SlideShare a Scribd company logo
How to stop dreaming
about security and start
implementing
2019 Kromtech
Agenda
- AWS Security problems
- Options to start with …
- AWS Security tools
- AWS CIS Implementation
- Q&A
Intro & speakers
Aleksandr Maklakov
CIO at ZEO Alliance/Kromtech
14 years in IT
MBA
ISO 27001 Internal Auditor
AWS Certified Solutions Architect - Associate
Nazariy Uniyat
IT Security Engineer at Kromtech
8 years in IT
Data breach security trends in cloud
#1 - publicly accessible buckets
#2 - open ports(especially in databases)
#3 - stolen/leaked credentials (access/secret keys) -
cryprominers
Options to start with ...
- Find consulting company
- Find some tools for audit and compliance check
- Find framework/controls
CIS Amazon Web Services Benchmark
Center for Internet Security (CIS) - nonprofit organization.
Its mission is to "identify, develop, validate, promote, and
sustain best practice solutions for cyber defense and build and
lead communities to enable an environment of trust in
cyberspace"
Recommended for use by many security vendor and PCI DSS
CIS Amazon Web Services Benchmark
© Sift Security Inc
CIS Amazon Web Services Benchmark
Continuous audit vs monitoring
Audit
- Owned by External
Company or Internal
Auditor
- Conduct annually (or
often)
- More formal
Monitoring
- Owned by management
team
- On-going process to
ensure processes are
working as intended
- Easely implement
continuous approach
Services
CloudTrail
AWS Config
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
GuardDuty
How to stop dreaming about security and start implementing
Macie
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
Security Hub
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
Security Hub Data Sources
Enable Them All
How to stop dreaming about security and start implementing
CloudTrail
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
CloudWatch Logs in Trail
How to stop dreaming about security and start implementing
AWS Config
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
Aggregator
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
Guard Duty
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
111111111111
Macie
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
111111111111
How to stop dreaming about security and start implementing
Security Hub
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
How to stop dreaming about security and start implementing
Lessons
- Lambda Logs
- Encryption S3 logs
- SCP policy only for working regions
- Architecture!
SUMMARY
RECAP
- AWS CIS Benchmark as starting point
- AWS Security Services overview (CloudTrail, Macie,
Guard Duty, SecurityHub, etc)
- Best Practices Architecture
- Lessons & Bugs
COST
~ $600/month
~ 200Gb of Logs
~ 17M Events
Links
AWS Security Best Practices
AWS CIS Benchmark
AWS CIS Benchmark Quick Start
AWS CloudTrail
AWS Organizations
Amazon GuardDuty
AWS Security Hub
Next Steps
Incident Management
More services
Inspector WAF Shield
Q&A

More Related Content

What's hot (19)

PDF
Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)
Priyanka Aash
 
PPTX
Defcon23 from zero to secure in 1 minute - nir valtman and moshe ferber
Moshe Ferber
 
DOCX
Cloud keybank privacy and owner authorization
Pvrtechnologies Nellore
 
PDF
Devil's Bargain: Sacrificing Strategic Investments to Fund Today's Problems
scoopnewsgroup
 
DOCX
What is zero trust model of information security?
Ahmed Banafa
 
PDF
How to emrace risk-based Security management in a compliance-driven culture
Shahid Shah
 
PDF
Symantec Webinar | Implementing a Zero Trust Framework to Secure Modern Workf...
Symantec
 
PDF
What is the Future of SIEM?
Elasticsearch
 
PDF
Forrester no more chewy centers- the zero trust model
Cristian Garcia G.
 
PDF
ATP Technology Pillars
Priyanka Aash
 
PDF
Innovating at speed and scale with implicit security
Elasticsearch
 
PDF
Next-generation enterprise Ethereum managed services
Eugene Aseev
 
PPTX
Herding Pets and Cattle: Extending Foundational Controls Into the Cloud
Tripwire
 
PPTX
Zero trust deck 2020
Guido Marchetti
 
PDF
Advantages of privacy by design in IoE
Marc Vael
 
PPTX
Navigating Cybersecurity
Segun Ebenezer Olaniyan
 
PPT
Internet Security - Protecting your critical assets
Andre Jankowitz
 
PDF
Outpost24 webinar - Implications when migrating to a Zero Trust model
Outpost24
 
PPTX
Mastering Next Gen SIEM Use Cases (Part 3)
DNIF
 
Sacon - Fresh Thinking IoT (Arnab Chattopadhayay)
Priyanka Aash
 
Defcon23 from zero to secure in 1 minute - nir valtman and moshe ferber
Moshe Ferber
 
Cloud keybank privacy and owner authorization
Pvrtechnologies Nellore
 
Devil's Bargain: Sacrificing Strategic Investments to Fund Today's Problems
scoopnewsgroup
 
What is zero trust model of information security?
Ahmed Banafa
 
How to emrace risk-based Security management in a compliance-driven culture
Shahid Shah
 
Symantec Webinar | Implementing a Zero Trust Framework to Secure Modern Workf...
Symantec
 
What is the Future of SIEM?
Elasticsearch
 
Forrester no more chewy centers- the zero trust model
Cristian Garcia G.
 
