SlideShare ist ein Scribd-Unternehmen logo
1 von 35
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Keith Brooks
Senior Manager, Amazon Web Services
David Cruley
Solutions Architecture Manager, Amazon Web Services
194340
How to Architect and Bring to Market
SaaS on AWS GovCloud (US)
Dave Packer
VP, Product and Alliance Marketing
Public cloud
trends are
accelerating
2
of cloud workloads
will be in public cloud
(35% CAGR from 2015
to 2020)
of cloud workloads
will be Software-as-
a-Service (SaaS)
by 2020
in public
cloud + SaaS
revenue by
2020
68%
74 %
236B$
B Y 2 0 2 0 :
Source: Cisco Global Cloud Index, 2015-2020 *
Workload = a virtual machine or a container
• 10-40% business applications developed in-house
• 30% open source/free software
• 70% COTS software
• ~200+ software product vendors
• Large EA/ELAs for top 50 vendors
• Long list of products not well known or tracked
• Upgrade cascades over 3-5 year cycle
• High potential for rationalization
Enterprise software
portfolio is in transition
S T A R T I N G P O S I T I O N
ON-PREMISE SOFTWARE CATALOG:
Cloud will
increasingly be
the default
option for
software
deployment.
“
“
The Federal Government spends
more than $6 billion on
software…..
—Tony Scott, Former U.S. Federal CIO
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
SOFTWARE PACKAGE
INSTALLATION AMAZON MACHINE IMAGE
SOFTWARE AS A SERVICE
(SAAS)
Traditional software installation on
an Amazon EC2 instance using
Windows Installer (.MSI), Linux-
based (.RPM), and Unix-based
packages.
Public or private software template
that provides the information
required to launch an AWS EC2
instance. Include root volume,
permissions, and block device
mappings.
Software licensing and delivery
model whereby software is
managed and hosted on AWS and
available to customers on a
subscription basis.
How do organizations implement software on AWS?
AWS SOFTWARE DEPLOYMENT OPTIONS
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
SOFTWARE PACKAGE
INSTALLATION AMAZON MACHINE IMAGE
SOFTWARE AS A SERVICE
(SAAS)
Traditional software installation on
an Amazon EC2 instance using
Windows Installer (.MSI), Linux-
based (.RPM) and Unix-based
packages.
Public or private software template
that provides the information
required to launch an AWS EC2
instance. Include root volume,
permissions and block device
mappings.
Software licensing and delivery
model whereby software is
managed and hosted on AWS and
available to customers on a
subscription basis.
How do organizations implement software on AWS?
AWS SOFTWARE DEPLOYMENT OPTIONS
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What are the implications of SaaS for
public sector and highly regulated
organizations?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Hosting SaaS in the AWS GovCloud (US) Region
SAAS TO SUPPORT SENSITIVE AND REGULATED WORKLOADS
Isolated, secure, and
compliant IaaS and
services
Built for sensitive and
regulated data including
Controlled Unclassified
Information (CUI)
Mission and business
critical workload
delivery
Tools and resources to
accelerate time to
compliance
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Hosting SaaS in the AWS GovCloud (US) Region
ACCELERATING TIME TO COMPLIANCE IN THE AWS CLOUD
International Traffic and
Arms Regulation
DOD Security Req’s
Guide IL 2, 4 and 5
Criminal Justice Information
Service Security Policy
Federal Information Processing
Standard Pub
IRS Publication 1075
FedRAMP Moderate
and High
SP 800-53 (rev 4)
SP 800-171
Health Insurance Portability &
Accountability Act
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Key Considerations for SaaS in AWS GovCloud (US)
WHAT SAAS VENDORS NEED TO KNOW
1. CUSTOMERS, POLICIES, AND OPERATIONS MATTER
2. ARCHITECTURE INFLUENCES PRODUCT STRATEGY
3. COMPLIANCE. COMPLIANCE. COMPLIANCE.
4. ASSESS TENANCY, PRICING, AND DISTRIBUTION OPTIONS
5. CONSIDER ADJACENT SEGMENTS AND INDUSTRIES
6. LEVERAGE AWS PARTNER AND COMPETENCY PROGRAMS
7. GET THE MESSAGE OUT; BE EXPLICIT WITH MARKETING
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
So that’s the why… what about the how?
GETTING STARTED TECHNICALLY
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Architecting for Compliance in the
AWS GovCloud (US) Region
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Use AWS GovCloud’s compliant infrastructure and I am done!
Should I worry about compliance in AWS GovCloud?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS Foundation Services
Compute Storage Database Networking
AWS Global
Infrastructure
Regions
Availability
Zones Edge
Locations
Client-side Data
Encryption
Server-side Data
Encryption
Network Traffic
Protection
Platform, Applications, Identity & Access Management
Operating System, Network, & Firewall Configuration
Customer applications & contentCustomers
Customers have
their choice of
security
configurations IN
the Cloud
AWS is
responsible for the
security OF
the Cloud
Security and compliance is a shared responsibility
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
International Traffic and
Arms Regulation
DOD Security Req’s
Guide IL 2, 4 and 5
Criminal Justice Information
Service Security Policy
Federal Information Processing
Standard Pub
IRS Publication 1075
FedRAMP Moderate
and High
SP 800-53 (rev 4)
SP 800-171
OTHERS….?
What are your actual compliance requirements?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Architectural Considerations
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
What’s your starting point…?
On premise deployment Another AWS region
OR
Migration to GovCloud Architecture Portability Compliance Foundation
Migrating data, servers or entire
application stacks?
Lift and shift?
Optimizing on cloud-native
services?
Can existing compliance audits
be leveraged?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Assess AWS service availability and compliance status
Service availability in AWS GovCloud AWS service compliance posture
Service availability varies by AWS region
Refer to AWS Region Table for availability details
… and the AWS GovCloud (US) User Guide
Some compliance is region based (e.g., ITAR)
Others are service by service (e.g. FedRAMP, SRG)
Refer to AWS Services in Scope for details
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
GovCloud is an isolated region – cross region functionality disabled
VPN is viable for cross region access.
For apps with sensitive data -- Is direct internet access allowed?
Be aware of encryption requirements for data leaving of the region.
ITAR: Ensure no restricted data is leaving the region (see the GovCloud Users Guide).
FedRAMP and SRG: Carefully document the security controls
