SlideShare une entreprise Scribd logo
1  sur  26
Télécharger pour lire hors ligne
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Achieving Continuous
Compliance
with CTP and AWS
• Peter Williams, Global Technology Lead, Amazon Web Services
• Brian Ott, VP of Managed Cloud Control Services, Cloud Technology
Partners
• Ann Neidenbach, CIO, Cowen
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
• How compliance in the cloud is different than on-premises, particularly for
financial services organizations.
• What it means to be in continuous compliance and why it’s important.
• How Cloud Technology Partners (CTP) and Amazon Web Services (AWS) work
together to keep you in compliance.
• How to improve visibility of all compliance requirements across the business.
Learning Objectives
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS and Financial Services-
Governance, Risk and Compliance
(GRC)
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Industry Challenges
The regulatory environment for
financial services organizations is
both complex and dynamic.
Identifying, assessing, and
complying with change across the
business is even more challenging
without a comprehensive approach.
How can organizations ensure
regulatory compliance in the
cloud?
EMA
PRA
Treasury
FDIC
FFIECBASEL
Dodd-Frank
NMS
MiFID II BCBS 239
CCAR
ESMA
RDAFR Y-9C
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Key AWS Certifications and Assurance Programs
Visit http://aws.amazon.com/compliance for more details.
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Security by Design (SbD) is a modern,
security assurance approach that
formalizes AWS account design,
automates security controls, and
streamlines auditing.
It is a systematic approach to ensure
security; instead of relying on after-the-fact
auditing, SbD provides control insights
throughout the IT management process.
Create Invisible Guardrails: Security by Design
CloudTrail
CloudHSM
IAM
KMS
AWS
Config
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
AWS WAF
Tool designed to filter
malicious web traffic
AWS Organizations
Policy-based management
for multiple AWS accounts
Amazon Inspector
Automated application
security assessment service
AWS Shield
Managed Distributed Denial
of Service (DDoS) protection
service that safeguards web
applications running on AWS
AWS Identity and
Access Management
(IAM)
Securely control access to
AWS services and
resources for your users
AWS Key Management
Service (AWS KMS)
Managed service to create
and control encryption keys
AWS CloudHSM
Hardware-based keys storage
for regulatory compliance
AWS EC2 Systems
Manager
Fleet management for
vulnerability scanning and
patching.
AWS Config and AWS
Config rules
AWS resource inventory,
configuration history, and
configuration change notifications
& preventive rules.
AWS Service Catalog &
AWS CloudFormation
AWS tools to manage approved
services and environments
across all accounts, Lines of
Business, and user bases.
Amazon Macie
Uses machine learning to
automatically discover, classify,
and protect sensitive data on
AWS.
AWS Tools & Services
Amazon VPC
Logically isolated section of the
AWS Cloud where you launch
AWS resources in a virtual
network that you define
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Continuous Compliance Monitoring
Compliance organizations need to:
• Monitor compliance with rules required for their organization.
• Maintain up-to-date regulations across numerous regulators.
• Consolidate monitoring across their organization in a ‘single pane of glass’.
• Prove to auditors that compliance is maintained now and historically.
© 2017 Cloud Technology Partners, Inc. / Confidential 9
Managed Cloud Controls
Continuous Compliance
© 2017 Cloud Technology Partners, Inc. / Confidential 10
We Are Enterprise Cloud Experts
CTP is a premier cloud services and
software company for enterprises
moving to cloud.
500+ Enterprise Engagements
Across Platforms
✓ AWS Premier Consulting Partner
✓ Gartner Cool Cloud Vendor
● Migration Competency
● Security Competency
● IoT Competency
● DevOps Competency
● Financial Services Competency
● Managed Services Partner
© 2017 Cloud Technology Partners, Inc. / Confidential 11
Common Questions & Concerns in Moving to
AWS
Minimize the risk and
uncertainly and to
accelerate adoption of AWS.
“Continuous
Compliance”
• “How do I gain alignment around my cloud
strategy and continuously govern everything
we’re doing in the cloud?”
• “How do I prepare for regulatory audits?”
• “How do I ensure that applications we migrate to
the cloud are following my security and
governance requirements?”
• “How do I find peace of mind and ensure our
employees are following our governance, risk
and compliance standards?”
© 2017 Cloud Technology Partners, Inc. / Confidential 12
What is Continuous Compliance?
A Service to Provide Your Single Source of
Proof for Compliance.
Continuous monitoring of over 1,000 IT compliance, corporate
governance and regulatory compliance controls.
 Real-time monitoring and alerting of control failures and
recommendations for remediation
 The most up-to-date policies from regulatory organizations
that ensure compliance frameworks are updated upon