ATP Technology Pillars
Priyanka Aash
 
Innovating at speed and scale with implicit security
Elasticsearch
 
Next-generation enterprise Ethereum managed services
Eugene Aseev
 
Herding Pets and Cattle: Extending Foundational Controls Into the Cloud
Tripwire
 
Zero trust deck 2020
Guido Marchetti
 
Advantages of privacy by design in IoE
Marc Vael
 
Navigating Cybersecurity
Segun Ebenezer Olaniyan
 
Internet Security - Protecting your critical assets
Andre Jankowitz
 
Outpost24 webinar - Implications when migrating to a Zero Trust model
Outpost24
 
Mastering Next Gen SIEM Use Cases (Part 3)
DNIF
 

Similar to How to stop dreaming about security and start implementing (20)

PPTX
Automating AWS security and compliance
John Varghese
 
PPTX
CIS Compliance Automations Eevidence Collection, Security and Compliance Be...
Faiza Mehar
 
PPTX
AWS Spotlight Series - Modernization and Security with AWS
CloudHesive
 
PPTX
Security on AWS
CloudHesive
 
PPTX
Build and Manage a Highly Secure Cloud Environment on AWS and Azure
CloudHesive
 
PPTX
AWS Cloud Security
AWS Riyadh User Group
 
PPTX
Top 10 AWS Security and Compliance best practices
Ahmad Khan
 
PPTX
Security on AWS, 2021 Edition Meetup
CloudHesive
 
PPTX
Security on AWS, 2021 Edition Meetup
CloudHesive
 
PPTX
Blue Chip Tek Connect and Protect Presentation #3
Kimberly Macias
 
PDF
AWS_security_at_scale__From_development_to_production.pdf
kantrajnee88
 
PDF
Security in the cloud
Reham Maher El-Safarini
 
PDF
Securing Your Customers Data From Day One
Amazon Web Services LATAM
 
PDF
AWS Cloud Security
Amazon Web Services LATAM
 
PDF
1. aws security and compliance wwps pre-day sao paolo - markry
Amazon Web Services LATAM
 
PDF
Security Best Practices_John Hildebrandt
Helen Rogers
 
PPTX
Best Practices in Secure Cloud Migration
CloudHesive
 
PDF
Introduction to AWS Security
LalitMohanSharma8
 
PPTX
Building security from scratch
Roman Zelenko
 
PDF
AWS Cloud Governance & Security through Automation - Atlanta AWS Builders
James Strong
 
Automating AWS security and compliance
John Varghese
 
CIS Compliance Automations Eevidence Collection, Security and Compliance Be...
Faiza Mehar
 
AWS Spotlight Series - Modernization and Security with AWS
CloudHesive
 
Security on AWS
CloudHesive
 
Build and Manage a Highly Secure Cloud Environment on AWS and Azure
CloudHesive
 
AWS Cloud Security
AWS Riyadh User Group
 
Top 10 AWS Security and Compliance best practices
Ahmad Khan
 
Security on AWS, 2021 Edition Meetup
CloudHesive
 
Security on AWS, 2021 Edition Meetup
CloudHesive
 
Blue Chip Tek Connect and Protect Presentation #3
Kimberly Macias
 
AWS_security_at_scale__From_development_to_production.pdf
kantrajnee88
 
Security in the cloud
Reham Maher El-Safarini
 
Securing Your Customers Data From Day One
Amazon Web Services LATAM
 
AWS Cloud Security
Amazon Web Services LATAM
 
1. aws security and compliance wwps pre-day sao paolo - markry
Amazon Web Services LATAM
 
Security Best Practices_John Hildebrandt
Helen Rogers
 
Best Practices in Secure Cloud Migration
CloudHesive
 
Introduction to AWS Security
LalitMohanSharma8
 
Building security from scratch
Roman Zelenko
 
AWS Cloud Governance & Security through Automation - Atlanta AWS Builders
James Strong
 
Ad

More from Aleksandr Maklakov (14)