Ensure access to GovCloud is clearly defined (who, when, where, and how).
VPN
Be cognizant of system boundaries and data egress
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Corporate Network?
Internet?
End user access path…
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Do either of these acronyms mean anything to you?
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Trusted Internet Connection (TIC)
OMB Mandate M-08-05
Initiative to optimize and standardize the security of individual external network
connections currently in use by federal agencies, including connections to the
Internet. Reduces and consolidates external connections and provides enhanced
monitoring and situational awareness of external network connections.
DOD Cloud Access Point (CAP)
Defense Information Systems Agency
A system of network boundary protection and monitoring devices, otherwise
known as a cybersecurity stack, through which CSP infrastructure will connect to
a DoD Information Network (DODIN) service, the NIPRNet, or the Secret Internet
Protocol Router Network (SIPRNet).
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Customer Network
InternetTIC Provider
Secure Connection
Direct Connect (w/VPN) or
VPN Over the Internet
Secure Connection
Direct Connect (w/VPN) or
VPN Over the Internet
SaaS Infrastructure
TIC and CAP requirements may impact architecture
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
GovCloud Users Guide
https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-us-ug.pdf
AWS service compliance
https://aws.amazon.com/compliance/services-in-scope/
AWS services by region
https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/
NIST 800-53 standardized architecture quick start
https://aws.amazon.com/about-aws/whats-new/2016/01/nist-800-53-standardized-architecture-on-the-
aws-cloud-quick-start-reference-deployment/
Architecture and security recommendations for FedRAMP compliance
https://d0.awsstatic.com/whitepapers/compliance/aws-architecture-and-security-recommendations-for-
fedramp-compliance.pdf
Resources
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Enterprise
Customers
4,000+
Data Under
Management
100PB+
Amazon Storage
Partner
Top 5
“ With Druva we gained data visibility while reducing costs
and complexity, simplifying, and reinforcing our entire data
protection strategy.” Brian Bagwell, Director of IT
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
The Data Center is No Longer the Center of Data
50%
ofdataexistsoutsidethe
corporatefirewallby
2020
Public Cloud – IaaS &
PaaS
Branch
Offices
Office 365, Google, Salesforce,
Box
SaaS
Endpoints
Source: Gartner
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Druva Vision: Data Management as-a-Service
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Druva Cloud Platform: One Platform to Protect it All
inSync
Endpoints & SaaS Applications
Office 365, Google G Suite, Box and Salesforce
Phoenix
Data Centers & Branch Offices
Physical Servers, Databases, VMware,
Hyper-V and NAS
CloudRanger
AWS IaaS/PaaS Services
EC2, RDS, EBS and RedShift
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Why AWS GovCloud (US)?
• Existing government customers and contractors
• Market gap for a GovCloud-hosted data protection
vendor
• Increasing market interest for cloud solution (cloud
first)
• Cloud-native, security-focused, zero-knowledge
design made it a natural fit, or so we thought…
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
GovCloud & FedRAMP ATO
Road to FedRAMP
• Initiated FedRAMP in early 2014 for inSync
• Achieved moderate ATO Nov. 2017 (3.5 years later)
• Sponsored by NCI (National Cancer Institute)
• DoD IL-2 Designation
Lessons Learned
• You don’t know what you don’t know
• AWS was a great partner through the whole process
• Re-architecting was minimal
• Long Poles: Process changes, FIPS, AWS Service ATOs
• Oh, and the documentation & reviews, ………
Next Steps
• Phoenix services FIPS compliance
• Should take much less time once initiated
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Druva FedRAMP Architecture
KMS
Route53 SES
US-EAST-REGION-1
CUSTOMER
SITE
CLOUD
OPS
RDS
CloudWatchCloudTrail
Internet
Private SubnetPublic Subnet Private SubnetPublic Subnet
Private SubnetPublic Subnet
MASTER VPC NODE VPC
MGMT VPC
GovCloud (US)
Configuration Mgmtgovcloud.druva.com Storage Nodes S3 / DynamoDB
Mgmt &
Monitoring
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Port of New Orleans
Streamlines critical data protection
Challenges
• Manually intensive legacy data protection infrastructure
• Widespread end-user productivity issues; high rate of help desk calls
• Complex state and federal-mandated data compliance demands
• Data vulnerability concerns: natural disasters like Hurricane Katrina
Solution
• Druva inSync on endpoints to protect against ransomware, device loss, or
failure; Druva Phoenix to manage backup and disaster recovery for on-premises
and cloud
Hyper-V environments
Benefits with Druva
• Central visibility, security, and controls
• Calls to the IT department have dropped by 60–70%
• Multi-day server restores now only take seconds to complete
• Reduced backup window—from day-long to 30 minutes or less;
built-in security and controls enabling cloud compliance
• One of world’s busiest port systems
• Critical to US national economy
• 30M tons of goods, millions
of passengers
• $500M national impact if the
port went down for 3 days
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
National Cancer Institute
Challenges
• Highly distributed, mobile staff carrying sensitive data
• Data loss concerns
• Embracing Cloud First in a highly regulated environment
• Clinical researchers’ concerns with using cloud for their intellectual property
• Needing to align with FedRAMP for cloud data handling
Solution
• Druva inSync for end user data, which provides data protection for over 8,000
users and aligns to FedRAMP Moderate compliance requirements
Benefits with Druva
• Compliance alignment with FedRAMP across SaaS and infrastructure
• Staff data is protected around the clock, with zero-productivity impact
• Protection against catastrophic data loss
• Centralized accessibility & visibility to data when needed
• Increased user satisfaction around data handling, protection and management needs
• Solution offers availability, durability and scalability offered by AWS
• Founded in 1937, part of the National
Institutes of Health (NIH)
• Focus on cancer research, training,
health info dissemination related to
the causes, prevention & diagnosis of
cancer
• $5B+ in annual funding
© 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank You!

