYDNEY
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
AWS PROTECTED: Why this
matters for Australia
Herman Coomans
Senior Manager, Solutions Architecture,
Amazon Web Services
Source: Wikimedia commons
Parliament House, Canberra
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
“Innovation and cloud help form
the basis on which we will
make the Australian
government more secure.
Innovation is good. Cloud is
good – because it helps us
move off from legacy
systems. Our biggest risk is
indeed legacy systems.”
Voice of our customers
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Quick acronym glossary
ACSC Australian Cyber Security Centre
https://www.acsc.gov.au/
ASD Australian Signals Directorate
https://asd.gov.au/
ISM Australian Government Information Security Manual
IRAP Information Security Registered Assessors Program
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
AWS services assessed at PROTECTED
42 services across a broad range of categories
Standard services, standard pricing
Leverage familiar and established AWS Sydney region
Access to 3 availability zones
Consumer guide and reference architecture immediately available
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Why is it important?
• to government
• to private enterprise
• to developers and partners
• to citizens
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Voice of our customers
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Let us do the heavy lifting
acsc.gov.au/infosec/ism
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Database subnetPrivate subnet
Lambda subnet
App subnet
Reference Architecture
VPC
Sydney Region
Auto Scaling
Users
Office
Amazon CloudWatch
AWS Direct Connect Amazon RDS
AWS WAF
AWS Lambda
(NLB ALB Sync)
Security group
AWS Lambda
(WAF updates)
Security group
Application Load
Balancer
Agent
MFA token
Network Load
Balancer
Amazon VPC
PrivateLink for
cross-VPC or
cross-agency
access
VPN Gateway
Security group
Role
Instances
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
What about DR?
AWS Region
Availability Zone
Physical Sites
Availability Zone
Physical Sites
Availability Zone
Physical Sites
ap-southeast-2a ap-southeast-2b
ap-southeast-2c
Sydney Region
ap-southeast-2
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
PROTECTED
Why is it all uppercase?
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Classification
www.protectivesecurity.gov.au
Sensitive
information
Security classified information
UNOFFICIAL OFFICIAL
OFFICIAL:
Sensitive
PROTECTED SECRET TOP SECRET
Compromise
of information
confidentiality
would be
expected to
cause →
No business
impact
1 Low business
impact
2 Low to
medium
business
impact
3 High
business
impact
4 Extreme
business
impact
5 Catastrophic
business
impact
Not applicable.
This
information
does not form
part of official
duty.
Not applicable.
This is the
majority of
routine
information
created or
processed by
the public
sector.
Limited
damage to an
individual,
organisation or
government
generally if
compromised.
Damage to the
national
interest,
organisations
or individuals.
Serious
damage to the
national
interest,
organisations
or individuals.
Exceptionally
grave damage
to the national
interest,
organisations
or individuals.
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Markings
Sensitive
information
Security classified information
OFFICIAL
OFFICIAL:
Sensitive
PROTECTED SECRET TOP SECRET
1 Low business
impact
2 Low to medium
business impact
3 High business
impact
4 Extreme business
impact
5 Catastrophic
business impact
Identify information with
text-based markings used
unless impractical for
operational reasons
Marking not
required.
Text marking
required:
OFFICIAL:
Sensitive
Text marking
required:
PROTECTED
Text marking
required:
SECRET
Text marking
required:
TOP SECRET
If text-based markings
cannot be used, use
colour-based markings
Marking not
required.
Marking not
required.
Blue colour marking
required (if text
marking cannot be
used).
Salmon (pink) colour
marking required (if
text marking cannot
be used).
Red colour marking
required (if text
marking cannot be
used).
If text or colour based
markings cannot be used,
document the entity
Marking not
required.
Marking not
required.
Marking required. Marking required. Marking required.
www.protectivesecurity.gov.au
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
What’s the difference?
Is there a checkbox? How do I order PROTECTED services?
… there is no difference!
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
PROTECTED Scope
Analytics
Amazon Elastic MapReduce (Amazon EMR)
Amazon Kinesis Data Streams
Amazon Kinesis Data Firehose
Desktop
Amazon WorkSpaces
Amazon WorkDocs
Storage
Amazon S3
Amazon S3 Transfer Acceleration
Amazon EBS
Amazon Glacier
Database
Amazon DynamoDB
Amazon Redshift
Amazon RDS
• MySQL
• PostgreSQL
• SQL Server
• Oracle
• MariaDB
• Aurora
Amazon ElastiCache
Management
Amazon CloudWatch
Amazon CloudWatch Logs
AWS CloudFormation
AWS CloudTrail
AWS Config
AWS Systems Manager
Mobile
Amazon API Gateway
Compute
Amazon EC2
Amazon Elastic Container Service
(Amazon ECS)
Amazon EC2 Auto Scaling
Amazon ELB
AWS Lambda
AWS Lambda@Edge
Networking & Content Delivery
Amazon Virtual Private Cloud (Amazon VPC)
AWS Direct Connect
Amazon CloudFront
Security, Identity and Compliance
Amazon Identity and Access Management (IAM)
