Computer Science CS654
3
Christopher Slaton_CS654_IP3.doc
Key Assignment Outline
Table of Contents Project Outline (Week 1) 3 Security Requirements (Week 1)…………………………………………………………………………………………………………3 Security Business requirement (Week 2) 3 Security Policy (Week 3) 4 System design principles (Week 4) 4 Training Module (Week5) 4 References 5
Project Outline (Week 1)
The Description of Amazon Web Services (AWS)
The management graph, working group (WG) framework, CMMI model and method region was included in the application of Amazon Web Services ( AWS). Ultimately, the Comprehensive Security Management Plan will be developed and specified by security policy described in AWS.
Jeff Bezos, Chairman and CEO of the multi-billion - dollar corporation, started Amazon in Seattle , Washington in 1994. He began Amazon in a workshop and founded the business today. Amazon has about half a million contractors, spanning from executives to retail workers. Today the organization has a range of branches across the USA, Europe, Asia and South America. Cape Place, Jakarta and Milan will be accessible soon; foreign destinations will also be many other. AWS was founded in 2003 by Andrew R. Jassy, former Senior Vice-President of the Amazon from 1997 to 2003, and is an Amazon.com affiliate (Amazon Web Services, Inc., 2019).
Figure 1.1: The AWS Enterprise Organizational Chart
Figure 1.2: AWS WG Structure
The Security Requirements
The nature of this mutual understanding together provides the customer management and flexibility that enables reading. The confidence distinction is seen in the table below, labeled as "Internet protection" and "Server defense," respectively. The portion of accountability rests in the manner the resources are delivered. The joint accountability concept would be applied to. AWS is responsible for the protection of the facilities controlling the full AWS Cloud service. It is focused on a variety of AWS cloud infrastructure , applications, networking, software and hardware (Amazon Web Services, Inc., 2019).
Amazon Web Services Chief Information Security Officer (CISO) is the leading & promoting voice and its leaders' squad. In order to safeguard branded products and even consumers constructively. Security will now be established and spent in days. Security teams are liable for the various styles of expertise and even forms of thinking in a whole new setting (Amazon Web Services, Inc., 2019).
3
Security Business Requirements (Week 2)
The Summary of Capability Maturity Model Integration
The maturity model incorporation capabilities might be a process and pattern of operation, which could complement the contour of the enterprise, strengthen it and promote profitability. The economic activities and actions which lower the chance of software development , product creation and repair. The CMMI was created by Carnegie Andrew W. Mellon University's Software Package Development Center. It was a way to strengthen the method, departments or organizations. The US Government and the US Department of Defense ( DoD) contributed to the development of the CMMI. The CMMI Institute which was founded by the ISACA is actually managed(White, 2018).
The CMMI Model
The CMMI starts with an associate degree to examine three different areas: the field of operations and maintenance, the business organization and administration and the field of goods and repairs. The goal is to boost efficiency by supplying businesses with what they need to consistently produce the right goods and services.
Nevertheless, the CMMI is a method-based device, usually called an activity-type. Businesses are using the CMMI to address upgraded performance through the development of measurable benchmarks. However, a mechanism to promote constructive and economic actions through the whole organization may also be established (White, 2018).
The Process Areas and the CMMI Model
Amazon network services offer a wide range of global cloud-based products, including storage, reasoning, analysis, networking, mobile applications, developer tools, management tools, IoT, data base, security and corporate apps. Such programs allow businesses to continue to that IT costs to scale faster. AWS is confident of the most leading enterprises, as well as the most up-to - date startups, to provide the right type of working loads, including network and mobile applications (Amazon Web Services, Inc., 2019).
The Grouping Categories for the CMMI PA
The Process of Management
The AWS Management Console * offers the personal computer (PC) or even mobile devices with a secure and easy-to-use web-based style interface with the impeccable range, scope and breadth of the AWS. Explore innovative features, handle the whole portfolio, develop modern apps and more to do with AWS (Amazon Web Services, Inc., 2019).
The Project of Management
The Federal healthcare clients are responsible for the delivery of technical , operational, and body type leadership for their appointed AWS. The management of the work of engineers , architects and even vendors can be achieved throughout the whole life cycle of the cloud computing, implementing, hosting and activities (cost , schedule, effectiveness, threat) (The Consortium, Inc., 2019).
The Engineering Part
The AWS Certified DevOps Engineer is a qualified analysis for people who have a role as DevOps engineer for over 2 years in the supply, operation and management of AWS systems (Amazon Web Services, Inc., 2019).
