Presentation is loading. Please wait.

Presentation is loading. Please wait.

Ensure your cloud is secure and well-managed

Similar presentations


Presentation on theme: "Ensure your cloud is secure and well-managed"— Presentation transcript:

1 Ensure your cloud is secure and well-managed
9/12/2018 6:26 AM Ensure your cloud is secure and well-managed With Azure security and operations management Customer-ready deck Opening statement (Introduce yourself) Today we will talk about how you can take simple steps to ensure that your Azure cloud resources are secure and well-managed with Azure security and operations management services that are built-in within Azure. Speaker Title © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

2 Cloud security and management requires a more proactive approach
Proliferation of new cloud users Need better visibility and control Cloud security and management requires a more proactive approach Increasingly sophisticated threats Need more advanced security solutions Cloud security and management requires a more proactive approach Cloud adoption is driving major changes in IT security and management. Let’s look at some of the key drivers for the changes and how we should respond. There is a proliferation of new cloud users. Within companies, business units and developers (defined as cloud users) are leveraging cloud to drive business innovation and agility. And, they are seeing amazing results. However, cloud security and management is not always top-of-mind for them and often is an after- thought, which increases the company’s exposure to unnecessary cloud risks. The central IT & security teams (and cloud users) need to have better visibility and control over cloud environments across the company to minimize risks, while continuing to enable business innovation. Increasingly sophisticated threats Attacks on cloud infrastructure are becoming more sophisticated and automated, often infiltrated onto networks in stages and lying inert before finding a vulnerable moment to attack, making them harder to detect. To respond to these threats, organizations need security solutions that 1) are more robust and intelligent, 2) can assess the cloud security state continuously and provide real-time alerts, 3) can detect, diagnose, and respond to threats quickly. Dynamic cloud environments Cloud resources are quickly spun up or down to enable faster time to market, meet seasonal customer demand, or maximize resource utilization and stay cost effective. Additionally, DevOps processes and practices leverage the cloud to enable agile software development through deployment of infrastructure as code, continuous testing, integration, and delivery, etc. As a result, organizations need a more agile and continuous approach to monitor and manage cloud environments and resources to ensure cloud health and performance, maximize resource utilization, and eliminate waste. Dynamic cloud environments Need continuous and agile management approach © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

3 It’s also a joint responsibility between Microsoft and the customer
9/12/2018 6:26 AM It’s also a joint responsibility between Microsoft and the customer MICROSOFT’S COMMITMENT JOINT RESPONSIBILITY Securing and managing the cloud foundation Securing and managing your cloud resources Physical assets Virtual machines It’s also a joint responsibility between Microsoft and the customer Securing and managing your cloud is a joint responsibility, shared between you and Microsoft. Our (Microsoft’s) commitment is to securing and managing the cloud foundation through: Security and management of physical assets: Multiple layers of physical protection from the perimeter to buildings to computer rooms State-of-the-art security controls such as video coverage, biometrical authentication, verified single- person entry Provisioning and maintenance of all the hardware. Datacenter operations security and management: Security operations center, with 24x7x365 security operations. Comprehensive and quick incident assessments. Continuous monitoring by security experts. Cloud infrastructure security and management: Secure multi-tenancy DDos defense system Data segregation and encryption And it’s a joint responsibility to secure and manage your cloud resources in an IaaS model. Customers have the responsibility to keep their virtual machines, applications and workloads, and data secure and well-managed. And Microsoft provides the tools natively to make it easy for you to secure and manage your cloud resources. Now let me show you how you can take simple steps to keep your Azure resources secure and well- managed. Datacenter operations Apps and workloads Cloud infrastructure Data © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

4 Azure gives you simple ways to secure and manage your cloud
9/12/2018 6:26 AM Azure gives you simple ways to secure and manage your cloud Secure your cloud resources Protect your data in the cloud Monitor your cloud health Azure gives you simple ways to secure and manage your cloud There are three simple things you can do: Secure your cloud resources such as virtual machines, workloads, and apps with Azure Security Center. Protect your data in the cloud with Azure Backup, and Continuously monitor your cloud health with Azure Log Analytics. For the rest of this presentation, I am going to show you how to accomplish this. First, we’ll walk through securing cloud resources with Azure Security Center. Azure Security Center Azure Backup Azure Log Analytics © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