Weitere ähnliche Inhalte

Was ist angesagt?

20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier
20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier
20190220 AWS Black Belt Online Seminar Amazon S3 / GlacierAmazon Web Services Japan
 
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用Amazon Web Services Japan
 
Let's Talk About: Azure Networking
Let's Talk About: Azure NetworkingLet's Talk About: Azure Networking
Let's Talk About: Azure NetworkingPedro Sousa
 
20200331 AWS Black Belt Online Seminar AWS Elemental MediaConvert
20200331 AWS Black Belt Online Seminar AWS Elemental MediaConvert20200331 AWS Black Belt Online Seminar AWS Elemental MediaConvert
20200331 AWS Black Belt Online Seminar AWS Elemental MediaConvertAmazon Web Services Japan
 
20180509 AWS Black Belt Online Seminar Amazon GuardDuty
20180509 AWS Black Belt Online Seminar Amazon GuardDuty20180509 AWS Black Belt Online Seminar Amazon GuardDuty
20180509 AWS Black Belt Online Seminar Amazon GuardDutyAmazon Web Services Japan
 
【第20回セキュリティ共有勉強会】Amazon FSx for Windows File Serverをセキュリティ観点で試してみたお話
【第20回セキュリティ共有勉強会】Amazon FSx for Windows File Serverをセキュリティ観点で試してみたお話【第20回セキュリティ共有勉強会】Amazon FSx for Windows File Serverをセキュリティ観点で試してみたお話
【第20回セキュリティ共有勉強会】Amazon FSx for Windows File Serverをセキュリティ観点で試してみたお話Hibino Hisashi
 
AWS Black Belt Techシリーズ Amazon WorkDocs / Amazon WorkMail
AWS Black Belt Techシリーズ Amazon WorkDocs / Amazon WorkMailAWS Black Belt Techシリーズ Amazon WorkDocs / Amazon WorkMail
AWS Black Belt Techシリーズ Amazon WorkDocs / Amazon WorkMailAmazon Web Services Japan
 
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)Amazon Web Services Japan
 
AWS Black Belt Tech シリーズ 2015 AWS CLI & AWS Tools for Windows Powershell
AWS Black Belt Tech シリーズ 2015 AWS CLI & AWS Tools for Windows PowershellAWS Black Belt Tech シリーズ 2015 AWS CLI & AWS Tools for Windows Powershell
AWS Black Belt Tech シリーズ 2015 AWS CLI & AWS Tools for Windows PowershellAmazon Web Services Japan
 
20200630 AWS Black Belt Online Seminar Amazon Cognito
20200630 AWS Black Belt Online Seminar Amazon Cognito20200630 AWS Black Belt Online Seminar Amazon Cognito
20200630 AWS Black Belt Online Seminar Amazon CognitoAmazon Web Services Japan
 
AWS Black Belt Techシリーズ AWS Directory Service
AWS Black Belt Techシリーズ AWS Directory ServiceAWS Black Belt Techシリーズ AWS Directory Service
AWS Black Belt Techシリーズ AWS Directory ServiceAmazon Web Services Japan
 
詳説!Azure AD 条件付きアクセス - 動作の仕組みを理解する編
詳説!Azure AD 条件付きアクセス - 動作の仕組みを理解する編詳説!Azure AD 条件付きアクセス - 動作の仕組みを理解する編
詳説!Azure AD 条件付きアクセス - 動作の仕組みを理解する編Yusuke Kodama
 
