How To Design A Least Privilege Architecture in AWS Slides
How To Design A Least Privilege Architecture in AWS Slides
Architecture in AWS
Sponsored by
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
AWS services that enable network segmentation
AWS Identity
and Access
Investigate
Management
AWS Well-
AWS Firewall
Architected
Tool
Manager
Amazon
Detective
Snapshot Archive
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Implementing least privilege with AWS IAM Access Analyzer
Account
Resource-based policies Findings
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Leveraging VPC Traffic Mirroring for network segmentation
Remote
AWS Cloud Administration
VPC Internet
traffic
Traffic
eth0 Mirroring ens5
eth1 ens6
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
How are AWS customers leveraging Palo Alto Networks?
Provide complete
visibility into traffic
through Layer 7
Enforce policies
consistently to aid
segmentation
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Western Asset Management mitigates risk
With Prisma Cloud by Palo Alto Networks
Benefits:
• Full network visibility
• Incident and
misconfiguration
response times reduced
from days to minutes
• Built-in compliance
reporting eliminates
manually sifting through
audit files
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
FNTS achieves secure network segmentation
Utilizing VM-series firewalls by Palo Alto Networks
Benefits:
• Enhanced protection of
inbound, outbound, and
east-west network traffic
• Achieved a single,
consistent management
console across entire
environment
• Gained ability to auto-
scale provisioning and
de-provisioning
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Epsilon boosts network visibility and control
Leveraging Aviatrix’s Secure Networking Platform
Benefits:
• Increased visibility and
troubleshooting
• Established profile-based
remote user access
control
• Secured connectivity
between Amazon VPCs
and on-premises
resources
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Vonage prevents lateral threats
Using Edgewise Zero Trust Auto-Segmentation
Benefits:
• Fully automated micro-
segmentation
• Environment can now be
mapped out in 20
minutes vs. 2 months
• Increased lateral
protection across its
networks
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Why AWS Marketplace?
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
How can you get started?
Find Buy Deploy
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Webinar summary
Leverage AWS Services that integrate with your AWS environment and can
enhance your network segmentation capabilities.
Current tools? Bring your own license to leverage benefits of AWS Marketplace.
New tools? Select solutions in AWS Marketplace for a curated list proven on AWS.
© 2020, Amazon Web Services, Inc. or its Affiliates. All rights reserved.
Q&A
Please use GoToWebinar’s
Questions tool to submit
questions to our panel.