PDF
GraphQL backend with AWS AppSync & AWS Lambda
Aleksandr Maklakov
 
PPTX
AWS Certification from scratch
Aleksandr Maklakov
 
PPTX
Chronicle of ReInvent 2019
Aleksandr Maklakov
 
PPTX
Secure perimeter with AWS workspaces
Aleksandr Maklakov
 
PPTX
Going Serverless on AWS
Aleksandr Maklakov
 
PDF
AWS Security Best Practices
Aleksandr Maklakov
 
PDF
AWS Container services
Aleksandr Maklakov
 
PPTX
How to implement DevSecOps on AWS for startups
Aleksandr Maklakov
 
PDF
AWS CloudFront
Aleksandr Maklakov
 
PDF
HOW TO DRONE.IO IN CI/CD WORLD
Aleksandr Maklakov
 
PDF
Amazon EC2 container service
Aleksandr Maklakov
 
PDF
Continuous operations in AWS
Aleksandr Maklakov
 
PDF
Architecture of NoSQL distributed clusters on AWS
Aleksandr Maklakov
 
PDF
Managing users and aws accounts
Aleksandr Maklakov
 
GraphQL backend with AWS AppSync & AWS Lambda
Aleksandr Maklakov
 
AWS Certification from scratch
Aleksandr Maklakov
 
Chronicle of ReInvent 2019
Aleksandr Maklakov
 
Secure perimeter with AWS workspaces
Aleksandr Maklakov
 
Going Serverless on AWS
Aleksandr Maklakov
 
AWS Security Best Practices
Aleksandr Maklakov
 
AWS Container services
Aleksandr Maklakov
 
How to implement DevSecOps on AWS for startups
Aleksandr Maklakov
 
AWS CloudFront
Aleksandr Maklakov
 
HOW TO DRONE.IO IN CI/CD WORLD
Aleksandr Maklakov
 
Amazon EC2 container service
Aleksandr Maklakov
 
Continuous operations in AWS
Aleksandr Maklakov
 
Architecture of NoSQL distributed clusters on AWS
Aleksandr Maklakov
 
Managing users and aws accounts
Aleksandr Maklakov
 
Ad

Recently uploaded (20)

PDF
Presentation - Vibe Coding The Future of Tech
yanuarsinggih1
 
PDF
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PDF
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
PDF
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
PDF
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
PDF
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
PDF
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
PDF
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
PDF
The Builder’s Playbook - 2025 State of AI Report.pdf
jeroen339954
 
PPTX
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
PDF
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
PPTX
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
PPTX
WooCommerce Workshop: Bring Your Laptop
Laura Hartwig
 
PPTX
UiPath Academic Alliance Educator Panels: Session 2 - Business Analyst Content
DianaGray10
 
PDF
Windsurf Meetup Ottawa 2025-07-12 - Planning Mode at Reliza.pdf
Pavel Shukhman
 
PDF
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
PDF
Timothy Rottach - Ramp up on AI Use Cases, from Vector Search to AI Agents wi...
AWS Chicago
 
PPTX
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
PPTX
MSP360 Backup Scheduling and Retention Best Practices.pptx
MSP360
 
Presentation - Vibe Coding The Future of Tech
yanuarsinggih1
 
New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
"AI Transformation: Directions and Challenges", Pavlo Shaternik
Fwdays
 
CIFDAQ Weekly Market Wrap for 11th July 2025
CIFDAQ
 
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
Exolore The Essential AI Tools in 2025.pdf
Srinivasan M
 
NewMind AI - Journal 100 Insights After The 100th Issue
NewMind AI
 
Log-Based Anomaly Detection: Enhancing System Reliability with Machine Learning
Mohammed BEKKOUCHE
 
The Builder’s Playbook - 2025 State of AI Report.pdf
jeroen339954
 
Q2 FY26 Tableau User Group Leader Quarterly Call
lward7
 
CIFDAQ Token Spotlight for 9th July 2025
CIFDAQ
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
"Autonomy of LLM Agents: Current State and Future Prospects", Oles` Petriv
Fwdays
 
WooCommerce Workshop: Bring Your Laptop
Laura Hartwig
 
UiPath Academic Alliance Educator Panels: Session 2 - Business Analyst Content
DianaGray10
 
Windsurf Meetup Ottawa 2025-07-12 - Planning Mode at Reliza.pdf
Pavel Shukhman
 
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
Timothy Rottach - Ramp up on AI Use Cases, from Vector Search to AI Agents wi...
AWS Chicago
 
Building Search Using OpenSearch: Limitations and Workarounds
Sease
 
MSP360 Backup Scheduling and Retention Best Practices.pptx
MSP360
 

How to stop dreaming about security and start implementing