SlideShare a Scribd company logo
1 of 52
You, RightScale, and the Universe of
Compliance

Phil Cox
Director of Security and Compliance, RightScale
2#




     SARBANES-OXLEY




    Massachusetts Privacy Law - 201 CMR 17



Talk with the Experts.
3#




            We are in a world of transition




Talk with the Experts.
4#




    From Consumerization of IT and BYOD




Talk with the Experts.
5#




                         To Arab Summer




Talk with the Experts.
6#




          The world around us is changing
           technically and it affects us all




Talk with the Experts.
7#




               Compliance standards are
                  slow to catch up




Talk with the Experts.
8#




 PCI - 1.1.3 Requirements for a firewall at
 each Internet connection and between any
 demilitarized zone (DMZ) and the internal
 network zone



Talk with the Experts.
9#




  There is a lot of FUD (Fear, Uncertainty
 and Doubt) with regards to what you "have
            to do" to meet them



Talk with the Experts.
10#




  This is my point of view from ~15 years of
  experience as a Consultant/Assessor and
               a Practitioner …




Talk with the Experts.
11#




      We’ll identify what the standards and
             regulations really “Want”




Talk with the Experts.
12#




    We’ll then identify “How” can RightScale
     help you meet those requirements




Talk with the Experts.
13#




                  Side Note
  You need to know if you are you shooting
                      for
             “letter of the law”
                       or
            “intent of the law”
                 compliance
Talk with the Experts.
14#



 And a way we go …




Talk with the Experts.
15#




                 Want #1:
   Governance – Verifiable and Repeatable




Talk with the Experts.
16#




 You have identified business drivers and
    know what you want to accomplish




Talk with the Experts.
17#




     You have taken the time to document
       what you want, so it is repeatable




Talk with the Experts.
18#




  You have evidence that you do what you
               say you do




Talk with the Experts.
19#




                         How #1
       This is your governance structure.
     I can chat with you, but this is on you.




Talk with the Experts.
20#




                      Want #2
     Build it right – Design and Architecture




Talk with the Experts.
21#




     It is entirely possible to design and
  architect something that is not securable!




Talk with the Experts.
22#




                         How #2
  Engage RightScale Professional Services
       We ARE as good as it gets!



Talk with the Experts.
23#




                         How #2
       The support portal for webinars and
                 whitepapers




Talk with the Experts.
24#




                      Want #3
          Deploy it correctly and securely




Talk with the Experts.
25#




                         How #3
         Leverage Multi-Cloud Images,
       ServerTemplates, RightScripts/Chef
                  Templates




Talk with the Experts.
26#




                 Added advantage
         Meet governance requirements -
         Documented with version control




Talk with the Experts.
27#




                         Want #4
                   Patch it appropriately




Talk with the Experts.
28#




                         How #4
 Use RightScale to configure the system to
 be consistent with your process and policy




Talk with the Experts.
29#




                         Want #5
           Audit/Watch what is happening




Talk with the Experts.
30#




                         How #5
      Operational Audit Entries via API or
                  Dashboard




Talk with the Experts.
31#




                         How #5
  Configure syslog/event logs to your SIEM




Talk with the Experts.
32#




                         Want #6
       Proactive vulnerability management




Talk with the Experts.
33#




                         How #6
    Use RightScale to deploy agents (e.g.,
    CloudPassage Halo, TrendMicro Deep
               Security, etc.)



Talk with the Experts.
34#




                         How #6
     Use RightScale API to get all active
   internal and external IP’s regardless of
   Cloud and feed to Vulnerability Scanner
            (SAINT, Nessus, etc.)



Talk with the Experts.
35#




                         Want #7
                     Audit and Review




Talk with the Experts.
36#




                         How #7
    Use the Infrastructure Audit report to
        show Security Group settings




Talk with the Experts.
37#



 Infrastructure Audit report




Talk with the Experts.
38#




                         How #7
                 Verify Users and Roles




Talk with the Experts.
39#



 Users on an Account




Talk with the Experts.
40#




                         Want #8
      Incident Response and Management




Talk with the Experts.
41#




                         How #8
  RightScale gives you a “single view” into
             your “IaaS world”




Talk with the Experts.
42#




                         Want #9
                Governance – Evidence




Talk with the Experts.
43#




                         How #9
      RightScale give you Events, Version
       Control, Self-Documenting configs




Talk with the Experts.
44#




                         Want #10
        You tell me … Anything I missed?