AWS Directory Services
Amazon Cognito
Amazon Inspector
AWS Key Management Service
AWS CloudHSM
AWS WAF
Amazon GuardDuty
Application Integration
Amazon Simple Workflow Service
AWS Step Functions
Amazon Simple Notification Service
Amazon Simple Queue Service
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
PROTECTED Scope
Analytics
Amazon Elastic MapReduce (Amazon EMR)
Amazon Kinesis Data Streams
Amazon Kinesis Data Firehose
Desktop
Amazon WorkSpaces
Amazon WorkDocs
Storage
Amazon S3
Amazon S3 Transfer Acceleration
Amazon EBS
Amazon Glacier
Database
Amazon DynamoDB
Amazon Redshift
Amazon RDS
• MySQL
• PostgreSQL
• SQL Server
• Oracle
• MariaDB
• Aurora
Amazon ElastiCache
Management
Amazon CloudWatch
Amazon CloudWatch Logs
AWS CloudFormation
AWS CloudTrail
AWS Config
AWS Systems Manager
Mobile
Amazon API Gateway
Compute
Amazon EC2
Amazon Elastic Container Service
(Amazon ECS)
Amazon EC2 Auto Scaling
Amazon ELB
AWS Lambda
AWS Lambda@Edge
Networking & Content Delivery
Amazon Virtual Private Cloud (Amazon VPC)
AWS Direct Connect
Amazon CloudFront
Security, Identity and Compliance
Amazon Identity and Access Management (IAM)
AWS Directory Services
Amazon Cognito
Amazon Inspector
AWS Key Management Service
AWS CloudHSM
AWS WAF
Amazon GuardDuty
Application Integration
Amazon Simple Workflow Service
AWS Step Functions
Amazon Simple Notification Service
Amazon Simple Queue Service
Security, Identity and Compliance
Amazon Identity and Access
Management (IAM)
AWS Directory Services
Amazon Cognito
Amazon Inspector
AWS Key Management Service
AWS CloudHSM
AWS WAF
Amazon GuardDuty
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
PROTECTED Scope
Analytics
Amazon Elastic MapReduce (Amazon EMR)
Amazon Kinesis Data Streams
Amazon Kinesis Data Firehose
Desktop
Amazon WorkSpaces
Amazon WorkDocs
Storage
Amazon S3
Amazon S3 Transfer Acceleration
Amazon EBS
Amazon Glacier
Database
Amazon DynamoDB
Amazon Redshift
Amazon RDS
• MySQL
• PostgreSQL
• SQL Server
• Oracle
• MariaDB
• Aurora
Amazon ElastiCache
Management
Amazon CloudWatch
Amazon CloudWatch Logs
AWS CloudFormation
AWS CloudTrail
AWS Config
AWS Systems Manager
Mobile
Amazon API Gateway
Compute
Amazon EC2
Amazon Elastic Container Service
(Amazon ECS)
Amazon EC2 Auto Scaling
Amazon ELB
AWS Lambda
AWS Lambda@Edge
Networking & Content Delivery
Amazon Virtual Private Cloud (Amazon VPC)
AWS Direct Connect
Amazon CloudFront
Security, Identity and Compliance
Amazon Identity and Access Management (IAM)
AWS Directory Services
Amazon Cognito
Amazon Inspector
AWS Key Management Service
AWS CloudHSM
AWS WAF
Amazon GuardDuty
Application Integration
Amazon Simple Workflow Service
AWS Step Functions
Amazon Simple Notification Service
Amazon Simple Queue Service
Storage
Amazon S3
Amazon S3 Transfer Acceleration
Amazon EBS
Amazon Glacier
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
PROTECTED Scope
Analytics
Amazon Elastic MapReduce (Amazon EMR)
Amazon Kinesis Data Streams
Amazon Kinesis Data Firehose
Desktop
Amazon WorkSpaces
Amazon WorkDocs
Storage
Amazon S3
Amazon S3 Transfer Acceleration
Amazon EBS
Amazon Glacier
Database
Amazon DynamoDB
Amazon Redshift
Amazon RDS
• MySQL
• PostgreSQL
• SQL Server
• Oracle
• MariaDB
• Aurora
Amazon ElastiCache
Management
Amazon CloudWatch
Amazon CloudWatch Logs
AWS CloudFormation
AWS CloudTrail
AWS Config
AWS Systems Manager
Mobile
Amazon API Gateway
Compute
Amazon EC2
Amazon Elastic Container Service
(Amazon ECS)
Amazon EC2 Auto Scaling
Amazon ELB
AWS Lambda
AWS Lambda@Edge
Networking & Content Delivery
Amazon Virtual Private Cloud (Amazon VPC)
AWS Direct Connect
Amazon CloudFront
Security, Identity and Compliance
Amazon Identity and Access Management (IAM)
AWS Directory Services
Amazon Cognito
Amazon Inspector
AWS Key Management Service
AWS CloudHSM
AWS WAF
Amazon GuardDuty
Application Integration
Amazon Simple Workflow Service
AWS Step Functions
Amazon Simple Notification Service
Amazon Simple Queue Service
Database
Amazon DynamoDB
Amazon Redshift
Amazon RDS
• MySQL
• PostgreSQL
• SQL Server
• Oracle
• MariaDB
• Aurora
Amazon ElastiCache
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
PROTECTED Scope
Analytics
Amazon Elastic MapReduce (Amazon EMR)
Amazon Kinesis Data Streams
Amazon Kinesis Data Firehose
Desktop
Amazon WorkSpaces
Amazon WorkDocs
Storage
Amazon S3
Amazon S3 Transfer Acceleration
Amazon EBS
Amazon Glacier
Database
Amazon DynamoDB
Amazon Redshift
Amazon RDS
• MySQL
• PostgreSQL
• SQL Server
• Oracle
• MariaDB
• Aurora
Amazon ElastiCache
Management
Amazon CloudWatch
Amazon CloudWatch Logs
AWS CloudFormation
AWS CloudTrail
AWS Config
AWS Systems Manager
Mobile
Amazon API Gateway
Compute
Amazon EC2
Amazon Elastic Container Service
(Amazon ECS)
Amazon EC2 Auto Scaling
Amazon ELB
AWS Lambda
AWS Lambda@Edge
Networking & Content Delivery
Amazon Virtual Private Cloud (Amazon VPC)
AWS Direct Connect
Amazon CloudFront
Security, Identity and Compliance
Amazon Identity and Access Management (IAM)
AWS Directory Services
Amazon Cognito
Amazon Inspector
AWS Key Management Service
AWS CloudHSM
AWS WAF
Amazon GuardDuty
Application Integration
Amazon Simple Workflow Service
AWS Step Functions
Amazon Simple Notification Service
Amazon Simple Queue Service
Compute
Amazon EC2
Amazon Elastic Container Service
Amazon EC2 Auto Scaling
Amazon ELB
AWS Lambda