5 Secure your cloud resources
Microsoft Worldwide Partner Conference 2016 9/12/2018 6:26 AM Secure your cloud resources Azure Security Center Gain full visibility and control of your cloud security state Proactively identify and mitigate risks to reduce exposure to attacks Secure your cloud resources with Azure Security Center With Azure Security Center you can gain full visibility and control of your cloud security state with a single, unified view: Collect security data from multiple sources: Collect, search, and analyze security data from a variety of sources, including connected partner solutions like network firewalls and other Microsoft services. Integration with existing security workflows: Access, integrate, and analyze security information using REST APIs to connect existing tools and processes. Easily onboard cloud resources: Keep pace with rapidly changing cloud workloads. Automatically discover and onboard new resources created in your Azure subscriptions. Continuous security assessment: monitor the security of virtual machines, networks, and Azure services using hundreds of built-in security assessments or create your own. Built-in dashboards provide instant insights into security issues that require attention. Centralized policy management: Ensure compliance with company or regulatory security requirements by centrally managing security policies across all your cloud workloads. Compliance reporting: Use security data and insights to demonstrate compliance and easily generate evidence for auditors. (If asked whether Azure Security Center supports hybrid workloads, the answer is yes: manage security across all your hybrid cloud workloads – on-premises, Azure, and other cloud platforms – in one console.) You can also identify and mitigate risks proactively to reduce your exposure to security threats: Proactive security assessment: Identify software and configurations that are vulnerable to attack. Actionable recommendations: Remediate security vulnerabilities before they can be exploited by attackers with prioritized, actionable security recommendations and built-in automation playbooks. Adaptive application controls: Block malware and other unwanted applications by applying whitelisting recommendations adapted to your specific workloads and powered by machine learning. Controlled network access: Reduce the network attack surface with just-in-time, controlled access to management ports on Azure VMs, drastically reducing exposure to brute force and other network attacks. Azure Security Center has robust capabilities to prevent attacks. When threats do happen, Security Center can quickly detect and respond to threats with advanced analytics and Microsoft Intelligent Security Graph. Industry’s most extensive threat intelligence: Tap into the Microsoft Intelligent Security Graph, which uses trillions of signals from Microsoft services and systems around the globe to identify new and evolving threats. Advanced threat detection: Use built-in behavioral analytics and machine learning to identify attacks and zero-day exploits. Monitor networks, machines, and cloud services for known attack patterns and post- breach activity. Prioritized alerts and incidents: Focus on the most critical threats first with prioritized security alerts and incidents that map alerts of different types into a single attack campaign. Create your own custom security alerts as well. Streamlined investigation: Quickly assess the scope and impact of an attack with a visual, interactive experience. Use predefined or ad hoc queries for deeper exploration of security data. Contextual threat intelligence: Visualize the source of attacks on an interactive world map. Use built-in threat intelligence reports to gain valuable insight into the techniques and objectives of known malicious actors. Quickly detect and respond to threats with advanced analytics © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