Protecting Your Data with Encryption on AWS
Protecting Your Data with Encryption on AWSProtecting Your Data with Encryption on AWS
Protecting Your Data with Encryption on AWSAmazon Web Services
 
20200826 AWS Black Belt Online Seminar AWS CloudFormation
20200826 AWS Black Belt Online Seminar AWS CloudFormation 20200826 AWS Black Belt Online Seminar AWS CloudFormation
20200826 AWS Black Belt Online Seminar AWS CloudFormation Amazon Web Services Japan
 
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...Amazon Web Services
 
20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...Amazon Web Services Japan
 
Architecture Patterns for Multi-Region Active-Active Applications (ARC209-R2)...
Architecture Patterns for Multi-Region Active-Active Applications (ARC209-R2)...Architecture Patterns for Multi-Region Active-Active Applications (ARC209-R2)...
Architecture Patterns for Multi-Region Active-Active Applications (ARC209-R2)...Amazon Web Services
 

Was ist angesagt? (20)

20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier
20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier
20190220 AWS Black Belt Online Seminar Amazon S3 / Glacier
 
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
202202 AWS Black Belt Online Seminar AWS Managed Rules for AWS WAF の活用
 
Let's Talk About: Azure Networking
Let's Talk About: Azure NetworkingLet's Talk About: Azure Networking
Let's Talk About: Azure Networking
 
20200331 AWS Black Belt Online Seminar AWS Elemental MediaConvert
20200331 AWS Black Belt Online Seminar AWS Elemental MediaConvert20200331 AWS Black Belt Online Seminar AWS Elemental MediaConvert
20200331 AWS Black Belt Online Seminar AWS Elemental MediaConvert
 
20180509 AWS Black Belt Online Seminar Amazon GuardDuty
20180509 AWS Black Belt Online Seminar Amazon GuardDuty20180509 AWS Black Belt Online Seminar Amazon GuardDuty
20180509 AWS Black Belt Online Seminar Amazon GuardDuty
 
【第20回セキュリティ共有勉強会】Amazon FSx for Windows File Serverをセキュリティ観点で試してみたお話
【第20回セキュリティ共有勉強会】Amazon FSx for Windows File Serverをセキュリティ観点で試してみたお話【第20回セキュリティ共有勉強会】Amazon FSx for Windows File Serverをセキュリティ観点で試してみたお話
【第20回セキュリティ共有勉強会】Amazon FSx for Windows File Serverをセキュリティ観点で試してみたお話
 
AWS Black Belt Techシリーズ Amazon WorkDocs / Amazon WorkMail
AWS Black Belt Techシリーズ Amazon WorkDocs / Amazon WorkMailAWS Black Belt Techシリーズ Amazon WorkDocs / Amazon WorkMail
AWS Black Belt Techシリーズ Amazon WorkDocs / Amazon WorkMail
 
はじめよう DynamoDB ハンズオン
はじめよう DynamoDB ハンズオンはじめよう DynamoDB ハンズオン
はじめよう DynamoDB ハンズオン
 
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)
202205 AWS Black Belt Online Seminar Amazon VPC IP Address Manager (IPAM)
 
AWS Black Belt Tech シリーズ 2015 AWS CLI & AWS Tools for Windows Powershell
AWS Black Belt Tech シリーズ 2015 AWS CLI & AWS Tools for Windows PowershellAWS Black Belt Tech シリーズ 2015 AWS CLI & AWS Tools for Windows Powershell
AWS Black Belt Tech シリーズ 2015 AWS CLI & AWS Tools for Windows Powershell
 
20200630 AWS Black Belt Online Seminar Amazon Cognito
20200630 AWS Black Belt Online Seminar Amazon Cognito20200630 AWS Black Belt Online Seminar Amazon Cognito
20200630 AWS Black Belt Online Seminar Amazon Cognito
 
AWS Black Belt Techシリーズ AWS Directory Service
AWS Black Belt Techシリーズ AWS Directory ServiceAWS Black Belt Techシリーズ AWS Directory Service
AWS Black Belt Techシリーズ AWS Directory Service
 
詳説!Azure AD 条件付きアクセス - 動作の仕組みを理解する編
詳説!Azure AD 条件付きアクセス - 動作の仕組みを理解する編詳説!Azure AD 条件付きアクセス - 動作の仕組みを理解する編
詳説!Azure AD 条件付きアクセス - 動作の仕組みを理解する編
 
Protecting Your Data with Encryption on AWS
Protecting Your Data with Encryption on AWSProtecting Your Data with Encryption on AWS
Protecting Your Data with Encryption on AWS
 
20200826 AWS Black Belt Online Seminar AWS CloudFormation
20200826 AWS Black Belt Online Seminar AWS CloudFormation 20200826 AWS Black Belt Online Seminar AWS CloudFormation
20200826 AWS Black Belt Online Seminar AWS CloudFormation
 
AWS Cloud Security Fundamentals
AWS Cloud Security FundamentalsAWS Cloud Security Fundamentals
AWS Cloud Security Fundamentals
 
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...
Amazon GuardDuty: Intelligent Threat Detection and Continuous Monitoring to P...
 