AWS Lambda@Edge
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
PROTECTED Scope
Analytics
Amazon Elastic MapReduce (Amazon EMR)
Amazon Kinesis Data Streams
Amazon Kinesis Data Firehose
Desktop
Amazon WorkSpaces
Amazon WorkDocs
Storage
Amazon S3
Amazon S3 Transfer Acceleration
Amazon EBS
Amazon Glacier
Database
Amazon DynamoDB
Amazon Redshift
Amazon RDS
• MySQL
• PostgreSQL
• SQL Server
• Oracle
• MariaDB
• Aurora
Amazon ElastiCache
Management
Amazon CloudWatch
Amazon CloudWatch Logs
AWS CloudFormation
AWS CloudTrail
AWS Config
AWS Systems Manager
Mobile
Amazon API Gateway
Compute
Amazon EC2
Amazon Elastic Container Service
(Amazon ECS)
Amazon EC2 Auto Scaling
Amazon ELB
AWS Lambda
AWS Lambda@Edge
Networking & Content Delivery
Amazon Virtual Private Cloud (Amazon VPC)
AWS Direct Connect
Amazon CloudFront
Security, Identity and Compliance
Amazon Identity and Access Management (IAM)
AWS Directory Services
Amazon Cognito
Amazon Inspector
AWS Key Management Service
AWS CloudHSM
AWS WAF
Amazon GuardDuty
Application Integration
Amazon Simple Workflow Service
AWS Step Functions
Amazon Simple Notification Service
Amazon Simple Queue Service
Networking & Content Delivery
Amazon Virtual Private Cloud (VPC)
AWS Direct Connect
Amazon CloudFront
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
PROTECTED Scope
Analytics
Amazon Elastic MapReduce (Amazon EMR)
Amazon Kinesis Data Streams
Amazon Kinesis Data Firehose
Desktop
Amazon WorkSpaces
Amazon WorkDocs
Storage
Amazon S3
Amazon S3 Transfer Acceleration
Amazon EBS
Amazon Glacier
Database
Amazon DynamoDB
Amazon Redshift
Amazon RDS
• MySQL
• PostgreSQL
• SQL Server
• Oracle
• MariaDB
• Aurora
Amazon ElastiCache
Management
Amazon CloudWatch
Amazon CloudWatch Logs
AWS CloudFormation
AWS CloudTrail
AWS Config
AWS Systems Manager
Mobile
Amazon API Gateway
Compute
Amazon EC2
Amazon Elastic Container Service
(Amazon ECS)
Amazon EC2 Auto Scaling
Amazon ELB
AWS Lambda
AWS Lambda@Edge
Networking & Content Delivery
Amazon Virtual Private Cloud (Amazon VPC)
AWS Direct Connect
Amazon CloudFront
Security, Identity and Compliance
Amazon Identity and Access Management (IAM)
AWS Directory Services
Amazon Cognito
Amazon Inspector
AWS Key Management Service
AWS CloudHSM
AWS WAF
Amazon GuardDuty
Application Integration
Amazon Simple Workflow Service
AWS Step Functions
Amazon Simple Notification Service
Amazon Simple Queue Service
Desktop
Amazon WorkSpaces
Amazon WorkDocs
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
PROTECTED Scope
Analytics
Amazon Elastic MapReduce (Amazon EMR)
Amazon Kinesis Data Streams
Amazon Kinesis Data Firehose
Desktop
Amazon WorkSpaces
Amazon WorkDocs
Storage
Amazon S3
Amazon S3 Transfer Acceleration
Amazon EBS
Amazon Glacier
Database
Amazon DynamoDB
Amazon Redshift
Amazon RDS
• MySQL
• PostgreSQL
• SQL Server
• Oracle
• MariaDB
• Aurora
Amazon ElastiCache
Management
Amazon CloudWatch
Amazon CloudWatch Logs
AWS CloudFormation
AWS CloudTrail
AWS Config
AWS Systems Manager
Mobile
Amazon API Gateway
Compute
Amazon EC2
Amazon Elastic Container Service
(Amazon ECS)
Amazon EC2 Auto Scaling
Amazon ELB
AWS Lambda
AWS Lambda@Edge
Networking & Content Delivery
Amazon Virtual Private Cloud (Amazon VPC)
AWS Direct Connect
Amazon CloudFront
Security, Identity and Compliance
Amazon Identity and Access Management (IAM)
AWS Directory Services
Amazon Cognito
Amazon Inspector
AWS Key Management Service
AWS CloudHSM
AWS WAF
Amazon GuardDuty
Application Integration
Amazon Simple Workflow Service
AWS Step Functions
Amazon Simple Notification Service
Amazon Simple Queue Service
Management
Amazon CloudWatch
Amazon CloudWatch Logs
AWS CloudFormation
AWS CloudTrail
AWS Config
AWS Systems Manager
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
AWS shared responsibility model
Security IN
the Cloud
Managed by
customers
Security OF
the Cloud
Managed by
AWS
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
ISM and IRAP
Extensive and highly detailed standard for Information Security
Rigorous audit standard is part and parcel of ISM
For more info see
https://acsc.gov.au/infosec/ism
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Additional services in reference architecture
Trusted
Advisor
AWS
Organisations
AWS
Shield
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
March 2019 ISM
Welcome re-name of Unclassified DLM (Dissemination Limiting Marker)
acsc.gov.au/infosec/ism
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Additional certification guidance
All PROTECTED certified services can be used at UNCLASSIFIED DLM
UNCLASSIFIED DLM certified services can be leveraged in
PROTECTED solutions
Specific global UNCLASSIFIED DLM certified services can leverage
AWS Regions outside of Australia, subject to ACSC Guidance.
(Please refer to the ACSC Certification Report and Consumer Guide
for more details.)
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Accessing AWS compliance reports
https://aws.amazon.com/compliance/ https://aws.amazon.com/artifact/
© 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Further reading…
Take a picture of this slide, and visit the URLs…
https://aws.amazon.com/compliance/
https://aws.amazon.com/security/
https://aws.amazon.com/guardduty/
https://aws.amazon.com/artifact/
Thank you!
S U M M I T © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Herman Coomans