release
 Continuous synchronization of new cloud services and
capabilities with regulatory compliance frameworks
 Reduced time, cost and complexity of audit preparation
 CTP’s expertise to provide ongoing recommendations for
remediation and cloud compliance
© 2017 Cloud Technology Partners, Inc. / Confidential 13
Continuous Compliance - Approach
Compliance
Risk
Security
Control Frameworks
Technical Rules
Process Rules
** CTP BP: CTP Best Practices for AWS
© 2017 Cloud Technology Partners, Inc. / Confidential 14
How Does Continuous Compliance Work?
Source of Data Key Stakeholders
Compliance
Risk
Security
Cloud
Applications
Infrastructure
Regulatory
Framework
Technical Rules
Process Rules
SaaS
Continuous Compliance
Policy Hub
We scan AWS
© 2017 Cloud Technology Partners, Inc. / Confidential 15
CTP’s Continuous Compliance Bridges the Customer
& AWS Areas of Responsibility as a Single Source for
Compliance
Continuous
Compliance
© 2017 Cloud Technology Partners, Inc. / Confidential 16
CTP Worked with Cowen to Enable & Accelerate the
Move to AWS Including Continuous Compliance
PHASE 5:
OPERATE & OPTIMIZE
PHASE 2:
ASSESS & PLAN
TCO / ROI Assessment
Application Portfolio Assessment
Security Assessment
Infrastructure Assessment
DevOps Assessment
ESTABLISH BASELINE TRANSITION
PHASE 1:
WORKSHOP
DISCOVERY
PHASE 4:
MIGRATE
PHASE 3:
BUILD
LAY FOUNDATION
Minimum Viable Cloud (MVC)
DevOps Enablement
Tooling & Automation
CloudOps
InfoSec
Client Solutions
Financial Management
Application Optimization
>> >> >>
MANAGED
CLOUD
CONTROLS
Continuous Compliance
Continuous Cost Control
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Case Study
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cowen Challenges
• Legacy/Aging infrastructure and datacenters: High costs to maintain
(comp and non-comp) – significant capital expenditure required to
upgrade/refresh.
• Shift in business model: Moved many critical business systems to
Software as a Service (SaaS) providers resulting in over-engineered
infrastructure for what remained.
• Evolving business strategy: Required agile infrastructure that could
easily remove cost.
• Reliable compliance controls in regulated industry: Alignment to the
National Institute of Standards and Technology (NIST) compliance
framework.
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Why Choose CTP and AWS?
Proven APN Partner
Experience with a number
of financial services firms
on cloud migrations
Scaling
Engagements
Assess capabilities before
committing to a longer
term engagement
Monitor and Leverage
C2
Continuously monitor our
applications against the NIST
compliance framework
Experience/Knowledge
Grow overall cloud strategy
and migration
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
How Did CTP Address Cowen’s Challenges?
Cowen IT experienced a significant cultural shift in a manner of
months,
having a fully functional DevOps Team in 13 weeks.
•Validated our assumptions on
Cloud economics
•Developed a roadmap to ensure
our time horizons were realistic
Provided the necessary training
and frameworks:
● Agile Development Methodology
● Minimally Viable Cloud (MVC) model
● Cloud Migration Factory
Guided the development of
tools/process to maintain
security/compliance
1 2
3 4
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Cowen AWS Migration
Cowen’s migration to AWS followed an agile development methodology, allowing for
iterative learning.
Cowen’s ‘Migration Factory’ ran in 3 week
Sprints with successively more complex apps
in each Sprint. Initial Sprints developed the
automated building blocks used in the later
stages.
The MVC workstream built upon itself
starting with Foundational, Fundamental,
and Extended components as the staff
experience and cloud usage expanded.
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Specific Benefits to Cowen
The migration to AWS has yielded significant improvements to Cowen’s
overall IT environment.
• Consistent, repeatable, and fully automated build process through infrastructure and
application deployment.
• On-demand lab/development and QA environments only run during hours of usage with
automated start/stop.
• Enhanced cost and Total Cost of Ownership (TCO) details by application.
• Automated patching process of base images across cloud infrastructure.
• Hybrid operational model across both cloud and on-premises environments:
 Centralized cloud-based monitoring – ‘single pane of glass’
 Central Support Staff for cloud and on-premises
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
CTP Continuous Compliance on AWS
• Achieve and maintain a continuous state of compliance for a cloud
enabled business
• Build a data-driven approach to compliance
• Get real-time notification analysis and remediation strategy
• Accelerate the pace of innovation
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
© 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Q&A
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Learn More About CTP
https://www.cloudtp.com/
Learn More About Continuous Compliance
https://hubs.ly/H08FlB70
Try AWS for Free
https://aws.amazon.com/
Next Steps and Further Information
© 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Thank You!

