AWS Boulder - Denver Meetup – January 2017 11/24/2018 IT Governance with AWS AWS Boulder - Denver Meetup – January 2017 Mike Reese, Solution Architect
IT Governance (ITG) “The processes that ensure the effective and efficient use of IT in enabling an organization to achieve it’s goals” – Gartner IT Glossary
Why it’s important Risk Management Aligning IT goals with those of the business Making IT a key element of the business strategy Aid in compliance Optimize IT operations Performance management Elevating IT above a cost center Improved communication across business units
What it entails Mapping IT initiatives to business objectives Does the project support the goals of the business? Implementing best practices Facilitating the alignment of priorities between IT and business units Effective resource management
Governance Models Centralized vs Local vs Distributed GOOD BEST There’s no one, perfect model Understand the operating model of the business Determine which processes are core to the business Consider the business culture BETTER “centralize for efficiency, decentralize for effectiveness” Michael Pilkington Former CIO of Euroclear
Governance in AWS Understand the AWS Shared Responsibility Model 11/24/2018 Governance in AWS Understand the AWS Shared Responsibility Model Understand the organization’s compliance requirements Establish a set of controls to meet compliance objectives Implement policies and procedures to validate compliance Continually monitor the effectiveness of the compliance controls
AWS Governance Best Practices Access control and IAM configuration Standard users and or groups Cross-account and/or federated roles EC2 instance roles S3 and shared resource roles Security requirements
AWS Governance Best Practices Amazon VPC configuration and networking The number of VPCs per AWS account The subnet structure within a VPC The use of multiple availability zones (Azs) Connectivity options: internet gateways, virtual private gateways, routing
AWS Governance Best Practices Resource tagging Define common keys and expected values across all accounts Enforce tagging through auditing and automation Implement automatic tagging via an automated deployment strategy
AWS Governance Best Practices AMI creation and management Preconfigure for host-based security software and OS hardening Avoid including customized software and configurations that might change frequently
AWS Governance Best Practices AWS CloudTrail AWS CloudWatch Centralized Logging Notifications AWS Config
AWS Governance Best Practices Development of a shared services VPC