More Related Content

What's hot

AWS雲端自動化合規檢核與資安警訊通報管理
AWS雲端自動化合規檢核與資安警訊通報管理AWS雲端自動化合規檢核與資安警訊通報管理
AWS雲端自動化合規檢核與資安警訊通報管理
Amazon Web Services
 

What's hot (20)

Serverless Observability Tech Talk
Serverless Observability Tech TalkServerless Observability Tech Talk
Serverless Observability Tech Talk
 
Education : Digital transformation & AWS Foundations
Education : Digital transformation & AWS FoundationsEducation : Digital transformation & AWS Foundations
Education : Digital transformation & AWS Foundations
 
AWSome Day MODULE 1 - AWS Foundations
AWSome Day MODULE 1 - AWS FoundationsAWSome Day MODULE 1 - AWS Foundations
AWSome Day MODULE 1 - AWS Foundations
 
AWS雲端自動化合規檢核與資安警訊通報管理
AWS雲端自動化合規檢核與資安警訊通報管理AWS雲端自動化合規檢核與資安警訊通報管理
AWS雲端自動化合規檢核與資安警訊通報管理
 
Developing Modern Applications in the Cloud
Developing Modern Applications in the CloudDeveloping Modern Applications in the Cloud
Developing Modern Applications in the Cloud
 
AWS Security Deep Dive
AWS Security Deep DiveAWS Security Deep Dive
AWS Security Deep Dive
 
Performing real-time ETL into data lakes - ADB202 - Santa Clara AWS Summit.pdf
Performing real-time ETL into data lakes - ADB202 - Santa Clara AWS Summit.pdfPerforming real-time ETL into data lakes - ADB202 - Santa Clara AWS Summit.pdf
Performing real-time ETL into data lakes - ADB202 - Santa Clara AWS Summit.pdf
 
AWS Greengrass & Amazon FreeRTOS: Connectivity & Security at the Edge (IOT356...
AWS Greengrass & Amazon FreeRTOS: Connectivity & Security at the Edge (IOT356...AWS Greengrass & Amazon FreeRTOS: Connectivity & Security at the Edge (IOT356...
AWS Greengrass & Amazon FreeRTOS: Connectivity & Security at the Edge (IOT356...
 
Transforming your Business Ops Team for Cloud - AWS Summit Sydney 2018
Transforming your Business Ops Team for Cloud - AWS Summit Sydney 2018Transforming your Business Ops Team for Cloud - AWS Summit Sydney 2018
Transforming your Business Ops Team for Cloud - AWS Summit Sydney 2018
 
Infrastructure, security, and operations as code - DEM05-S - Mexico City AWS ...
Infrastructure, security, and operations as code - DEM05-S - Mexico City AWS ...Infrastructure, security, and operations as code - DEM05-S - Mexico City AWS ...
Infrastructure, security, and operations as code - DEM05-S - Mexico City AWS ...
 
Building IoT Applications for a Smart Home, ft. Vestel (IOT306-R1) - AWS re:I...
Building IoT Applications for a Smart Home, ft. Vestel (IOT306-R1) - AWS re:I...Building IoT Applications for a Smart Home, ft. Vestel (IOT306-R1) - AWS re:I...
Building IoT Applications for a Smart Home, ft. Vestel (IOT306-R1) - AWS re:I...
 
Governance for the Cloud Age - DEM12-R - AWS re:Inforce 2019
 Governance for the Cloud Age - DEM12-R - AWS re:Inforce 2019  Governance for the Cloud Age - DEM12-R - AWS re:Inforce 2019
Governance for the Cloud Age - DEM12-R - AWS re:Inforce 2019
 
Securing the edge with AWS IoT services - FND330 - AWS re:Inforce 2019
Securing the edge with AWS IoT services - FND330 - AWS re:Inforce 2019 Securing the edge with AWS IoT services - FND330 - AWS re:Inforce 2019
Securing the edge with AWS IoT services - FND330 - AWS re:Inforce 2019
 
Twelve-factor serverless applications - MAD302 - Santa Clara AWS Summit
Twelve-factor serverless applications - MAD302 - Santa Clara AWS SummitTwelve-factor serverless applications - MAD302 - Santa Clara AWS Summit
Twelve-factor serverless applications - MAD302 - Santa Clara AWS Summit
 
‘Smart Place’ Essentials: IoT Networks and Platforms
‘Smart Place’ Essentials: IoT Networks and Platforms‘Smart Place’ Essentials: IoT Networks and Platforms
‘Smart Place’ Essentials: IoT Networks and Platforms
 
Public Cloud Security Blueprint
Public Cloud Security BlueprintPublic Cloud Security Blueprint
Public Cloud Security Blueprint
 
Leadership session - Governance, risk, and compliance - GRC326-L - AWS re:Inf...
Leadership session - Governance, risk, and compliance - GRC326-L - AWS re:Inf...Leadership session - Governance, risk, and compliance - GRC326-L - AWS re:Inf...
Leadership session - Governance, risk, and compliance - GRC326-L - AWS re:Inf...
 