20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
20190129 AWS Black Belt Online Seminar AWS Identity and Access Management (AW...
 
Architecture Patterns for Multi-Region Active-Active Applications (ARC209-R2)...
Architecture Patterns for Multi-Region Active-Active Applications (ARC209-R2)...Architecture Patterns for Multi-Region Active-Active Applications (ARC209-R2)...
Architecture Patterns for Multi-Region Active-Active Applications (ARC209-R2)...
 
AWSではじめるDNSSEC
AWSではじめるDNSSECAWSではじめるDNSSEC
AWSではじめるDNSSEC
 

Ähnlich wie How to Architect and Bring to Market SaaS on AWS GovCloud (US)

Leadership Session: Networking (NET209-L) - AWS re:Invent 2018
Leadership Session: Networking (NET209-L) - AWS re:Invent 2018Leadership Session: Networking (NET209-L) - AWS re:Invent 2018
Leadership Session: Networking (NET209-L) - AWS re:Invent 2018Amazon Web Services
 
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...Amazon Web Services
 
Costruire Architetture Ibride con AWS
Costruire Architetture Ibride con AWSCostruire Architetture Ibride con AWS
Costruire Architetture Ibride con AWSAmazon Web Services
 
Track 5 Session 4_ intel 透過AWS Outposts就地佈署 on-premises 雲端環境.pptx
Track 5 Session 4_ intel 透過AWS Outposts就地佈署 on-premises 雲端環境.pptxTrack 5 Session 4_ intel 透過AWS Outposts就地佈署 on-premises 雲端環境.pptx
Track 5 Session 4_ intel 透過AWS Outposts就地佈署 on-premises 雲端環境.pptxAmazon Web Services
 
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...Amazon Web Services
 
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...Amazon Web Services
 
Elevate_your_security_with_the_cloud
Elevate_your_security_with_the_cloudElevate_your_security_with_the_cloud
Elevate_your_security_with_the_cloudAmazon Web Services
 
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...Amazon Web Services
 
Enabling Your Organization’s Amazon Redshift Adoption – Going from Zero to He...
Enabling Your Organization’s Amazon Redshift Adoption – Going from Zero to He...Enabling Your Organization’s Amazon Redshift Adoption – Going from Zero to He...
Enabling Your Organization’s Amazon Redshift Adoption – Going from Zero to He...Amazon Web Services
 
深入淺出 AWS 混合式雲端架構
深入淺出 AWS 混合式雲端架構 深入淺出 AWS 混合式雲端架構
深入淺出 AWS 混合式雲端架構 Amazon Web Services
 
Strengthen Your Organizations Security and Privacy.pdf
Strengthen Your Organizations Security and Privacy.pdfStrengthen Your Organizations Security and Privacy.pdf
Strengthen Your Organizations Security and Privacy.pdfAmazon Web Services
 
AWS Fundamentals for DoD, Immersion Day Huntsville 2019
AWS Fundamentals for DoD, Immersion Day Huntsville 2019AWS Fundamentals for DoD, Immersion Day Huntsville 2019
AWS Fundamentals for DoD, Immersion Day Huntsville 2019Amazon Web Services
 
Virtual AWSome Day October 2018 - Amazon Web Services
Virtual AWSome Day October 2018 - Amazon Web ServicesVirtual AWSome Day October 2018 - Amazon Web Services
Virtual AWSome Day October 2018 - Amazon Web ServicesAmazon Web Services
 
Introduction to Hybrid Cloud on AWS
Introduction to Hybrid Cloud on AWSIntroduction to Hybrid Cloud on AWS
Introduction to Hybrid Cloud on AWSTom Laszewski
 
Introduction to Hybrid Cloud on AWS - AWS Online Tech Talks
Introduction to Hybrid Cloud on AWS - AWS Online Tech TalksIntroduction to Hybrid Cloud on AWS - AWS Online Tech Talks
Introduction to Hybrid Cloud on AWS - AWS Online Tech TalksAmazon Web Services
 
Secure Your Customers' Data From Day One
Secure Your Customers' Data From Day OneSecure Your Customers' Data From Day One
Secure Your Customers' Data From Day OneAmazon Web Services
 

Ähnlich wie How to Architect and Bring to Market SaaS on AWS GovCloud (US) (20)

AWS Outposts Update
AWS Outposts UpdateAWS Outposts Update
AWS Outposts Update
 
Leadership Session: Networking (NET209-L) - AWS re:Invent 2018
Leadership Session: Networking (NET209-L) - AWS re:Invent 2018Leadership Session: Networking (NET209-L) - AWS re:Invent 2018
Leadership Session: Networking (NET209-L) - AWS re:Invent 2018
 
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
Moving 400 Engineers to AWS: Our Journey to Secure Adoption (SEC306-S) - AWS ...
 
Costruire Architetture Ibride con AWS
Costruire Architetture Ibride con AWSCostruire Architetture Ibride con AWS
Costruire Architetture Ibride con AWS
 
Track 5 Session 4_ intel 透過AWS Outposts就地佈署 on-premises 雲端環境.pptx
Track 5 Session 4_ intel 透過AWS Outposts就地佈署 on-premises 雲端環境.pptxTrack 5 Session 4_ intel 透過AWS Outposts就地佈署 on-premises 雲端環境.pptx
Track 5 Session 4_ intel 透過AWS Outposts就地佈署 on-premises 雲端環境.pptx
 
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...
[REPEAT 1] Safeguard the Integrity of Your Code for Fast and Secure Deploymen...
 
