Till Kahlbrock, Soenke Ruempler | 09.09.2019 Community Day 2019 Sponsors
https://securityboulevard.com/2019/07/hacker-group-magecart-attacking-misconfigured-s3-buckets/
Soenke Till Ruempler Kahlbrock
Low Maintenance Best Practices Secure & Compliant Minimized Future Proof Setup Time-To-Market
Teams Billing Compliance / Security Workload Isolation Controls (Blast Radius Reduction, Hard/Soft limits)
AWS Landing Zone AWS Control Tower Custom Built (LZ) (CT) Solution
Actively maintained and supported by AWS
Dedicated Core Accounts - Master Account - Audit / Security Account - Log Archive Account
Guardrails - Preventive & Detective - Under the hood - Preventive = Service Control Policies - Detective = Config Rules
Account Factory - Service Catalog for account management - Organize accounts by OU - Parameterise account creation (Name, E-Mail, VPC settings) - ACL for account creation
Control Tower Landing Zone Provided as AWS No Yes managed service CloudFormation Setup One-click template Yes, with manual work Yes, one-click Updates
Control Tower Landing Zone Use existing AWS Org Yes No Import existing AWS Yes No Accounts
Control Tower Landing Zone Custom baseline Yes No
Control Tower Landing Zone Custom Guardrails Yes No
Control Tower Landing Zone Customize Account Yes Very limited Factory
Control Tower Landing Zone Unified Dashboard No Yes
Control Tower Landing Zone GuardDuty Yes No pre-configured
Control Tower Landing Zone AWS Config Rules Only Custom Built Yes Aggregation
Control Tower Landing Zone Currently us- 🔦 -1, Supported regions All us-east-2, us-west-1, eu-west-1 Configure Regions To Yes No Use
Control Tower Landing Zone SSO Concept No AWS SSO built-in
So actually we want AWS Landing Zone, but as Control Tower.
Control Tower if greenfield , restrictions are understood , and no customizations necessary otherwise AWS Landing Zone
AWS and superluminar are doing free virtual AMA sessions for startups When : 17th + 18th September Register : hi@superluminar.io
- Advantages of AWS Multi-Account Architecture - Tested for you: multi-account setups with AWS Landing Zone - AWS re:Inforce 2019: Implementing Your Landing Zone (FND210)
- How much does it cost? - How does AWS SSO work? Can you show a demo? - Can you show a demo of Control Tower or Landing Zone? - Can you show a demo of the Account Factory?
Recommend
More recommend