Contenu connexe

Tendances

Tendances (19)

Getting started with AWS Security
Getting started with AWS SecurityGetting started with AWS Security
Getting started with AWS Security
 
Identity and Access Management: The First Step in AWS Security
Identity and Access Management: The First Step in AWS SecurityIdentity and Access Management: The First Step in AWS Security
Identity and Access Management: The First Step in AWS Security
 
Module 2 AWS Foundational Services - AWSome Day Online Conference
Module 2 AWS Foundational Services - AWSome Day Online Conference Module 2 AWS Foundational Services - AWSome Day Online Conference
Module 2 AWS Foundational Services - AWSome Day Online Conference
 
9 Security Best Practices
9 Security Best Practices9 Security Best Practices
9 Security Best Practices
 
Identity and Access Management: The First Step in AWS Security
Identity and Access Management: The First Step in AWS SecurityIdentity and Access Management: The First Step in AWS Security
Identity and Access Management: The First Step in AWS Security
 
Introduction to Security and AWS Storage
Introduction to Security and AWS StorageIntroduction to Security and AWS Storage
Introduction to Security and AWS Storage
 
9 Security Best Practices
9 Security Best Practices9 Security Best Practices
9 Security Best Practices
 
Identify and Access Management: The First Step in AWS Security
Identify and Access Management: The First Step in AWS SecurityIdentify and Access Management: The First Step in AWS Security
Identify and Access Management: The First Step in AWS Security
 
AWS 101 - Tel Aviv Summit 2018
AWS 101 - Tel Aviv Summit 2018AWS 101 - Tel Aviv Summit 2018
AWS 101 - Tel Aviv Summit 2018
 
AWS Technical Essentials Day
AWS Technical Essentials DayAWS Technical Essentials Day
AWS Technical Essentials Day
 
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech TalksDeep Dive on AWS Single Sign-On - AWS Online Tech Talks
Deep Dive on AWS Single Sign-On - AWS Online Tech Talks
 
AWS business essentials
AWS business essentials AWS business essentials
AWS business essentials
 
Foundations: Understanding the Critical Building Blocks of AWS Identity and G...
Foundations: Understanding the Critical Building Blocks of AWS Identity and G...Foundations: Understanding the Critical Building Blocks of AWS Identity and G...
Foundations: Understanding the Critical Building Blocks of AWS Identity and G...
 
AWS Certificate Management and Private Certificate Authority Deep Dive (SEC41...
AWS Certificate Management and Private Certificate Authority Deep Dive (SEC41...AWS Certificate Management and Private Certificate Authority Deep Dive (SEC41...
AWS Certificate Management and Private Certificate Authority Deep Dive (SEC41...
 
AWS Security Fundamentals
AWS Security FundamentalsAWS Security Fundamentals
AWS Security Fundamentals
 
AWS Training and Certification
AWS Training and CertificationAWS Training and Certification
AWS Training and Certification
 
Scaling threat detection and response on AWS
Scaling threat detection and response on AWSScaling threat detection and response on AWS
Scaling threat detection and response on AWS
 
Secure Your Customers' Data From Day One
Secure Your Customers' Data From Day OneSecure Your Customers' Data From Day One
Secure Your Customers' Data From Day One
 