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...
Safeguard the Integrity of Your Code for Fast and Secure Deployments (DEV349-...
 
Elevate_your_security_with_the_cloud
Elevate_your_security_with_the_cloudElevate_your_security_with_the_cloud
Elevate_your_security_with_the_cloud
 
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...
[NEW LAUNCH!] Introducing AWS App Mesh – service mesh on AWS (CON367) - AWS r...
 
AWS_Security_Essentials
AWS_Security_EssentialsAWS_Security_Essentials
AWS_Security_Essentials
 
Enabling Your Organization’s Amazon Redshift Adoption – Going from Zero to He...
Enabling Your Organization’s Amazon Redshift Adoption – Going from Zero to He...Enabling Your Organization’s Amazon Redshift Adoption – Going from Zero to He...
Enabling Your Organization’s Amazon Redshift Adoption – Going from Zero to He...
 
Hybrid Cloud on AWS
Hybrid Cloud on AWSHybrid Cloud on AWS
Hybrid Cloud on AWS
 
深入淺出 AWS 混合式雲端架構
深入淺出 AWS 混合式雲端架構 深入淺出 AWS 混合式雲端架構
深入淺出 AWS 混合式雲端架構
 
Strengthen Your Organizations Security and Privacy.pdf
Strengthen Your Organizations Security and Privacy.pdfStrengthen Your Organizations Security and Privacy.pdf
Strengthen Your Organizations Security and Privacy.pdf
 
AWS Fundamentals for DoD, Immersion Day Huntsville 2019
AWS Fundamentals for DoD, Immersion Day Huntsville 2019AWS Fundamentals for DoD, Immersion Day Huntsville 2019
AWS Fundamentals for DoD, Immersion Day Huntsville 2019
 
Virtual AWSome Day October 2018 - Amazon Web Services
Virtual AWSome Day October 2018 - Amazon Web ServicesVirtual AWSome Day October 2018 - Amazon Web Services
Virtual AWSome Day October 2018 - Amazon Web Services
 
Introduction to Hybrid Cloud on AWS
Introduction to Hybrid Cloud on AWSIntroduction to Hybrid Cloud on AWS
Introduction to Hybrid Cloud on AWS
 
Introduction to Hybrid Cloud on AWS - AWS Online Tech Talks
Introduction to Hybrid Cloud on AWS - AWS Online Tech TalksIntroduction to Hybrid Cloud on AWS - AWS Online Tech Talks
Introduction to Hybrid Cloud on AWS - AWS Online Tech Talks
 
AWS - Security & Compliance
AWS - Security & ComplianceAWS - Security & Compliance
AWS - Security & Compliance
 
Secure Your Customers' Data From Day One
Secure Your Customers' Data From Day OneSecure Your Customers' Data From Day One
Secure Your Customers' Data From Day One
 

Mehr von Amazon Web Services

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Amazon Web Services
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Amazon Web Services
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateAmazon Web Services
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSAmazon Web Services
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Amazon Web Services
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Amazon Web Services
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...Amazon Web Services
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsAmazon Web Services
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareAmazon Web Services
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSAmazon Web Services
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAmazon Web Services
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareAmazon Web Services
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWSAmazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckAmazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without serversAmazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...Amazon Web Services
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceAmazon Web Services
 

Mehr von Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

How to Architect and Bring to Market SaaS on AWS GovCloud (US)

