Security and Compliance Services Flashcards
What is the Customer responsible for in the Cloud
Managment of guest OS, customer data, IAM, NACL, client and server side encryption
What is AWS responsible for of the Cloud
Setup and maintenance of physical hardware, maintenace of host virtualisation software, compute, storage, database, networking, global infrastructure (regions, az and edge locations)
DDoS and penetration testing
AWS customers can do this without prior approval. They cannot however do DNS zone walking, DDoS and floodings.
CloudFront and Route 53 aid in DDoS mitigation
Other AWS Security Services
- AWS Org = centralised management of AWS accounts and billings
- Amazon GuardDuty = Threat detection
- Amazon Inspector = Analyses VPC environment for potential security issues (gives findings and recommendations)
- AWS Shield = Managed DDoS protection
- WAF = Monitors web requests (can allow/deny access)
- AWS Artifact = Portal access to AWS compliance docs e.g PCI and ISO
What is AWS Key Management Service
Encryptes data and provided key storage. Keys can be made in KMS, CloudHSM or imported. KMS integrates with S3, Databases, CloudTrail and SNS
Other Services?
Amazon Athena = Serverless sql service
Amazon EMR = Managed Hadoop framework, big data
Amazon Lightsail = private virtual server with prepackaged setups
Amazon Rekognition = Video/image analysis
Amazon Mech Turk = crowdsourced marketplace