Talk with the Experts.
45#




     Questions about RightScale Security?




Talk with the Experts.
46#




  Our “Security Questionnaire Response” is
              the place to start!




Talk with the Experts.
47#




  Quick Case Study: CareCloud and HIPAA




Talk with the Experts.
48#




      HIPAA data is in datacenter currently




Talk with the Experts.
49#




 Customer needs will require moving HIPAA
              data to cloud




Talk with the Experts.
50#




                Q: What is the trick?
            A: No trick, just proper design




Talk with the Experts.
51#




   Punch line: Can do HIPAA in the cloud,
      just need to design and operate it
                   correctly!




Talk with the Experts.
52#



 Questions?




Talk with the Experts.

More Related Content

Viewers also liked

RightScale Webinar: Learn about the RightScale Cloud Appliance for vSphere
RightScale Webinar: Learn about the RightScale Cloud Appliance for vSphereRightScale Webinar: Learn about the RightScale Cloud Appliance for vSphere
RightScale Webinar: Learn about the RightScale Cloud Appliance for vSphere
RightScale
 
MultiCloud Bursting from Openstack to Windows Azure and Amazon AWS with Righ...
 MultiCloud Bursting from Openstack to Windows Azure and Amazon AWS with Righ... MultiCloud Bursting from Openstack to Windows Azure and Amazon AWS with Righ...
MultiCloud Bursting from Openstack to Windows Azure and Amazon AWS with Righ...
bn-cloud
 

Viewers also liked (9)

Ask The Architect: RightScale & AWS Dive Deep into Hybrid IT
Ask The Architect: RightScale & AWS Dive Deep into Hybrid ITAsk The Architect: RightScale & AWS Dive Deep into Hybrid IT
Ask The Architect: RightScale & AWS Dive Deep into Hybrid IT
 
RightScale Webinar: Learn about the RightScale Cloud Appliance for vSphere
RightScale Webinar: Learn about the RightScale Cloud Appliance for vSphereRightScale Webinar: Learn about the RightScale Cloud Appliance for vSphere
RightScale Webinar: Learn about the RightScale Cloud Appliance for vSphere
 
RightScale Webinar: Provide a Self-Service Portal for vSphere, AWS and Other ...
RightScale Webinar: Provide a Self-Service Portal for vSphere, AWS and Other ...RightScale Webinar: Provide a Self-Service Portal for vSphere, AWS and Other ...
RightScale Webinar: Provide a Self-Service Portal for vSphere, AWS and Other ...
 
RightScale Webinar: Best Practices: Software Development Strategies Using Win...
RightScale Webinar: Best Practices: Software Development Strategies Using Win...RightScale Webinar: Best Practices: Software Development Strategies Using Win...
RightScale Webinar: Best Practices: Software Development Strategies Using Win...
 
RightScale Webinar: Hybrid Cloud Fundamentals and Lessons Learned
RightScale Webinar: Hybrid Cloud Fundamentals and Lessons LearnedRightScale Webinar: Hybrid Cloud Fundamentals and Lessons Learned
RightScale Webinar: Hybrid Cloud Fundamentals and Lessons Learned
 
Integracion Openstack VMware
Integracion Openstack VMwareIntegracion Openstack VMware
Integracion Openstack VMware
 
MultiCloud Bursting from Openstack to Windows Azure and Amazon AWS with Righ...
 MultiCloud Bursting from Openstack to Windows Azure and Amazon AWS with Righ... MultiCloud Bursting from Openstack to Windows Azure and Amazon AWS with Righ...
MultiCloud Bursting from Openstack to Windows Azure and Amazon AWS with Righ...
 
RightScale Webinar: Continuous Integration and Delivery in the Cloud - How Ri...
RightScale Webinar: Continuous Integration and Delivery in the Cloud - How Ri...RightScale Webinar: Continuous Integration and Delivery in the Cloud - How Ri...
RightScale Webinar: Continuous Integration and Delivery in the Cloud - How Ri...
 