  • 1. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Keith Brooks Senior Manager, Amazon Web Services David Cruley Solutions Architecture Manager, Amazon Web Services 194340 How to Architect and Bring to Market SaaS on AWS GovCloud (US) Dave Packer VP, Product and Alliance Marketing
  • 2. Public cloud trends are accelerating 2 of cloud workloads will be in public cloud (35% CAGR from 2015 to 2020) of cloud workloads will be Software-as- a-Service (SaaS) by 2020 in public cloud + SaaS revenue by 2020 68% 74 % 236B$ B Y 2 0 2 0 : Source: Cisco Global Cloud Index, 2015-2020 * Workload = a virtual machine or a container
  • 3. • 10-40% business applications developed in-house • 30% open source/free software • 70% COTS software • ~200+ software product vendors • Large EA/ELAs for top 50 vendors • Long list of products not well known or tracked • Upgrade cascades over 3-5 year cycle • High potential for rationalization Enterprise software portfolio is in transition S T A R T I N G P O S I T I O N ON-PREMISE SOFTWARE CATALOG: Cloud will increasingly be the default option for software deployment. “ “ The Federal Government spends more than $6 billion on software….. —Tony Scott, Former U.S. Federal CIO
  • 4. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. SOFTWARE PACKAGE INSTALLATION AMAZON MACHINE IMAGE SOFTWARE AS A SERVICE (SAAS) Traditional software installation on an Amazon EC2 instance using Windows Installer (.MSI), Linux- based (.RPM), and Unix-based packages. Public or private software template that provides the information required to launch an AWS EC2 instance. Include root volume, permissions, and block device mappings. Software licensing and delivery model whereby software is managed and hosted on AWS and available to customers on a subscription basis. How do organizations implement software on AWS? AWS SOFTWARE DEPLOYMENT OPTIONS
  • 5. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. SOFTWARE PACKAGE INSTALLATION AMAZON MACHINE IMAGE SOFTWARE AS A SERVICE (SAAS) Traditional software installation on an Amazon EC2 instance using Windows Installer (.MSI), Linux- based (.RPM) and Unix-based packages. Public or private software template that provides the information required to launch an AWS EC2 instance. Include root volume, permissions and block device mappings. Software licensing and delivery model whereby software is managed and hosted on AWS and available to customers on a subscription basis. How do organizations implement software on AWS? AWS SOFTWARE DEPLOYMENT OPTIONS
  • 6. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What are the implications of SaaS for public sector and highly regulated organizations?
  • 7.
  • 8. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Hosting SaaS in the AWS GovCloud (US) Region SAAS TO SUPPORT SENSITIVE AND REGULATED WORKLOADS Isolated, secure, and compliant IaaS and services Built for sensitive and regulated data including Controlled Unclassified Information (CUI) Mission and business critical workload delivery Tools and resources to accelerate time to compliance
  • 9. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Hosting SaaS in the AWS GovCloud (US) Region ACCELERATING TIME TO COMPLIANCE IN THE AWS CLOUD International Traffic and Arms Regulation DOD Security Req’s Guide IL 2, 4 and 5 Criminal Justice Information Service Security Policy Federal Information Processing Standard Pub IRS Publication 1075 FedRAMP Moderate and High SP 800-53 (rev 4) SP 800-171 Health Insurance Portability & Accountability Act
  • 10. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Key Considerations for SaaS in AWS GovCloud (US) WHAT SAAS VENDORS NEED TO KNOW 1. CUSTOMERS, POLICIES, AND OPERATIONS MATTER 2. ARCHITECTURE INFLUENCES PRODUCT STRATEGY 3. COMPLIANCE. COMPLIANCE. COMPLIANCE. 4. ASSESS TENANCY, PRICING, AND DISTRIBUTION OPTIONS 5. CONSIDER ADJACENT SEGMENTS AND INDUSTRIES 6. LEVERAGE AWS PARTNER AND COMPETENCY PROGRAMS 7. GET THE MESSAGE OUT; BE EXPLICIT WITH MARKETING
  • 11. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. So that’s the why… what about the how? GETTING STARTED TECHNICALLY
  • 12. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Architecting for Compliance in the AWS GovCloud (US) Region
  • 13. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Use AWS GovCloud’s compliant infrastructure and I am done! Should I worry about compliance in AWS GovCloud?
  • 14. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS Foundation Services Compute Storage Database Networking AWS Global Infrastructure Regions Availability Zones Edge Locations Client-side Data Encryption Server-side Data Encryption Network Traffic Protection Platform, Applications, Identity & Access Management Operating System, Network, & Firewall Configuration Customer applications & contentCustomers Customers have their choice of security configurations IN the Cloud AWS is responsible for the security OF the Cloud Security and compliance is a shared responsibility
  • 15. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. International Traffic and Arms Regulation DOD Security Req’s Guide IL 2, 4 and 5 Criminal Justice Information Service Security Policy Federal Information Processing Standard Pub IRS Publication 1075 FedRAMP Moderate and High SP 800-53 (rev 4) SP 800-171 OTHERS….? What are your actual compliance requirements?
  • 16. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Architectural Considerations
  • 17. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. What’s your starting point…? On premise deployment Another AWS region OR Migration to GovCloud Architecture Portability Compliance Foundation Migrating data, servers or entire application stacks? Lift and shift? Optimizing on cloud-native services? Can existing compliance audits be leveraged?
  • 18. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Assess AWS service availability and compliance status Service availability in AWS GovCloud AWS service compliance posture Service availability varies by AWS region Refer to AWS Region Table for availability details … and the AWS GovCloud (US) User Guide Some compliance is region based (e.g., ITAR) Others are service by service (e.g. FedRAMP, SRG) Refer to AWS Services in Scope for details
  • 19. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. GovCloud is an isolated region – cross region functionality disabled VPN is viable for cross region access. For apps with sensitive data -- Is direct internet access allowed? Be aware of encryption requirements for data leaving of the region. ITAR: Ensure no restricted data is leaving the region (see the GovCloud Users Guide). FedRAMP and SRG: Carefully document the security controls Ensure access to GovCloud is clearly defined (who, when, where, and how). VPN Be cognizant of system boundaries and data egress