Design, Deploy, & Optimize SQL Server Workloads
Design, Deploy, & Optimize SQL Server Workloads Design, Deploy, & Optimize SQL Server Workloads
Design, Deploy, & Optimize SQL Server Workloads
 

Similaire à Achieving Continuous Compliance with CTP and AWS

Similaire à Achieving Continuous Compliance with CTP and AWS (20)

GPSMKT201-Expanding Channel Opportunities Using AWS Marketplace as a Fulfillm...
GPSMKT201-Expanding Channel Opportunities Using AWS Marketplace as a Fulfillm...GPSMKT201-Expanding Channel Opportunities Using AWS Marketplace as a Fulfillm...
GPSMKT201-Expanding Channel Opportunities Using AWS Marketplace as a Fulfillm...
 
ENT315_Landing Zones
ENT315_Landing ZonesENT315_Landing Zones
ENT315_Landing Zones
 
Enabling Broad Organisational Transformation through the Adoption of AWS
Enabling Broad Organisational Transformation through the Adoption of AWSEnabling Broad Organisational Transformation through the Adoption of AWS
Enabling Broad Organisational Transformation through the Adoption of AWS
 
Financial Services Industry Forum
Financial Services Industry ForumFinancial Services Industry Forum
Financial Services Industry Forum
 
Understand the performance of customer facing applications with AWS Marketpla...
Understand the performance of customer facing applications with AWS Marketpla...Understand the performance of customer facing applications with AWS Marketpla...
Understand the performance of customer facing applications with AWS Marketpla...
 
AWS FSI Symposium 2017 NYC- Shared Reponsibility & AWS Compliance
AWS FSI Symposium 2017 NYC- Shared Reponsibility & AWS ComplianceAWS FSI Symposium 2017 NYC- Shared Reponsibility & AWS Compliance
AWS FSI Symposium 2017 NYC- Shared Reponsibility & AWS Compliance
 
Accelerating Your Cloud Migration Journey with MAP
Accelerating Your Cloud Migration Journey with MAPAccelerating Your Cloud Migration Journey with MAP
Accelerating Your Cloud Migration Journey with MAP
 
AWS Summit Singapore Webinar Edition | Secrets to Successful Cloud Migrations...
AWS Summit Singapore Webinar Edition | Secrets to Successful Cloud Migrations...AWS Summit Singapore Webinar Edition | Secrets to Successful Cloud Migrations...
AWS Summit Singapore Webinar Edition | Secrets to Successful Cloud Migrations...
 
規劃大規模遷移到 AWS 的最佳實踐
規劃大規模遷移到 AWS 的最佳實踐規劃大規模遷移到 AWS 的最佳實踐
規劃大規模遷移到 AWS 的最佳實踐
 
Security & Compliance in the Cloud
Security & Compliance in the CloudSecurity & Compliance in the Cloud
Security & Compliance in the Cloud
 
Casi reali di Mass Migration nel Cloud: benefici tangibili ed intangibili
Casi reali di Mass Migration nel Cloud: benefici tangibili ed intangibiliCasi reali di Mass Migration nel Cloud: benefici tangibili ed intangibili
Casi reali di Mass Migration nel Cloud: benefici tangibili ed intangibili
 
AWS Marketplace on Reaching Enterprises
AWS Marketplace on Reaching EnterprisesAWS Marketplace on Reaching Enterprises
AWS Marketplace on Reaching Enterprises
 
Building end-to-end IT Lifecycle Mgmt & Workflows with AWS Service Catalog - ...
Building end-to-end IT Lifecycle Mgmt & Workflows with AWS Service Catalog - ...Building end-to-end IT Lifecycle Mgmt & Workflows with AWS Service Catalog - ...
Building end-to-end IT Lifecycle Mgmt & Workflows with AWS Service Catalog - ...
 
Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...
Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...
Security Validation through Continuous Delivery at Verizon - DEV403 - re:Inve...
 