Hybrid Cloud on AWS
Hybrid Cloud on AWSHybrid Cloud on AWS
Hybrid Cloud on AWS
 
Kubernetes on AWS 實作工作坊
Kubernetes on AWS 實作工作坊Kubernetes on AWS 實作工作坊
Kubernetes on AWS 實作工作坊
 
Giving credit where credit’s due - myFICO’s cloud transformation - SVC204 - S...
Giving credit where credit’s due - myFICO’s cloud transformation - SVC204 - S...Giving credit where credit’s due - myFICO’s cloud transformation - SVC204 - S...
Giving credit where credit’s due - myFICO’s cloud transformation - SVC204 - S...
 

Similar to AWS PROTECTED: Why This Matters for Australia - AWS Summit Sydney

awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
himanipatel524244
 

Similar to AWS PROTECTED: Why This Matters for Australia - AWS Summit Sydney (20)

AWS PROTECTED Certification - Lunch & Learn
  AWS PROTECTED Certification - Lunch & Learn  AWS PROTECTED Certification - Lunch & Learn
AWS PROTECTED Certification - Lunch & Learn
 
Migrating Business Critical Applications to AWS
Migrating Business Critical Applications to AWSMigrating Business Critical Applications to AWS
Migrating Business Critical Applications to AWS
 
Detecting and mitigating threats with AWS - SEC301 - Chicago AWS Summit
Detecting and mitigating threats with AWS - SEC301 - Chicago AWS SummitDetecting and mitigating threats with AWS - SEC301 - Chicago AWS Summit
Detecting and mitigating threats with AWS - SEC301 - Chicago AWS Summit
 
AWS Technical Essentials Day
AWS Technical Essentials DayAWS Technical Essentials Day
AWS Technical Essentials Day
 
AWS Technical Essentials Day
AWS Technical Essentials DayAWS Technical Essentials Day
AWS Technical Essentials Day
 
Deploying critical Microsoft workloads on AWS at Capital One - SDD337 - AWS r...
Deploying critical Microsoft workloads on AWS at Capital One - SDD337 - AWS r...Deploying critical Microsoft workloads on AWS at Capital One - SDD337 - AWS r...
Deploying critical Microsoft workloads on AWS at Capital One - SDD337 - AWS r...
 
AWSome Day Nairobi 2019
AWSome Day Nairobi 2019AWSome Day Nairobi 2019
AWSome Day Nairobi 2019
 
Threat detection and mitigation at AWS
Threat detection and mitigation at AWSThreat detection and mitigation at AWS
Threat detection and mitigation at AWS
 
Humans and Data Don't Mix- Best Practices to Secure Your Cloud
Humans and Data Don't Mix- Best Practices to Secure Your CloudHumans and Data Don't Mix- Best Practices to Secure Your Cloud
Humans and Data Don't Mix- Best Practices to Secure Your Cloud
 
Keeping Humans Away From Data
Keeping Humans Away From DataKeeping Humans Away From Data
Keeping Humans Away From Data
 
AWS Security Week: Humans & Data Don’t Mix - Best Practices to Secure Your Cloud
AWS Security Week: Humans & Data Don’t Mix - Best Practices to Secure Your CloudAWS Security Week: Humans & Data Don’t Mix - Best Practices to Secure Your Cloud
AWS Security Week: Humans & Data Don’t Mix - Best Practices to Secure Your Cloud
 
Threat detection and mitigation at AWS - SEC201 - New York AWS Summit
Threat detection and mitigation at AWS - SEC201 - New York AWS SummitThreat detection and mitigation at AWS - SEC201 - New York AWS Summit
Threat detection and mitigation at AWS - SEC201 - New York AWS Summit
 
AWS Foundational and Platform Services - Module 1 Parts 2 & 3 - AWSome Day 2017
AWS Foundational and Platform Services - Module 1 Parts 2 & 3 - AWSome Day 2017AWS Foundational and Platform Services - Module 1 Parts 2 & 3 - AWSome Day 2017
AWS Foundational and Platform Services - Module 1 Parts 2 & 3 - AWSome Day 2017
 
AWSome Day Nashville 2018_Training
AWSome Day Nashville 2018_Training AWSome Day Nashville 2018_Training
AWSome Day Nashville 2018_Training
 
AWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in aws
AWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in awsAWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in aws
AWS Technical Day Riyadh Nov 2019 - Scaling threat detection and response in aws
 
AWSome Day Bethesda - February 2019
AWSome Day Bethesda - February 2019AWSome Day Bethesda - February 2019
AWSome Day Bethesda - February 2019
 
Enterprise Cloud Adoption
Enterprise Cloud AdoptionEnterprise Cloud Adoption
Enterprise Cloud Adoption
 
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
awsomedaymodules14gettingstartedwithaws161013161135convertedpptx__2022_01_10_...
 