6 MONISH DARDA Co-founder and Chief Technology Officer
ICERTIS “The prospect of having a single dashboard where we can prevent, detect, and respond to threats with increased visibility and control over our resources was very exciting… Today, our operations team saves at least 30 percent of its time by using Azure Security Center.” Microsoft Envision 2016 9/12/2018 6:26 AM Icertis customer story ( Company introduction: Icertis is the leading enterprise contract management provider in the cloud and solves the hardest contract management problems on the easiest to use platform. Challenges: The Icertis Contract Management Platform holds some of the most sensitive data such as personally identifiable information (PII), the terms of employee and sales contracts, and details of partner and vendor relationships. Security of the platform and data is a top of mind for its customers. Solution: Icertis runs their Contract Management Platform on Azure and boosts its security with Azure Security Center. Impact: The security of the Icertis Contract Management Platform has become a competitive advantage. “We have found that having a proven security solution from Microsoft makes a big difference to our customers and is a key differentiator in the value we provide our customers.” With Azure Security Center, Icertis simplifies and strengthens security monitoring, applies more granular security policies, and leverages advanced threat protection. “Security begins with data encryption, and we support customers bringing their own encryption keys, using Azure Key Vault. And when it comes to securing our infrastructure and applications, Azure has been very strong there, with built-in compliance with data center security standards such as ISO and SOC 1 and 2, and HIPAA. And without the new Microsoft datacenters at Frankfurt and Magdeburg in Germany, we wouldn’t have been able to offer ICM on Azure to German customers.” © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

7 Azure Security Center demo
Microsoft Worldwide Partner Conference 2016 9/12/2018 6:26 AM Azure Security Center demo Azure Security Center demo Now let me show you what this looks like. © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

8 Azure gives you simple ways to secure and manage your cloud
9/12/2018 6:26 AM Azure gives you simple ways to secure and manage your cloud Secure your cloud resources Protect your data in the cloud Monitor your cloud health Azure gives you simple ways to secure and manage your cloud Now let’s talk about protecting your data in the cloud with Azure Backup. Azure Security Center Azure Backup Azure Log Analytics © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

9 Protect your data in the cloud
Microsoft Worldwide Partner Conference 2016 9/12/2018 6:26 AM Protect your data in the cloud Azure Backup Protect against ransomware and human errors Meet compliance goals with data retention and encryption Protect your data in the cloud with Azure Backup Protect against ransomware and human errors Protecting against ransomware is top of mind for every chief security officer and security professional. Cybersecurity Ventures predicts global ransomware damage costs will exceed $5 billion in 2017 and will continue to grow. That’s a 15X increase from 2015. In addition to malware and malicious attacks, data also gets corrupted or lost due to human errors, such as coding an application incorrectly or inadvertently striking the wrong computer key. Studies show about 30% or more of data corruption or loss is caused due to human errors, right behind the data loss caused by malicious attacks. The good news is that Azure Backup helps you protect against ransomware and human errors. Some features to highlight: Enable just-in-time access for authorized users based on multifactor authentication to prevent unauthorized use. Monitor backup activities so you can detect anomalies and issues. Retain deleted backup data for up to 14 days so you can easily recover data corrupted due to human errors. Store your backup data in any Azure region around the globe to meet your risk mitigation strategy while keeping your data close to your branch offices for fast recovery. Meet compliance goals with data retention and encryption Azure has the most comprehensive compliance portfolio available. Enjoy up to 99 years of retention for your backup data. Your backup data is encrypted in transit and at rest. Start backup in minutes and restore data quickly when needed Choose Backup from the VM blade and set up your backup in minutes with three simple steps. Only pay for what you use, and restore data with no additional costs. Quickly restore your data to minimize business interruption with 99.9% service availability. Restore individual files or folders or the entire VM based on your business needs. Start backup in minutes and restore data quickly when needed © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

10 “The Azure Backup dashboard… makes it easier to monitor our cloud-based backups. Our staff is very busy—and now they can work on more valuable tasks than babysitting backup servers, which adds no value to the business.” KEREM KARABIBER IT and Business Development Manager Kardem Microsoft Envision 2016 9/12/2018 6:26 AM Kardem customer story Kardem is a Turkish garment manufacturer with a global supply chain that relies as much on data as on designs and dyes. Recently, the company moved to an integrated on-premises and cloud backup solution using Microsoft System Center 2012 R2 Data Protection Manager and Microsoft Azure Backup. With this solution, Kardem gains more reliable, scalable, and cost-effective data backup, which translates into a stable foundation for business expansion. © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

11 Microsoft Worldwide Partner Conference 2016
9/12/2018 6:26 AM Azure Backup demo Azure Backup demo Let’s walk through how Azure Backup backs up and restores your data © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