How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic
 How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic
How Rent-A-Center Stays Secure and Compliant on AWS with Alert Logic
 
How to Achieve PCI DSS Compliance on AWS
 How to Achieve PCI DSS Compliance on AWS How to Achieve PCI DSS Compliance on AWS
How to Achieve PCI DSS Compliance on AWS
 
Top 10 AWS Security and Compliance best practices
Top 10 AWS Security and Compliance best practicesTop 10 AWS Security and Compliance best practices
Top 10 AWS Security and Compliance best practices
 
GPSBUS208-GPS DevOps transformations leading to cloud migrations
GPSBUS208-GPS DevOps transformations leading to cloud migrationsGPSBUS208-GPS DevOps transformations leading to cloud migrations
GPSBUS208-GPS DevOps transformations leading to cloud migrations
 
GPSBUS214-Key Considerations for Cloud Procurement in the Public Sector
GPSBUS214-Key Considerations for Cloud Procurement in the Public SectorGPSBUS214-Key Considerations for Cloud Procurement in the Public Sector
GPSBUS214-Key Considerations for Cloud Procurement in the Public Sector
 
GPSBUS204_Building a Profitable Next Generation AWS MSP Practice
GPSBUS204_Building a Profitable Next Generation AWS MSP PracticeGPSBUS204_Building a Profitable Next Generation AWS MSP Practice
GPSBUS204_Building a Profitable Next Generation AWS MSP Practice
 

Plus de Amazon Web Services

Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
Amazon Web Services
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
Amazon Web Services
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
Amazon Web Services
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
Amazon Web Services
 

Plus de Amazon Web Services (20)

Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
Come costruire servizi di Forecasting sfruttando algoritmi di ML e deep learn...
 
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
Big Data per le Startup: come creare applicazioni Big Data in modalità Server...
 
Esegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS FargateEsegui pod serverless con Amazon EKS e AWS Fargate
Esegui pod serverless con Amazon EKS e AWS Fargate
 
Costruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWSCostruire Applicazioni Moderne con AWS
Costruire Applicazioni Moderne con AWS
 
Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot Come spendere fino al 90% in meno con i container e le istanze spot
Come spendere fino al 90% in meno con i container e le istanze spot
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
Rendi unica l’offerta della tua startup sul mercato con i servizi Machine Lea...
 
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...OpsWorks Configuration Management: automatizza la gestione e i deployment del...
OpsWorks Configuration Management: automatizza la gestione e i deployment del...
 
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows WorkloadsMicrosoft Active Directory su AWS per supportare i tuoi Windows Workloads
Microsoft Active Directory su AWS per supportare i tuoi Windows Workloads
 
Computer Vision con AWS
Computer Vision con AWSComputer Vision con AWS
Computer Vision con AWS
 
Database Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatareDatabase Oracle e VMware Cloud on AWS i miti da sfatare
Database Oracle e VMware Cloud on AWS i miti da sfatare
 
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJSCrea la tua prima serverless ledger-based app con QLDB e NodeJS
Crea la tua prima serverless ledger-based app con QLDB e NodeJS
 
API moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e webAPI moderne real-time per applicazioni mobili e web
API moderne real-time per applicazioni mobili e web
 
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatareDatabase Oracle e VMware Cloud™ on AWS: i miti da sfatare
Database Oracle e VMware Cloud™ on AWS: i miti da sfatare
 
Tools for building your MVP on AWS
Tools for building your MVP on AWSTools for building your MVP on AWS
Tools for building your MVP on AWS
 
How to Build a Winning Pitch Deck
How to Build a Winning Pitch DeckHow to Build a Winning Pitch Deck
How to Build a Winning Pitch Deck
 
Building a web application without servers
Building a web application without serversBuilding a web application without servers
Building a web application without servers
 
Fundraising Essentials
Fundraising EssentialsFundraising Essentials
Fundraising Essentials
 
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
AWS_HK_StartupDay_Building Interactive websites while automating for efficien...
 
Introduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container ServiceIntroduzione a Amazon Elastic Container Service
Introduzione a Amazon Elastic Container Service
 