The AWS Shared Responsibility Model in Practice
The AWS Shared Responsibility Model in PracticeThe AWS Shared Responsibility Model in Practice
The AWS Shared Responsibility Model in Practice
 
Security & Compliance in the Cloud
Security & Compliance in the CloudSecurity & Compliance in the Cloud
Security & Compliance in the Cloud
 

More from Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

More from Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

AWS PROTECTED: Why This Matters for Australia - AWS Summit Sydney

  • 1. S U M M I T SYDNEY
  • 2. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T AWS PROTECTED: Why this matters for Australia Herman Coomans Senior Manager, Solutions Architecture, Amazon Web Services
  • 4. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T “Innovation and cloud help form the basis on which we will make the Australian government more secure. Innovation is good. Cloud is good – because it helps us move off from legacy systems. Our biggest risk is indeed legacy systems.” Voice of our customers
  • 5. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Quick acronym glossary ACSC Australian Cyber Security Centre https://www.acsc.gov.au/ ASD Australian Signals Directorate https://asd.gov.au/ ISM Australian Government Information Security Manual IRAP Information Security Registered Assessors Program
  • 6. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T AWS services assessed at PROTECTED 42 services across a broad range of categories Standard services, standard pricing Leverage familiar and established AWS Sydney region Access to 3 availability zones Consumer guide and reference architecture immediately available
  • 7. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Why is it important? • to government • to private enterprise • to developers and partners • to citizens
  • 8. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Voice of our customers
  • 9. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Let us do the heavy lifting acsc.gov.au/infosec/ism
  • 10. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Database subnetPrivate subnet Lambda subnet App subnet Reference Architecture VPC Sydney Region Auto Scaling Users Office Amazon CloudWatch AWS Direct Connect Amazon RDS AWS WAF AWS Lambda (NLB ALB Sync) Security group AWS Lambda (WAF updates) Security group Application Load Balancer Agent MFA token Network Load Balancer Amazon VPC PrivateLink for cross-VPC or cross-agency access VPN Gateway Security group Role Instances
  • 11. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T What about DR? AWS Region Availability Zone Physical Sites Availability Zone Physical Sites Availability Zone Physical Sites ap-southeast-2a ap-southeast-2b ap-southeast-2c Sydney Region ap-southeast-2
  • 12. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T PROTECTED Why is it all uppercase?
  • 13. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Classification www.protectivesecurity.gov.au Sensitive information Security classified information UNOFFICIAL OFFICIAL OFFICIAL: Sensitive PROTECTED SECRET TOP SECRET Compromise of information confidentiality would be expected to cause → No business impact 1 Low business impact 2 Low to medium business impact 3 High business impact 4 Extreme business impact 5 Catastrophic business impact Not applicable. This information does not form part of official duty. Not applicable. This is the majority of routine information created or processed by the public sector. Limited damage to an individual, organisation or government generally if compromised. Damage to the national interest, organisations or individuals. Serious damage to the national interest, organisations or individuals. Exceptionally grave damage to the national interest, organisations or individuals.
  • 14. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Markings Sensitive information Security classified information OFFICIAL OFFICIAL: Sensitive PROTECTED SECRET TOP SECRET 1 Low business impact 2 Low to medium business impact 3 High business impact 4 Extreme business impact 5 Catastrophic business impact Identify information with text-based markings used unless impractical for operational reasons Marking not required. Text marking required: OFFICIAL: Sensitive Text marking required: PROTECTED Text marking required: SECRET Text marking required: TOP SECRET If text-based markings cannot be used, use colour-based markings Marking not required. Marking not required. Blue colour marking required (if text marking cannot be used). Salmon (pink) colour marking required (if text marking cannot be used). Red colour marking required (if text marking cannot be used). If text or colour based markings cannot be used, document the entity Marking not required. Marking not required. Marking required. Marking required. Marking required. www.protectivesecurity.gov.au
  • 15. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T What’s the difference? Is there a checkbox? How do I order PROTECTED services? … there is no difference!
