SlideShare a Scribd company logo
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
@marknca
Strategy 
Tactics
Traditional Responsibility Model 
You
AWS 
You 
Shared Responsibility Model
AWS 
Facilities 
Physical 
Network 
Virtualization Layer 
You 
Shared Responsibility Model
Monitoring 
Forensics 
4 pillars of practice
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
SANS incident response process
SANS incident response process
Business point of view
Incident response before 
Server 
Analyze 
Repair 
Improve 
Replacement
Incident response before 
Instance 
Analyze 
Repair 
Improve 
Replacement
Advantages
In action…
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
Optimized response
Optimized response 
Instance 
Script 
Analyze 
Improve 
API 
Replacement
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
Business point of view
Creating an audit trail before 
Servers 
ChangeRecord 
Storage 
Logs 
Firewall / IPS
Creating an audit trail before 
Instances 
ChangeRecord 
CentralManagement 
Logs 
AWS Services
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
In action…
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014
Please give us your feedback on this session. 
Complete session evaluations and earn re:Invent swag. 
http://bit.ly/awsevals

More Related Content

(SEC313) Updating Security Operations for the Cloud | AWS re:Invent 2014