Till Kahlbrock, Soenke Ruempler | 09.09.2019
Till Kahlbrock, Soenke Ruempler | 09.09.2019 Community Day 2019 - - PowerPoint PPT Presentation
Till Kahlbrock, Soenke Ruempler | 09.09.2019 Community Day 2019 - - PowerPoint PPT Presentation
Till Kahlbrock, Soenke Ruempler | 09.09.2019 Community Day 2019 Sponsors https://securityboulevard.com/2019/07/hacker-group-magecart-attacking-misconfigured-s3-buckets/ Soenke Till Ruempler Kahlbrock Low Maintenance Best Practices Secure
SLIDE 1
SLIDE 2
https://securityboulevard.com/2019/07/hacker-group-magecart-attacking-misconfigured-s3-buckets/
SLIDE 3
Till Kahlbrock Soenke Ruempler
SLIDE 4
Minimized Time-To-Market Low Maintenance Future Proof Setup Best Practices Secure & Compliant
SLIDE 5
Teams Billing Workload Isolation (Blast Radius Reduction, Hard/Soft limits) Compliance / Security Controls
SLIDE 6
AWS Landing Zone (LZ) AWS Control Tower (CT) Custom Built Solution
SLIDE 7
Actively maintained and supported by AWS
SLIDE 8
Dedicated Core Accounts
- Master Account
- Audit / Security Account
- Log Archive Account
SLIDE 9
Guardrails
- Preventive & Detective
- Under the hood
- Preventive = Service Control Policies
- Detective = Config Rules
SLIDE 10
Account Factory
- Service Catalog for account management
- Organize accounts by OU
- Parameterise account creation (Name, E-Mail, VPC
settings)
- ACL for account creation
SLIDE 11
Landing Zone Control Tower
Provided as AWS managed service
No Yes
Setup
CloudFormation template One-click
Updates
Yes, with manual work Yes, one-click
SLIDE 12
Landing Zone Control Tower
Use existing AWS Org
Yes No
Import existing AWS Accounts
Yes No
SLIDE 13
Landing Zone Control Tower Custom baseline Yes No
SLIDE 14
Landing Zone Control Tower Custom Guardrails Yes No
SLIDE 15
Landing Zone Control Tower Customize Account Factory Yes Very limited
SLIDE 16
Landing Zone Control Tower Unified Dashboard No Yes
SLIDE 17
Landing Zone Control Tower GuardDuty pre-configured Yes No
SLIDE 18
Landing Zone Control Tower AWS Config Rules Aggregation Only Custom Built Yes
SLIDE 19
Landing Zone Control Tower Supported regions All Currently us-🔦-1, us-east-2, us-west-1, eu-west-1 Configure Regions To Use Yes No
SLIDE 20
Landing Zone Control Tower SSO Concept No AWS SSO built-in
SLIDE 21
So actually we want AWS Landing Zone, but as Control Tower.
SLIDE 22
SLIDE 23
Control Tower if greenfield, restrictions are understood, and no customizations necessary
- therwise AWS Landing Zone
SLIDE 24
AWS and superluminar are doing free virtual AMA sessions for startups When: 17th + 18th September Register: hi@superluminar.io
SLIDE 25
- Advantages of AWS Multi-Account Architecture
- Tested for you: multi-account setups with AWS
Landing Zone
- AWS re:Inforce 2019: Implementing Your Landing
Zone (FND210)
SLIDE 26
- How much does it cost?
- How does AWS SSO work? Can you show a demo?
- Can you show a demo of Control Tower or Landing
Zone?
- Can you show a demo of the Account Factory?