How to Operate in the Cloud Using ServiceNow, RightScale and More
How to Operate in the Cloud Using ServiceNow, RightScale and MoreHow to Operate in the Cloud Using ServiceNow, RightScale and More
How to Operate in the Cloud Using ServiceNow, RightScale and More
 

Similar to You, RightScale, and the Universe of Compliance

.NET Architecture for Enterprises
.NET Architecture for Enterprises.NET Architecture for Enterprises
.NET Architecture for Enterprises
Wade Wegner
 
How To Become A Blockchain Engineer
How To Become A Blockchain EngineerHow To Become A Blockchain Engineer
How To Become A Blockchain Engineer
101 Blockchains
 

Similar to You, RightScale, and the Universe of Compliance (20)

Clean Code Software Engineering
Clean Code Software Engineering Clean Code Software Engineering
Clean Code Software Engineering
 
DevSecOps with Microsoft Tech
DevSecOps with Microsoft TechDevSecOps with Microsoft Tech
DevSecOps with Microsoft Tech
 
Tec314
Tec314Tec314
Tec314
 
Tricks for cracking a blockchain expert interview
Tricks for cracking a blockchain expert interviewTricks for cracking a blockchain expert interview
Tricks for cracking a blockchain expert interview
 
WordCamp Nashville: Clean Code for WordPress
WordCamp Nashville: Clean Code for WordPressWordCamp Nashville: Clean Code for WordPress
WordCamp Nashville: Clean Code for WordPress
 
DevOps and the Future of Information Security
DevOps and the Future of Information SecurityDevOps and the Future of Information Security
DevOps and the Future of Information Security
 
Innovation Women Speak! Career Pivot - How to Break into Cybersecurity
Innovation Women Speak! Career Pivot - How to Break into CybersecurityInnovation Women Speak! Career Pivot - How to Break into Cybersecurity
Innovation Women Speak! Career Pivot - How to Break into Cybersecurity
 
Developers are easy to sell to
Developers are easy to sell toDevelopers are easy to sell to
Developers are easy to sell to
 
Software as a craft (February, 2018)
Software as a craft (February, 2018)Software as a craft (February, 2018)
Software as a craft (February, 2018)
 
Using Product Box to Build the Complete Developer
Using Product Box to Build the Complete DeveloperUsing Product Box to Build the Complete Developer
Using Product Box to Build the Complete Developer
 
L'illusione dell'ortogonalità
L'illusione dell'ortogonalitàL'illusione dell'ortogonalità
L'illusione dell'ortogonalità
 
How to Do Kick-Ass Software Development
How to Do Kick-Ass Software DevelopmentHow to Do Kick-Ass Software Development
How to Do Kick-Ass Software Development
 
DOES SFO 2016 - Greg Padak - Default to Open
DOES SFO 2016 - Greg Padak - Default to OpenDOES SFO 2016 - Greg Padak - Default to Open
DOES SFO 2016 - Greg Padak - Default to Open
 
6 Digital Myths Debunked: What it really takes to create a dynamic web presence
6 Digital Myths Debunked: What it really takes to create a dynamic web presence6 Digital Myths Debunked: What it really takes to create a dynamic web presence
6 Digital Myths Debunked: What it really takes to create a dynamic web presence
 
.NET Architecture for Enterprises
.NET Architecture for Enterprises.NET Architecture for Enterprises
.NET Architecture for Enterprises
 
How To Become A Blockchain Engineer
How To Become A Blockchain EngineerHow To Become A Blockchain Engineer
How To Become A Blockchain Engineer
 
Software craftsmanship and you a strong foundation in your team
Software craftsmanship and you a strong foundation in your teamSoftware craftsmanship and you a strong foundation in your team
Software craftsmanship and you a strong foundation in your team
 
[Europe merge world tour] Perforce Europe Merge World Tour Keynote
[Europe   merge world tour] Perforce Europe Merge World Tour Keynote[Europe   merge world tour] Perforce Europe Merge World Tour Keynote
[Europe merge world tour] Perforce Europe Merge World Tour Keynote
 
Lyra Infosystems Services and Consulting Portfolio 2020
Lyra Infosystems Services and Consulting Portfolio 2020Lyra Infosystems Services and Consulting Portfolio 2020
Lyra Infosystems Services and Consulting Portfolio 2020
 