  • 20. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Corporate Network? Internet? End user access path…
  • 21. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Do either of these acronyms mean anything to you?
  • 22. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Trusted Internet Connection (TIC) OMB Mandate M-08-05 Initiative to optimize and standardize the security of individual external network connections currently in use by federal agencies, including connections to the Internet. Reduces and consolidates external connections and provides enhanced monitoring and situational awareness of external network connections. DOD Cloud Access Point (CAP) Defense Information Systems Agency A system of network boundary protection and monitoring devices, otherwise known as a cybersecurity stack, through which CSP infrastructure will connect to a DoD Information Network (DODIN) service, the NIPRNet, or the Secret Internet Protocol Router Network (SIPRNet).
  • 23. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Customer Network InternetTIC Provider Secure Connection Direct Connect (w/VPN) or VPN Over the Internet Secure Connection Direct Connect (w/VPN) or VPN Over the Internet SaaS Infrastructure TIC and CAP requirements may impact architecture
  • 24. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. GovCloud Users Guide https://docs.aws.amazon.com/govcloud-us/latest/UserGuide/govcloud-us-ug.pdf AWS service compliance https://aws.amazon.com/compliance/services-in-scope/ AWS services by region https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/ NIST 800-53 standardized architecture quick start https://aws.amazon.com/about-aws/whats-new/2016/01/nist-800-53-standardized-architecture-on-the- aws-cloud-quick-start-reference-deployment/ Architecture and security recommendations for FedRAMP compliance https://d0.awsstatic.com/whitepapers/compliance/aws-architecture-and-security-recommendations-for- fedramp-compliance.pdf Resources
  • 25. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
  • 26. Enterprise Customers 4,000+ Data Under Management 100PB+ Amazon Storage Partner Top 5 “ With Druva we gained data visibility while reducing costs and complexity, simplifying, and reinforcing our entire data protection strategy.” Brian Bagwell, Director of IT
  • 27. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. The Data Center is No Longer the Center of Data 50% ofdataexistsoutsidethe corporatefirewallby 2020 Public Cloud – IaaS & PaaS Branch Offices Office 365, Google, Salesforce, Box SaaS Endpoints Source: Gartner
  • 28. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Druva Vision: Data Management as-a-Service
  • 29. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Druva Cloud Platform: One Platform to Protect it All inSync Endpoints & SaaS Applications Office 365, Google G Suite, Box and Salesforce Phoenix Data Centers & Branch Offices Physical Servers, Databases, VMware, Hyper-V and NAS CloudRanger AWS IaaS/PaaS Services EC2, RDS, EBS and RedShift
  • 30. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why AWS GovCloud (US)? • Existing government customers and contractors • Market gap for a GovCloud-hosted data protection vendor • Increasing market interest for cloud solution (cloud first) • Cloud-native, security-focused, zero-knowledge design made it a natural fit, or so we thought…
  • 31. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. GovCloud & FedRAMP ATO Road to FedRAMP • Initiated FedRAMP in early 2014 for inSync • Achieved moderate ATO Nov. 2017 (3.5 years later) • Sponsored by NCI (National Cancer Institute) • DoD IL-2 Designation Lessons Learned • You don’t know what you don’t know • AWS was a great partner through the whole process • Re-architecting was minimal • Long Poles: Process changes, FIPS, AWS Service ATOs • Oh, and the documentation & reviews, ……… Next Steps • Phoenix services FIPS compliance • Should take much less time once initiated
  • 32. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Druva FedRAMP Architecture KMS Route53 SES US-EAST-REGION-1 CUSTOMER SITE CLOUD OPS RDS CloudWatchCloudTrail Internet Private SubnetPublic Subnet Private SubnetPublic Subnet Private SubnetPublic Subnet MASTER VPC NODE VPC MGMT VPC GovCloud (US) Configuration Mgmtgovcloud.druva.com Storage Nodes S3 / DynamoDB Mgmt & Monitoring
  • 33. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Port of New Orleans Streamlines critical data protection Challenges • Manually intensive legacy data protection infrastructure • Widespread end-user productivity issues; high rate of help desk calls • Complex state and federal-mandated data compliance demands • Data vulnerability concerns: natural disasters like Hurricane Katrina Solution • Druva inSync on endpoints to protect against ransomware, device loss, or failure; Druva Phoenix to manage backup and disaster recovery for on-premises and cloud Hyper-V environments Benefits with Druva • Central visibility, security, and controls • Calls to the IT department have dropped by 60–70% • Multi-day server restores now only take seconds to complete • Reduced backup window—from day-long to 30 minutes or less; built-in security and controls enabling cloud compliance • One of world’s busiest port systems • Critical to US national economy • 30M tons of goods, millions of passengers • $500M national impact if the port went down for 3 days
  • 34. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. National Cancer Institute Challenges • Highly distributed, mobile staff carrying sensitive data • Data loss concerns • Embracing Cloud First in a highly regulated environment • Clinical researchers’ concerns with using cloud for their intellectual property • Needing to align with FedRAMP for cloud data handling Solution • Druva inSync for end user data, which provides data protection for over 8,000 users and aligns to FedRAMP Moderate compliance requirements Benefits with Druva • Compliance alignment with FedRAMP across SaaS and infrastructure • Staff data is protected around the clock, with zero-productivity impact • Protection against catastrophic data loss • Centralized accessibility & visibility to data when needed • Increased user satisfaction around data handling, protection and management needs • Solution offers availability, durability and scalability offered by AWS • Founded in 1937, part of the National Institutes of Health (NIH) • Focus on cancer research, training, health info dissemination related to the causes, prevention & diagnosis of cancer • $5B+ in annual funding
  • 35. © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved. Thank You!