Achieving Continuous Compliance with CTP and AWS

  • 1. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Achieving Continuous Compliance with CTP and AWS • Peter Williams, Global Technology Lead, Amazon Web Services • Brian Ott, VP of Managed Cloud Control Services, Cloud Technology Partners • Ann Neidenbach, CIO, Cowen
  • 2. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. • How compliance in the cloud is different than on-premises, particularly for financial services organizations. • What it means to be in continuous compliance and why it’s important. • How Cloud Technology Partners (CTP) and Amazon Web Services (AWS) work together to keep you in compliance. • How to improve visibility of all compliance requirements across the business. Learning Objectives
  • 3. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS and Financial Services- Governance, Risk and Compliance (GRC)
  • 4. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Industry Challenges The regulatory environment for financial services organizations is both complex and dynamic. Identifying, assessing, and complying with change across the business is even more challenging without a comprehensive approach. How can organizations ensure regulatory compliance in the cloud? EMA PRA Treasury FDIC FFIECBASEL Dodd-Frank NMS MiFID II BCBS 239 CCAR ESMA RDAFR Y-9C
  • 5. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Key AWS Certifications and Assurance Programs Visit http://aws.amazon.com/compliance for more details.
  • 6. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Security by Design (SbD) is a modern, security assurance approach that formalizes AWS account design, automates security controls, and streamlines auditing. It is a systematic approach to ensure security; instead of relying on after-the-fact auditing, SbD provides control insights throughout the IT management process. Create Invisible Guardrails: Security by Design CloudTrail CloudHSM IAM KMS AWS Config
  • 7. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. AWS WAF Tool designed to filter malicious web traffic AWS Organizations Policy-based management for multiple AWS accounts Amazon Inspector Automated application security assessment service AWS Shield Managed Distributed Denial of Service (DDoS) protection service that safeguards web applications running on AWS AWS Identity and Access Management (IAM) Securely control access to AWS services and resources for your users AWS Key Management Service (AWS KMS) Managed service to create and control encryption keys AWS CloudHSM Hardware-based keys storage for regulatory compliance AWS EC2 Systems Manager Fleet management for vulnerability scanning and patching. AWS Config and AWS Config rules AWS resource inventory, configuration history, and configuration change notifications & preventive rules. AWS Service Catalog & AWS CloudFormation AWS tools to manage approved services and environments across all accounts, Lines of Business, and user bases. Amazon Macie Uses machine learning to automatically discover, classify, and protect sensitive data on AWS. AWS Tools & Services Amazon VPC Logically isolated section of the AWS Cloud where you launch AWS resources in a virtual network that you define
  • 8. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Continuous Compliance Monitoring Compliance organizations need to: • Monitor compliance with rules required for their organization. • Maintain up-to-date regulations across numerous regulators. • Consolidate monitoring across their organization in a ‘single pane of glass’. • Prove to auditors that compliance is maintained now and historically.
  • 9. © 2017 Cloud Technology Partners, Inc. / Confidential 9 Managed Cloud Controls Continuous Compliance
  • 10. © 2017 Cloud Technology Partners, Inc. / Confidential 10 We Are Enterprise Cloud Experts CTP is a premier cloud services and software company for enterprises moving to cloud. 500+ Enterprise Engagements Across Platforms ✓ AWS Premier Consulting Partner ✓ Gartner Cool Cloud Vendor ● Migration Competency ● Security Competency ● IoT Competency ● DevOps Competency ● Financial Services Competency ● Managed Services Partner
  • 11. © 2017 Cloud Technology Partners, Inc. / Confidential 11 Common Questions & Concerns in Moving to AWS Minimize the risk and uncertainly and to accelerate adoption of AWS. “Continuous Compliance” • “How do I gain alignment around my cloud strategy and continuously govern everything we’re doing in the cloud?” • “How do I prepare for regulatory audits?” • “How do I ensure that applications we migrate to the cloud are following my security and governance requirements?” • “How do I find peace of mind and ensure our employees are following our governance, risk and compliance standards?”
  • 12. © 2017 Cloud Technology Partners, Inc. / Confidential 12 What is Continuous Compliance? A Service to Provide Your Single Source of Proof for Compliance. Continuous monitoring of over 1,000 IT compliance, corporate governance and regulatory compliance controls.  Real-time monitoring and alerting of control failures and recommendations for remediation  The most up-to-date policies from regulatory organizations that ensure compliance frameworks are updated upon release  Continuous synchronization of new cloud services and capabilities with regulatory compliance frameworks  Reduced time, cost and complexity of audit preparation  CTP’s expertise to provide ongoing recommendations for remediation and cloud compliance