12 Azure gives you simple ways to secure and manage your cloud
9/12/2018 6:26 AM Azure gives you simple ways to secure and manage your cloud Secure your cloud resources Protect your data in the cloud Monitor your cloud health Azure gives you simple ways to secure and manage your cloud Now, we’ll show you how to monitor your cloud health with Azure Log Analytics. Azure Security Center Azure Backup Azure Log Analytics © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

13 Monitor your cloud health
Microsoft Worldwide Partner Conference 2016 9/12/2018 6:26 AM Monitor your cloud health Azure Log Analytics Collect and store your data from any source Gain deep operational insights Monitor your cloud health with Log Analytics Collect and store your data from any source Easily collect, store, and analyze your systems and operational data from any source, both on-premises and in the cloud. Collect data from a wide range of sources including virtual machines, storage accounts, activity logs, Windows, Linux Servers, Java, .NET, legacy and modern apps. Centrally store activity logs, network logs, infrastructure metrics, app data points, diagnostics logs and alerts. Gain deep operational insights Understand CPU disk and memory utilization for your virtual machines. Get a comprehensive view of applications and network dependencies across multiple virtual machines to perform root-cause analysis more quickly. Track configuration changes, system updates, and malware status to improve security & compliance. Visualize data in intuitive and customizable dashboards. Find the information you need quickly using interactive queries and full-text search. Detect, diagnose and fix issues quickly Get notifications and alerts with rich diagnostic information so you can always stay on top of the issues. Separate the signal from the noise and accelerate root-cause analysis across platforms using advanced analytics including machine learning algorithms. Automate the implementation of recommended fixes so you can address issues quickly. Integrate with customer service systems such as your ticketing tool to speed up implementation of fixes. Detect, diagnose, and fix issues quickly © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

14 “Our internal technicians are gaining greater insight into our environment. This helps us fix potential future issues and enables us to develop monitoring scripts to prevent similar issues from ever happening again. It’s a process of continued improvement.”  HARRY FAAS Associate Directory of Business Systems Support Massey University Microsoft Envision 2016 9/12/2018 6:26 AM Massey University customer story it-support-for-i2 New Zealand’s Massey University wanted better insights into IT operations and a more proactive, centralized way to manage its sprawling infrastructure as a single ecosystem. To manage its disparate IT environment more efficiently, Massey implemented the Microsoft Operations Management Suite with Azure monitoring tools, and began connecting servers to the cloud to gain real-time insight and get alerts about performance. Operations Management Suite works with Microsoft System Center Operations Manager to provide a unified view of IT infrastructure and enable proactive maintenance. Even after loading only five servers—a fraction of its environment—the university gained impressive feedback. Massey now has 60 servers loaded, with more to come. Now, with System Center Operations Manager, Massey IT staff can perform sophisticated network analysis in minutes, reducing the university’s reliance on external troubleshooters and cutting the time it takes to solve problems in half. © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

15 Microsoft Worldwide Partner Conference 2016
9/12/2018 6:26 AM Azure Log Analytics demo Log analytics demo Let me show you how to monitor your cloud health with Log Analytics © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

16 Pricing model Fee only for consumption; no upfront licensing fees
9/12/2018 6:26 AM Pricing model Fee only for consumption; no upfront licensing fees Same Azure invoice, monetary commitment, subscriptions Competitive pricing For detailed pricing of each service, use Azure Pricing Calculator azure.com/pricing/calculator Pricing model In terms of pricing for the services I just walked you through, they are all built-in Azure services. Like other Azure services, you only pay for how much you use—no upfront licensing fees. You use the same Azure invoice, monetary commitment, and subscriptions to make it easy for you. Our pricing is also competitive. For detailed pricing of each service, use our Azure Pricing Calculator to see how Azure can save you money. © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