DevOps and the Future of InfoSec
DevOps and the Future of InfoSecDevOps and the Future of InfoSec
DevOps and the Future of InfoSec
 

More from RightScale

More from RightScale (20)

10 Must-Have Automated Cloud Policies for IT Governance
10 Must-Have Automated Cloud Policies for IT Governance10 Must-Have Automated Cloud Policies for IT Governance
10 Must-Have Automated Cloud Policies for IT Governance
 
Kubernetes and Terraform in the Cloud: How RightScale Does DevOps
Kubernetes and Terraform in the Cloud: How RightScale Does DevOpsKubernetes and Terraform in the Cloud: How RightScale Does DevOps
Kubernetes and Terraform in the Cloud: How RightScale Does DevOps
 
Optimize Software, SaaS, and Cloud with Flexera and RightScale
Optimize Software, SaaS, and Cloud with Flexera and RightScaleOptimize Software, SaaS, and Cloud with Flexera and RightScale
Optimize Software, SaaS, and Cloud with Flexera and RightScale
 
Prepare Your Enterprise Cloud Strategy for 2019: 7 Things to Think About Now
Prepare Your Enterprise Cloud Strategy for 2019: 7 Things to Think About NowPrepare Your Enterprise Cloud Strategy for 2019: 7 Things to Think About Now
Prepare Your Enterprise Cloud Strategy for 2019: 7 Things to Think About Now
 
How to Set Up a Cloud Cost Optimization Process for your Enterprise
How to Set Up a Cloud Cost Optimization Process for your EnterpriseHow to Set Up a Cloud Cost Optimization Process for your Enterprise
How to Set Up a Cloud Cost Optimization Process for your Enterprise
 
Multi-Cloud Management with RightScale CMP (Demo)
Multi-Cloud Management with RightScale CMP (Demo)Multi-Cloud Management with RightScale CMP (Demo)
Multi-Cloud Management with RightScale CMP (Demo)
 
Comparing Cloud VM Types and Prices: AWS vs Azure vs Google vs IBM
Comparing Cloud VM Types and Prices: AWS vs Azure vs Google vs IBMComparing Cloud VM Types and Prices: AWS vs Azure vs Google vs IBM
Comparing Cloud VM Types and Prices: AWS vs Azure vs Google vs IBM
 
How to Allocate and Report Cloud Costs with RightScale Optima
How to Allocate and Report Cloud Costs with RightScale OptimaHow to Allocate and Report Cloud Costs with RightScale Optima
How to Allocate and Report Cloud Costs with RightScale Optima
 
Should You Move Between AWS, Azure, or Google Clouds? Considerations, Pros an...
Should You Move Between AWS, Azure, or Google Clouds? Considerations, Pros an...Should You Move Between AWS, Azure, or Google Clouds? Considerations, Pros an...
Should You Move Between AWS, Azure, or Google Clouds? Considerations, Pros an...
 
Using RightScale CMP with Cloud Provider Tools
Using RightScale CMP with Cloud Provider ToolsUsing RightScale CMP with Cloud Provider Tools
Using RightScale CMP with Cloud Provider Tools
 
Best Practices for Multi-Cloud Security and Compliance
Best Practices for Multi-Cloud Security and ComplianceBest Practices for Multi-Cloud Security and Compliance
Best Practices for Multi-Cloud Security and Compliance
 
Automating Multi-Cloud Policies for AWS, Azure, Google, and More
Automating Multi-Cloud Policies for AWS, Azure, Google, and MoreAutomating Multi-Cloud Policies for AWS, Azure, Google, and More
Automating Multi-Cloud Policies for AWS, Azure, Google, and More
 
The 5 Stages of Cloud Management for Enterprises
The 5 Stages of Cloud Management for EnterprisesThe 5 Stages of Cloud Management for Enterprises
The 5 Stages of Cloud Management for Enterprises
 
9 Ways to Reduce Cloud Storage Costs
9 Ways to Reduce Cloud Storage Costs9 Ways to Reduce Cloud Storage Costs
9 Ways to Reduce Cloud Storage Costs
 