  • 16. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T PROTECTED Scope Analytics Amazon Elastic MapReduce (Amazon EMR) Amazon Kinesis Data Streams Amazon Kinesis Data Firehose Desktop Amazon WorkSpaces Amazon WorkDocs Storage Amazon S3 Amazon S3 Transfer Acceleration Amazon EBS Amazon Glacier Database Amazon DynamoDB Amazon Redshift Amazon RDS • MySQL • PostgreSQL • SQL Server • Oracle • MariaDB • Aurora Amazon ElastiCache Management Amazon CloudWatch Amazon CloudWatch Logs AWS CloudFormation AWS CloudTrail AWS Config AWS Systems Manager Mobile Amazon API Gateway Compute Amazon EC2 Amazon Elastic Container Service (Amazon ECS) Amazon EC2 Auto Scaling Amazon ELB AWS Lambda AWS Lambda@Edge Networking & Content Delivery Amazon Virtual Private Cloud (Amazon VPC) AWS Direct Connect Amazon CloudFront Security, Identity and Compliance Amazon Identity and Access Management (IAM) AWS Directory Services Amazon Cognito Amazon Inspector AWS Key Management Service AWS CloudHSM AWS WAF Amazon GuardDuty Application Integration Amazon Simple Workflow Service AWS Step Functions Amazon Simple Notification Service Amazon Simple Queue Service
  • 17. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T PROTECTED Scope Analytics Amazon Elastic MapReduce (Amazon EMR) Amazon Kinesis Data Streams Amazon Kinesis Data Firehose Desktop Amazon WorkSpaces Amazon WorkDocs Storage Amazon S3 Amazon S3 Transfer Acceleration Amazon EBS Amazon Glacier Database Amazon DynamoDB Amazon Redshift Amazon RDS • MySQL • PostgreSQL • SQL Server • Oracle • MariaDB • Aurora Amazon ElastiCache Management Amazon CloudWatch Amazon CloudWatch Logs AWS CloudFormation AWS CloudTrail AWS Config AWS Systems Manager Mobile Amazon API Gateway Compute Amazon EC2 Amazon Elastic Container Service (Amazon ECS) Amazon EC2 Auto Scaling Amazon ELB AWS Lambda AWS Lambda@Edge Networking & Content Delivery Amazon Virtual Private Cloud (Amazon VPC) AWS Direct Connect Amazon CloudFront Security, Identity and Compliance Amazon Identity and Access Management (IAM) AWS Directory Services Amazon Cognito Amazon Inspector AWS Key Management Service AWS CloudHSM AWS WAF Amazon GuardDuty Application Integration Amazon Simple Workflow Service AWS Step Functions Amazon Simple Notification Service Amazon Simple Queue Service Security, Identity and Compliance Amazon Identity and Access Management (IAM) AWS Directory Services Amazon Cognito Amazon Inspector AWS Key Management Service AWS CloudHSM AWS WAF Amazon GuardDuty
  • 18. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T PROTECTED Scope Analytics Amazon Elastic MapReduce (Amazon EMR) Amazon Kinesis Data Streams Amazon Kinesis Data Firehose Desktop Amazon WorkSpaces Amazon WorkDocs Storage Amazon S3 Amazon S3 Transfer Acceleration Amazon EBS Amazon Glacier Database Amazon DynamoDB Amazon Redshift Amazon RDS • MySQL • PostgreSQL • SQL Server • Oracle • MariaDB • Aurora Amazon ElastiCache Management Amazon CloudWatch Amazon CloudWatch Logs AWS CloudFormation AWS CloudTrail AWS Config AWS Systems Manager Mobile Amazon API Gateway Compute Amazon EC2 Amazon Elastic Container Service (Amazon ECS) Amazon EC2 Auto Scaling Amazon ELB AWS Lambda AWS Lambda@Edge Networking & Content Delivery Amazon Virtual Private Cloud (Amazon VPC) AWS Direct Connect Amazon CloudFront Security, Identity and Compliance Amazon Identity and Access Management (IAM) AWS Directory Services Amazon Cognito Amazon Inspector AWS Key Management Service AWS CloudHSM AWS WAF Amazon GuardDuty Application Integration Amazon Simple Workflow Service AWS Step Functions Amazon Simple Notification Service Amazon Simple Queue Service Storage Amazon S3 Amazon S3 Transfer Acceleration Amazon EBS Amazon Glacier
  • 19. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T PROTECTED Scope Analytics Amazon Elastic MapReduce (Amazon EMR) Amazon Kinesis Data Streams Amazon Kinesis Data Firehose Desktop Amazon WorkSpaces Amazon WorkDocs Storage Amazon S3 Amazon S3 Transfer Acceleration Amazon EBS Amazon Glacier Database Amazon DynamoDB Amazon Redshift Amazon RDS • MySQL • PostgreSQL • SQL Server • Oracle • MariaDB • Aurora Amazon ElastiCache Management Amazon CloudWatch Amazon CloudWatch Logs AWS CloudFormation AWS CloudTrail AWS Config AWS Systems Manager Mobile Amazon API Gateway Compute Amazon EC2 Amazon Elastic Container Service (Amazon ECS) Amazon EC2 Auto Scaling Amazon ELB AWS Lambda AWS Lambda@Edge Networking & Content Delivery Amazon Virtual Private Cloud (Amazon VPC) AWS Direct Connect Amazon CloudFront Security, Identity and Compliance Amazon Identity and Access Management (IAM) AWS Directory Services Amazon Cognito Amazon Inspector AWS Key Management Service AWS CloudHSM AWS WAF Amazon GuardDuty Application Integration Amazon Simple Workflow Service AWS Step Functions Amazon Simple Notification Service Amazon Simple Queue Service Database Amazon DynamoDB Amazon Redshift Amazon RDS • MySQL • PostgreSQL • SQL Server • Oracle • MariaDB • Aurora Amazon ElastiCache
  • 20. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T PROTECTED Scope Analytics Amazon Elastic MapReduce (Amazon EMR) Amazon Kinesis Data Streams Amazon Kinesis Data Firehose Desktop Amazon WorkSpaces Amazon WorkDocs Storage Amazon S3 Amazon S3 Transfer Acceleration Amazon EBS Amazon Glacier Database Amazon DynamoDB Amazon Redshift Amazon RDS • MySQL • PostgreSQL • SQL Server • Oracle • MariaDB • Aurora Amazon ElastiCache Management Amazon CloudWatch Amazon CloudWatch Logs AWS CloudFormation AWS CloudTrail AWS Config AWS Systems Manager Mobile Amazon API Gateway Compute Amazon EC2 Amazon Elastic Container Service (Amazon ECS) Amazon EC2 Auto Scaling Amazon ELB AWS Lambda AWS Lambda@Edge Networking & Content Delivery Amazon Virtual Private Cloud (Amazon VPC) AWS Direct Connect Amazon CloudFront Security, Identity and Compliance Amazon Identity and Access Management (IAM) AWS Directory Services Amazon Cognito Amazon Inspector AWS Key Management Service AWS CloudHSM AWS WAF Amazon GuardDuty Application Integration Amazon Simple Workflow Service AWS Step Functions Amazon Simple Notification Service Amazon Simple Queue Service Compute Amazon EC2 Amazon Elastic Container Service Amazon EC2 Auto Scaling Amazon ELB AWS Lambda AWS Lambda@Edge
