A presentation at AWS Community Summit Online UK 2021 by Bruno Amaro Almeida
7 AWS Deadly Sins The seven most common pitfalls - security, governance, architecture - I experienced after designing, reviewing and developing several AWS solutions Bruno Amaro Almeida AWS Community Summit Online UK Photo by Glen Carrie on Unsplash March 2021
Hello! About me Head of Technology & Architecture at Fortum Advisor / Architect Consulting π‘ Areas of interest > Cloud, DevOps, Security, Data Engineering & AI π Avid learner > 12xAWS, 2xAzure, 1xGCP β Author > AWS Security Specialty course Bruno Amaro Almeida Head of Technology & Architecture brunoamaro.com Reach out on: @bruno_amaro @brunoamaroalmeida
1# new AWS accounts need love π Three critical steps: 1. Enable MFA for Root account 2. Use AWS IAM 3. Enable AWS Cloud Trail 3 @bruno_amaro
#2 Make Cost management a priority β’ Enable AWS Budgets & Billing Alarms β’ Use AWS Cost Explorer (or similar) β’ Cloud costs as part of the technology governance β’ Give cost visibility to the development team https://iamondemand.com/blog/how-to-get-the-most-out-of-the-aws-cost-management-tools/ 4 @bruno_amaro
#3 Lack of Multi-Account Governance β’ Ownership β’ Limit incident blast radius β’ Healthy service limits β’ Set Guardrails and a Landing Zone β’ Define Service Control Policies β’ Consolidated billing 5 @bruno_amaro
#4 Missing Infrastructure as Code practices β’ Re-deployable infrastructure β’ Scalable β’ Documented β’ Maintainable https://speaking.brunoamaro.com/yUeFUQ/deployment-automation-for-an-awsserverless-project-sam-vs-cloudformation-vs-terraform 6 @bruno_amaro
#5 Not using IAM properly β’ Users == Humans or non-AWS resources β’ Least privilege policies β’ Avoid using Inline and AWS managed policies β’ Use AWS SSO > IAM Roles if possible β’ Leverage AWS IAM Access Analyzer 7 @bruno_amaro
#6 Encryption & Secrets β’ Huge security impact β’ Minimal cost impact (time and operational) β’ Compliance 8 @bruno_amaro Photo by Jordan Hopkins on Unsplash
#7 Missing out on interesting data Out-of-the-box data: β’ AWS Cloudtrail β’ AWS VPC Flow Logs β’ AWS ELB Access Logs Use cases: β’ Troubleshooting β’ Auditing & Compliance https://aws.amazon.com/guardduty/ β’ Analytics β’ SIEM 9 @bruno_amaro
Well-Architected Framework β’ Five core pillars β’ Additional Lens: Serverless, Machine Learning, Analytics, IoT, β¦ https://aws.amazon.com/architecture/well-architected/ 10 @bruno_amaro
Thanks! Questions? Feedback? Bruno Amaro Almeida Head of Technology & Architecture brunoamaro.com Reach out on: @bruno_amaro @brunoamaroalmeida
The seven most common pitfalls - #security, #governance, #architecture - I experienced after designing, reviewing and developing several Amazon Web Services (AWS) solutions.
Hereβs what was said about this presentation on social media.
π£οΈ 7 #AWS Deadly Sins at @AWScomsum
— Bruno Amaro Almeida (@bruno_amaro) March 4, 2021
The seven most common pitfalls - #security, #governance, #architecture - I experienced after designing, reviewing and developing several @awscloud solutions
π https://t.co/4ofgnvj3w1
I am going live soon on @AWScomsum for an @awscloud architecture roundtable discussion on the elements of a modern #AWS application.
— Bruno Amaro Almeida (@bruno_amaro) March 4, 2021
Topics: Security, Management, Governance, Data Strategy, ..
Join the stream directly via the link below π https://t.co/k9ON6AUzi4