till kahlbrock soenke ruempler 09 09 2019 community day
play

Till Kahlbrock, Soenke Ruempler | 09.09.2019 Community Day 2019 - PowerPoint PPT Presentation

Till Kahlbrock, Soenke Ruempler | 09.09.2019 Community Day 2019 Sponsors https://securityboulevard.com/2019/07/hacker-group-magecart-attacking-misconfigured-s3-buckets/ Soenke Till Ruempler Kahlbrock Low Maintenance Best Practices Secure


  1. Till Kahlbrock, Soenke Ruempler | 09.09.2019 Community Day 2019 Sponsors

  2. https://securityboulevard.com/2019/07/hacker-group-magecart-attacking-misconfigured-s3-buckets/

  3. Soenke Till Ruempler Kahlbrock

  4. Low Maintenance Best Practices Secure & Compliant Minimized Future Proof Setup Time-To-Market

  5. Teams Billing Compliance / Security Workload Isolation Controls (Blast Radius Reduction, Hard/Soft limits)

  6. AWS Landing Zone AWS Control Tower Custom Built (LZ) (CT) Solution

  7. Actively maintained and supported by AWS

  8. Dedicated Core Accounts - Master Account - Audit / Security Account - Log Archive Account

  9. Guardrails - Preventive & Detective - Under the hood - Preventive = Service Control Policies - Detective = Config Rules

  10. Account Factory - Service Catalog for account management - Organize accounts by OU - Parameterise account creation (Name, E-Mail, VPC settings) - ACL for account creation

  11. Control Tower Landing Zone Provided as AWS No Yes managed service CloudFormation Setup One-click template Yes, with manual work Yes, one-click Updates

  12. Control Tower Landing Zone Use existing AWS Org Yes No Import existing AWS Yes No Accounts

  13. Control Tower Landing Zone Custom baseline Yes No

  14. Control Tower Landing Zone Custom Guardrails Yes No

  15. Control Tower Landing Zone Customize Account Yes Very limited Factory

  16. Control Tower Landing Zone Unified Dashboard No Yes

  17. Control Tower Landing Zone GuardDuty Yes No pre-configured

  18. Control Tower Landing Zone AWS Config Rules Only Custom Built Yes Aggregation

  19. Control Tower Landing Zone Currently us- 🔦 -1, Supported regions All us-east-2, us-west-1, eu-west-1 Configure Regions To Yes No Use

  20. Control Tower Landing Zone SSO Concept No AWS SSO built-in

  21. So actually we want AWS Landing Zone, but as Control Tower.

  22. Control Tower if greenfield , restrictions are understood , and no customizations necessary otherwise AWS Landing Zone

  23. AWS and superluminar are doing free virtual AMA sessions for startups When : 17th + 18th September Register : hi@superluminar.io

  24. - Advantages of AWS Multi-Account Architecture - Tested for you: multi-account setups with AWS Landing Zone - AWS re:Inforce 2019: Implementing Your Landing Zone (FND210)

  25. - How much does it cost? - How does AWS SSO work? Can you show a demo? - Can you show a demo of Control Tower or Landing Zone? - Can you show a demo of the Account Factory?

Recommend


More recommend