  • 21. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T PROTECTED Scope Analytics Amazon Elastic MapReduce (Amazon EMR) Amazon Kinesis Data Streams Amazon Kinesis Data Firehose Desktop Amazon WorkSpaces Amazon WorkDocs Storage Amazon S3 Amazon S3 Transfer Acceleration Amazon EBS Amazon Glacier Database Amazon DynamoDB Amazon Redshift Amazon RDS • MySQL • PostgreSQL • SQL Server • Oracle • MariaDB • Aurora Amazon ElastiCache Management Amazon CloudWatch Amazon CloudWatch Logs AWS CloudFormation AWS CloudTrail AWS Config AWS Systems Manager Mobile Amazon API Gateway Compute Amazon EC2 Amazon Elastic Container Service (Amazon ECS) Amazon EC2 Auto Scaling Amazon ELB AWS Lambda AWS Lambda@Edge Networking & Content Delivery Amazon Virtual Private Cloud (Amazon VPC) AWS Direct Connect Amazon CloudFront Security, Identity and Compliance Amazon Identity and Access Management (IAM) AWS Directory Services Amazon Cognito Amazon Inspector AWS Key Management Service AWS CloudHSM AWS WAF Amazon GuardDuty Application Integration Amazon Simple Workflow Service AWS Step Functions Amazon Simple Notification Service Amazon Simple Queue Service Networking & Content Delivery Amazon Virtual Private Cloud (VPC) AWS Direct Connect Amazon CloudFront
  • 22. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T PROTECTED Scope Analytics Amazon Elastic MapReduce (Amazon EMR) Amazon Kinesis Data Streams Amazon Kinesis Data Firehose Desktop Amazon WorkSpaces Amazon WorkDocs Storage Amazon S3 Amazon S3 Transfer Acceleration Amazon EBS Amazon Glacier Database Amazon DynamoDB Amazon Redshift Amazon RDS • MySQL • PostgreSQL • SQL Server • Oracle • MariaDB • Aurora Amazon ElastiCache Management Amazon CloudWatch Amazon CloudWatch Logs AWS CloudFormation AWS CloudTrail AWS Config AWS Systems Manager Mobile Amazon API Gateway Compute Amazon EC2 Amazon Elastic Container Service (Amazon ECS) Amazon EC2 Auto Scaling Amazon ELB AWS Lambda AWS Lambda@Edge Networking & Content Delivery Amazon Virtual Private Cloud (Amazon VPC) AWS Direct Connect Amazon CloudFront Security, Identity and Compliance Amazon Identity and Access Management (IAM) AWS Directory Services Amazon Cognito Amazon Inspector AWS Key Management Service AWS CloudHSM AWS WAF Amazon GuardDuty Application Integration Amazon Simple Workflow Service AWS Step Functions Amazon Simple Notification Service Amazon Simple Queue Service Desktop Amazon WorkSpaces Amazon WorkDocs
  • 23. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T PROTECTED Scope Analytics Amazon Elastic MapReduce (Amazon EMR) Amazon Kinesis Data Streams Amazon Kinesis Data Firehose Desktop Amazon WorkSpaces Amazon WorkDocs Storage Amazon S3 Amazon S3 Transfer Acceleration Amazon EBS Amazon Glacier Database Amazon DynamoDB Amazon Redshift Amazon RDS • MySQL • PostgreSQL • SQL Server • Oracle • MariaDB • Aurora Amazon ElastiCache Management Amazon CloudWatch Amazon CloudWatch Logs AWS CloudFormation AWS CloudTrail AWS Config AWS Systems Manager Mobile Amazon API Gateway Compute Amazon EC2 Amazon Elastic Container Service (Amazon ECS) Amazon EC2 Auto Scaling Amazon ELB AWS Lambda AWS Lambda@Edge Networking & Content Delivery Amazon Virtual Private Cloud (Amazon VPC) AWS Direct Connect Amazon CloudFront Security, Identity and Compliance Amazon Identity and Access Management (IAM) AWS Directory Services Amazon Cognito Amazon Inspector AWS Key Management Service AWS CloudHSM AWS WAF Amazon GuardDuty Application Integration Amazon Simple Workflow Service AWS Step Functions Amazon Simple Notification Service Amazon Simple Queue Service Management Amazon CloudWatch Amazon CloudWatch Logs AWS CloudFormation AWS CloudTrail AWS Config AWS Systems Manager
  • 24. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T AWS shared responsibility model Security IN the Cloud Managed by customers Security OF the Cloud Managed by AWS
  • 25. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T ISM and IRAP Extensive and highly detailed standard for Information Security Rigorous audit standard is part and parcel of ISM For more info see https://acsc.gov.au/infosec/ism
  • 26. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Additional services in reference architecture Trusted Advisor AWS Organisations AWS Shield
  • 27. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T March 2019 ISM Welcome re-name of Unclassified DLM (Dissemination Limiting Marker) acsc.gov.au/infosec/ism
  • 28. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Additional certification guidance All PROTECTED certified services can be used at UNCLASSIFIED DLM UNCLASSIFIED DLM certified services can be leveraged in PROTECTED solutions Specific global UNCLASSIFIED DLM certified services can leverage AWS Regions outside of Australia, subject to ACSC Guidance. (Please refer to the ACSC Certification Report and Consumer Guide for more details.)
  • 29. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Accessing AWS compliance reports https://aws.amazon.com/compliance/ https://aws.amazon.com/artifact/
  • 30. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T Further reading… Take a picture of this slide, and visit the URLs… https://aws.amazon.com/compliance/ https://aws.amazon.com/security/ https://aws.amazon.com/guardduty/ https://aws.amazon.com/artifact/
  • 31. Thank you! S U M M I T © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved. Herman Coomans