The Support of the Model
AWS is supporting Amazon's customer obsession tradition in the technological world of Business Two (B2B). We tend to focus on helping you achieve the results you want your company to thrive.
In AWS, help goes beyond break-fixing and problem-fixing. AWS service provides a mix of technologies and resources , services and personnel, tailored to help you constructively boost efficiency, and costs and make the path much easier. Through helping you navigate quicker inside the cloud and focus on the core company, we aim to save time for your team (Amazon Web Services, Inc., 2019).
Security Policy (Week 3)
AWS, as the Department of Defense, is a part of several different regulated public sector industries. Like the Nasdaq, in the financial services sector, too. To pass the assessments, phases, and clearances, the organization must meet some forms of regulatory standards, as well as provide and sustain enforcement to ensure that the top information content is protected and efficient. Therefore, AWS have to and is required by law to obey the appropriate steps, guidelines and also the necessary steps authorized by the DoD and the United States. Governance. (Amazon Web Services, AWS Compliance, 2019)
The policies that Amazon Web Services (AWS0 needs are the SQS Queue Policy, the S3 Bucket Policy, the VPC Endpoint Policy, the IAM Policy, and the SNS Topic Policy.
SQS Queue Policy - Use this policy with AWS account ID, you may allow access or deny access. It requires necessary Send Message and Receive Message authorization. Creating and writing your plans will save time (Amazon Web Services, AWS, 2019).
S3 Bucket Policy - Both this policy and the user style policy are access style policies that allow you the option of being accessible on your own, and you can request permission to your Amazon S3 tools. The two systems use language form for the JSON-based access control (Amazon Web Services, Using Bucket Policies and User Policies, 2019).
VPC Endpoint Policy - It makes for a private link to the supporting AWS operation. This is operated by Private Link and may not need some type of internet portal, some NAT system, a VPN link, or even a direct connection to the AWS (Amazon Web Services, VPC Endpoints, 2019).
IAM Policy - Information governance and AWS individuality are an internet-type tool which allows secure your restricted access to the AWS resources. The AWS compliance code must test if the encryption to sign in is approved and has authorization to do so, ideally or not by the principal (Amazon Web Services, Access Management, 2019).
“SNS Topic Policy - In the Amazon SNS console, you can generate a topic that displays the name of the topic, the ARN, the display name and also the AWS account ID of the Topic owner. The development of an Endpoint subscription enables access to the Subject (Amazon Web Services, Getting Started with Amazon SNS, 2019).
“Detective controls should always be implemented to be able to successfully, accurately, a smoothly process the events, logs, and the monitoring that allow for the automated auditing, analyzation of information. These include the CloudTrail diaries and the CloudWatch, they provide the tracking of specific metrics, and offers configurations for the history (Amazon Web Services, AWS Well-Architected, 2019).”
The data protection method allows unauthorized users to know about a cluster and its data storage structures. It contains information which is stored in permanent files, named resting experience and details which are captured as they travel across the network known as Transit Transit awareness. Starting with Amazon EMR, you can make additional cluster encryption using Amazon EMR security configurations. Security configurations provide the security parameters for Transit knowledge and rest data in Amazon Elastic Block Store (Amazon EBS) and Amazon S3 EMRFS (Amazon Web Services, Encrypt Data at Rest and in Transit, 2019).
The Security Pillar enables the capacity, through risk prevention and control strategies, to protect information, systems, or assets while providing business value (Amazon Web Services, AWS Well-Architected, 2019).
3
REFERENCES Amazon.com, Inc. (2019). Design the next generation of computing. Retrieved from Amazon jobs: https://www.amazon.jobs/en/teams/software-development-engineers-and-managers Hyder, R. (2017, June 27). 10 Design Principles for AWS Cloud Architecture. Retrieved from Botmetric: https://www.botmetric.com/blog/aws-cloud-architecture-design-principles/ Kroonenburg, R. (2018). AWS Certified Solutions Architect Associate 2019. Retrieved from A Cloud Guru: https://acloud.guru/learn/aws-certified-solutions-architect-associate Safari Books Online. (2019). Oreilly. Retrieved from O'Reilly Safari: https://www.oreilly.com/library/view/training-on-the/1562863029/1562863029_ch06lev1sec1.html The Consortium, Inc. (2019). Amazon Web Services (AWS) Cloud Project Manager. Retrieved from The Consortium: http://www.consortiuminc.com/2015/12/amazon-web-services-aws-cloud-project-manager/ White, S. K. (2018, March 16). What is CMMI? A Model for optimizing development processes. Retrieved from CIO: https://www.cio.com/article/2437864/process-improvement-capability-maturity-model-integration-cmmi-definition-and-solutions.html