17 9/12/2018 6:26 AM Azure has a full set of services to meet all your security and management needs Secure Security Management Threat Protection Built in Intelligent Hybrid Govern Protect Policy Management Cost Management Backup Disaster Recovery Azure has a full set of services to meet all your security and management needs I just walked you through the three services that get you started to easily to secure and manage your Azure resources. However, I understand there is a lot more you need to manage and secure in your IT environment, both in the cloud and on-premises. Your job is complex and challenging. We have a whole set of tools natively in Azure to help you manage the full lifecycle of security and management. We covered Security capabilities protecting your data – besides Azure Backup we also discussed how Azure Site Recovery helps in disaster recovery. In Monitoring, we are bringing all the monitoring capabilities together in Azure Monitor, including Application Insights, Log Analytics, Network Watcher, and other monitoring tools. We also have tools for configuration, patching, automation, and PowerShell scripting. We have new exciting tools in the Governance area. Azure Policy, in limited preview, helps you centrally manage your policies. Azure Cost Management, previously known as Cloudyn, helps organizations manage and optimize cloud spend across a multi-cloud environment. Plus, they’re all built in to our platform so you don’t have to worry about 3rd party integration. The services are intelligent – gathering rich intelligence about your cloud infrastructure and resources with advanced analytics and machine learning algorithms, and are hybrid—extending security and management capabilities from cloud to your on-premises environment. Configure Monitor Configuration Update Management Automation Scripting App, Infra, and Network Monitoring Log Analytics & Diagnostics © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

18 Take actions today To learn more, visit azure.com/securewellmanaged
9/12/2018 6:26 AM Take actions today Simply turn on… Azure Security Center Azure Backup Azure Log Analytics …on every production instance. Take actions today It’s easy to get started. To ensure your Azure environment is secure and well-managed, simply turn on Azure Security Center, Azure Backup, and Log Analytics on every production virtual machine. To learn more, visit Azure.com/securewellmanaged To learn more, visit azure.com/securewellmanaged © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

19 Thank you

20

21 Appendix

22 “We get consistent levels of infrastructure security with Azure because we can leverage a wealth of security technologies that Microsoft is constantly improving. We use Azure Security Center to monitor our environment, and with it we can be much more responsive when threats are identified.” HAROLD GROOTHEDDE Technology Solutions Director COATS Microsoft Envision 2016 9/12/2018 6:26 AM Coats customer story Azure Security Center is one of the products Coats used to improve security of their cloud environment © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

23 “We know that if we lost our database, we would have it back up and running in a few minutes at most with Azure Backup. That is very compelling for our business.” FREDRIK ELMQVIST IT Systems Architect, Security & Defense Solutions Saab Microsoft Envision 2016 9/12/2018 6:26 AM Saab customer story SAFE is a security management platform for customers worldwide provided by the security and defense company Saab. The organization wanted to use SAFE for event security, and needed technology that could be quickly deployed and used to back up and restore customer data. SAFE was implemented on Microsoft Azure, using the Microsoft SQL Server Backup to Azure Tool, in order to back up data in minutes. It also offers fast deployment, eliminating the need for additional hardware, and scales to support thousands of users. © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

24 CHRIS PALMER Solutions Architect
PLC Construction “… give us a single monitoring and management plane for all our environments—multiple Rackspace datacenters and Azure and customer datacenters—so we know exactly what’s going on with our Windows and open source workloads, wherever they run.” Microsoft Envision 2016 9/12/2018 6:26 AM Rackspace customer story Rackspace, one of the biggest names in managed hosting, prides itself on providing customers with Fanatical Support, which means the uniquely best cloud solution and experience for every customer. However, the most security-conscious organizations would not host with Rackspace (or anyone) out of concern that Rackspace administrators could access their data. With the introduction of the Windows Server 2016 operating system, Rackspace was able to put that sales-blocker to rest. Using Shielded Virtual Machines and the Nano Server installation option in Windows Server 2016—augmented by Microsoft System Center 2016 and Microsoft Operations Management Suite for better security monitoring—Rackspace can move customers into a private cloud with the highest level of security assurance. And help them reap all the economic and scalability benefits of cloud computing. © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.


Download ppt "Ensure your cloud is secure and well-managed"

Similar presentations


Ads by Google