Serverless Comparison: AWS vs Azure vs Google vs IBM
Serverless Comparison: AWS vs Azure vs Google vs IBMServerless Comparison: AWS vs Azure vs Google vs IBM
Serverless Comparison: AWS vs Azure vs Google vs IBM
 
Best Practices for Cloud Managed Services Providers: The Path to CMP Success
Best Practices for Cloud Managed Services Providers: The Path to CMP SuccessBest Practices for Cloud Managed Services Providers: The Path to CMP Success
Best Practices for Cloud Managed Services Providers: The Path to CMP Success
 
Cloud Storage Comparison: AWS vs Azure vs Google vs IBM
Cloud Storage Comparison: AWS vs Azure vs Google vs IBMCloud Storage Comparison: AWS vs Azure vs Google vs IBM
Cloud Storage Comparison: AWS vs Azure vs Google vs IBM
 
2018 Cloud Trends: RightScale State of the Cloud Report
2018 Cloud Trends: RightScale State of the Cloud Report2018 Cloud Trends: RightScale State of the Cloud Report
2018 Cloud Trends: RightScale State of the Cloud Report
 
Got a Multi-Cloud Strategy? How RightScale CMP Helps
Got a Multi-Cloud Strategy? How RightScale CMP HelpsGot a Multi-Cloud Strategy? How RightScale CMP Helps
Got a Multi-Cloud Strategy? How RightScale CMP Helps
 
How to Manage Cloud Costs with RightScale Optima
How to Manage Cloud Costs with RightScale OptimaHow to Manage Cloud Costs with RightScale Optima
How to Manage Cloud Costs with RightScale Optima
 

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Recently uploaded (20)

Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 

You, RightScale, and the Universe of Compliance

  • 1. You, RightScale, and the Universe of Compliance Phil Cox Director of Security and Compliance, RightScale
  • 2. 2# SARBANES-OXLEY Massachusetts Privacy Law - 201 CMR 17 Talk with the Experts.
  • 3. 3# We are in a world of transition Talk with the Experts.
  • 4. 4# From Consumerization of IT and BYOD Talk with the Experts.
  • 5. 5# To Arab Summer Talk with the Experts.
  • 6. 6# The world around us is changing technically and it affects us all Talk with the Experts.
  • 7. 7# Compliance standards are slow to catch up Talk with the Experts.
  • 8. 8# PCI - 1.1.3 Requirements for a firewall at each Internet connection and between any demilitarized zone (DMZ) and the internal network zone Talk with the Experts.
  • 9. 9# There is a lot of FUD (Fear, Uncertainty and Doubt) with regards to what you "have to do" to meet them Talk with the Experts.
  • 10. 10# This is my point of view from ~15 years of experience as a Consultant/Assessor and a Practitioner … Talk with the Experts.
  • 11. 11# We’ll identify what the standards and regulations really “Want” Talk with the Experts.
  • 12. 12# We’ll then identify “How” can RightScale help you meet those requirements Talk with the Experts.
  • 13. 13# Side Note You need to know if you are you shooting for “letter of the law” or “intent of the law” compliance Talk with the Experts.
  • 14. 14# And a way we go … Talk with the Experts.
  • 15. 15# Want #1: Governance – Verifiable and Repeatable Talk with the Experts.
  • 16. 16# You have identified business drivers and know what you want to accomplish Talk with the Experts.
  • 17. 17# You have taken the time to document what you want, so it is repeatable Talk with the Experts.
  • 18. 18# You have evidence that you do what you say you do Talk with the Experts.
  • 19. 19# How #1 This is your governance structure. I can chat with you, but this is on you. Talk with the Experts.
  • 20. 20# Want #2 Build it right – Design and Architecture Talk with the Experts.
  • 21. 21# It is entirely possible to design and architect something that is not securable! Talk with the Experts.
  • 22. 22# How #2 Engage RightScale Professional Services We ARE as good as it gets! Talk with the Experts.
  • 23. 23# How #2 The support portal for webinars and whitepapers Talk with the Experts.
  • 24. 24# Want #3 Deploy it correctly and securely Talk with the Experts.
  • 25. 25# How #3 Leverage Multi-Cloud Images, ServerTemplates, RightScripts/Chef Templates Talk with the Experts.
  • 26. 26# Added advantage Meet governance requirements - Documented with version control Talk with the Experts.
  • 27. 27# Want #4 Patch it appropriately Talk with the Experts.
  • 28. 28# How #4 Use RightScale to configure the system to be consistent with your process and policy Talk with the Experts.
  • 29. 29# Want #5 Audit/Watch what is happening Talk with the Experts.
  • 30. 30# How #5 Operational Audit Entries via API or Dashboard Talk with the Experts.
  • 31. 31# How #5 Configure syslog/event logs to your SIEM Talk with the Experts.
  • 32. 32# Want #6 Proactive vulnerability management Talk with the Experts.
  • 33. 33# How #6 Use RightScale to deploy agents (e.g., CloudPassage Halo, TrendMicro Deep Security, etc.) Talk with the Experts.
  • 34. 34# How #6 Use RightScale API to get all active internal and external IP’s regardless of Cloud and feed to Vulnerability Scanner (SAINT, Nessus, etc.) Talk with the Experts.
  • 35. 35# Want #7 Audit and Review Talk with the Experts.
  • 36. 36# How #7 Use the Infrastructure Audit report to show Security Group settings Talk with the Experts.
  • 37. 37# Infrastructure Audit report Talk with the Experts.
  • 38. 38# How #7 Verify Users and Roles Talk with the Experts.
  • 39. 39# Users on an Account Talk with the Experts.
  • 40. 40# Want #8 Incident Response and Management Talk with the Experts.
  • 41. 41# How #8 RightScale gives you a “single view” into your “IaaS world” Talk with the Experts.
  • 42. 42# Want #9 Governance – Evidence Talk with the Experts.
  • 43. 43# How #9 RightScale give you Events, Version Control, Self-Documenting configs Talk with the Experts.
  • 44. 44# Want #10 You tell me … Anything I missed? Talk with the Experts.
  • 45. 45# Questions about RightScale Security? Talk with the Experts.
  • 46. 46# Our “Security Questionnaire Response” is the place to start! Talk with the Experts.
  • 47. 47# Quick Case Study: CareCloud and HIPAA Talk with the Experts.
  • 48. 48# HIPAA data is in datacenter currently Talk with the Experts.
  • 49. 49# Customer needs will require moving HIPAA data to cloud Talk with the Experts.
  • 50. 50# Q: What is the trick? A: No trick, just proper design Talk with the Experts.
  • 51. 51# Punch line: Can do HIPAA in the cloud, just need to design and operate it correctly! Talk with the Experts.
  • 52. 52# Questions? Talk with the Experts.

Editor's Notes

  1. Matt has over 12 years experience operating a variety of different datacenter and cloud environments with a heavy focus on automation, reliability and systems performance.Currently at Nextdoor.com, Matt serves as the primary architect for the Production and Development cloud environments serving thousands of Nextdoor.com private neighborhoods. Before Nextdoor, worked at Netflix in the IT Operations team as the Sr. Systems Architect for an internal cloud project based on Cloud.com and RightScale software/service solutions.
  2. Is VPN internal? What about SSL VPN? What about HTTPS? Can it be internal on a public multi-tenant system?
  3. Big problem is that many of the “checkers” are at odds as to what is the right answer.
  4. Pragmatically is should be the latter, but in reality it is often the former that you will be judged on. Need to keep that in mind.
  5. With that, here we go …
  6. The combination allows the complete automation of a “secure as possible” system and application
  7. Unpatched systems are a MAJOR source of compromise. Using RightScale to ensure that all system are under management correctly is a HUGE win.Question: What percentage of systems that are not running up to date anti-virus?Answer: Zero. There is NO acceptable excuse for out of date softwareSimilarly, there is NO acceptable excuse for a system that is open, unpatched, and unmonitored.Caveat: Mitigating controls – IT IS YOUR RISK ACCEPTANCE – If not patched, then blocked or heavily monitored (pref both)
  8. Trend Micro OSSEC is a good free solution used by manyMany commercial solutions exist: Splunk, QRadar, …
  9. With some pre-planning you could use our API to be able to pull massive forensics data on multiple cloud resources to give you huge gains in the forensics process.
  10. This is available to any current customer or qualified prospect