  • 13. © 2017 Cloud Technology Partners, Inc. / Confidential 13 Continuous Compliance - Approach Compliance Risk Security Control Frameworks Technical Rules Process Rules ** CTP BP: CTP Best Practices for AWS
  • 14. © 2017 Cloud Technology Partners, Inc. / Confidential 14 How Does Continuous Compliance Work? Source of Data Key Stakeholders Compliance Risk Security Cloud Applications Infrastructure Regulatory Framework Technical Rules Process Rules SaaS Continuous Compliance Policy Hub We scan AWS
  • 15. © 2017 Cloud Technology Partners, Inc. / Confidential 15 CTP’s Continuous Compliance Bridges the Customer & AWS Areas of Responsibility as a Single Source for Compliance Continuous Compliance
  • 16. © 2017 Cloud Technology Partners, Inc. / Confidential 16 CTP Worked with Cowen to Enable & Accelerate the Move to AWS Including Continuous Compliance PHASE 5: OPERATE & OPTIMIZE PHASE 2: ASSESS & PLAN TCO / ROI Assessment Application Portfolio Assessment Security Assessment Infrastructure Assessment DevOps Assessment ESTABLISH BASELINE TRANSITION PHASE 1: WORKSHOP DISCOVERY PHASE 4: MIGRATE PHASE 3: BUILD LAY FOUNDATION Minimum Viable Cloud (MVC) DevOps Enablement Tooling & Automation CloudOps InfoSec Client Solutions Financial Management Application Optimization >> >> >> MANAGED CLOUD CONTROLS Continuous Compliance Continuous Cost Control
  • 17. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Case Study
  • 18. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Cowen Challenges • Legacy/Aging infrastructure and datacenters: High costs to maintain (comp and non-comp) – significant capital expenditure required to upgrade/refresh. • Shift in business model: Moved many critical business systems to Software as a Service (SaaS) providers resulting in over-engineered infrastructure for what remained. • Evolving business strategy: Required agile infrastructure that could easily remove cost. • Reliable compliance controls in regulated industry: Alignment to the National Institute of Standards and Technology (NIST) compliance framework.
  • 19. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Why Choose CTP and AWS? Proven APN Partner Experience with a number of financial services firms on cloud migrations Scaling Engagements Assess capabilities before committing to a longer term engagement Monitor and Leverage C2 Continuously monitor our applications against the NIST compliance framework Experience/Knowledge Grow overall cloud strategy and migration
  • 20. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. How Did CTP Address Cowen’s Challenges? Cowen IT experienced a significant cultural shift in a manner of months, having a fully functional DevOps Team in 13 weeks. •Validated our assumptions on Cloud economics •Developed a roadmap to ensure our time horizons were realistic Provided the necessary training and frameworks: ● Agile Development Methodology ● Minimally Viable Cloud (MVC) model ● Cloud Migration Factory Guided the development of tools/process to maintain security/compliance 1 2 3 4
  • 21. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Cowen AWS Migration Cowen’s migration to AWS followed an agile development methodology, allowing for iterative learning. Cowen’s ‘Migration Factory’ ran in 3 week Sprints with successively more complex apps in each Sprint. Initial Sprints developed the automated building blocks used in the later stages. The MVC workstream built upon itself starting with Foundational, Fundamental, and Extended components as the staff experience and cloud usage expanded.
  • 22. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Specific Benefits to Cowen The migration to AWS has yielded significant improvements to Cowen’s overall IT environment. • Consistent, repeatable, and fully automated build process through infrastructure and application deployment. • On-demand lab/development and QA environments only run during hours of usage with automated start/stop. • Enhanced cost and Total Cost of Ownership (TCO) details by application. • Automated patching process of base images across cloud infrastructure. • Hybrid operational model across both cloud and on-premises environments:  Centralized cloud-based monitoring – ‘single pane of glass’  Central Support Staff for cloud and on-premises
  • 23. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. CTP Continuous Compliance on AWS • Achieve and maintain a continuous state of compliance for a cloud enabled business • Build a data-driven approach to compliance • Get real-time notification analysis and remediation strategy • Accelerate the pace of innovation
  • 24. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. © 2017, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Q&A
  • 25. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Learn More About CTP https://www.cloudtp.com/ Learn More About Continuous Compliance https://hubs.ly/H08FlB70 Try AWS for Free https://aws.amazon.com/ Next Steps and Further Information
  • 26. © 2017, Amazon Web Services, Inc. or its affiliates. All rights reserved. Thank You!