Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
AWS, Immutable Infrastructure, and PCI
Search
Philip Corliss
September 01, 2016
Programming
0
110
AWS, Immutable Infrastructure, and PCI
Philip Corliss
September 01, 2016
Tweet
Share
More Decks by Philip Corliss
See All by Philip Corliss
Building a Platform on AWS
pcorliss
1
120
Developer Happiness - Building Systems & Tools
pcorliss
0
100
xss
pcorliss
1
330
Other Decks in Programming
See All in Programming
実践ArchUnit ~実例による検証パターンの紹介~
ogiwarat
2
270
SODA - FACT BOOK
sodainc
1
1.1k
WindowInsetsだってテストしたい
ryunen344
1
190
来たるべき 8.0 に備えて React 19 新機能と React Router 固有機能の取捨選択とすり合わせを考える
oukayuka
2
800
コード書くの好きな人向けAIコーディング活用tips #orestudy
77web
3
320
技術懸念に立ち向かい 法改正を穏便に乗り切った話
pop_cashew
0
1.5k
AIコーディング道場勉強会#2 君(エンジニア)たちはどう生きるか
misakiotb
1
230
Go Modules: From Basics to Beyond / Go Modulesの基本とその先へ
kuro_kurorrr
0
120
Spring gRPC で始める gRPC 入門 / Introduction to gRPC with Spring gRPC
mackey0225
2
510
関数型まつりレポート for JuliaTokai #22
antimon2
0
130
F#で自在につくる静的ブログサイト - 関数型まつり2025
pizzacat83
0
310
Java on Azure で LangGraph!
kohei3110
0
150
Featured
See All Featured
A Tale of Four Properties
chriscoyier
159
23k
Bash Introduction
62gerente
614
210k
Building Better People: How to give real-time feedback that sticks.
wjessup
367
19k
Done Done
chrislema
184
16k
Learning to Love Humans: Emotional Interface Design
aarron
273
40k
How to Think Like a Performance Engineer
csswizardry
24
1.7k
Docker and Python
trallard
44
3.4k
How to Create Impact in a Changing Tech Landscape [PerfNow 2023]
tammyeverts
52
2.8k
Code Reviewing Like a Champion
maltzj
524
40k
Code Review Best Practice
trishagee
68
18k
The Invisible Side of Design
smashingmag
299
51k
[RailsConf 2023] Rails as a piece of cake
palkan
55
5.6k
Transcript
AWS, IMMUTABLE INFRASTRUCTURE, AND PCI Slides: https://speakerdeck.com/pcorliss/
WHO IS THIS ? • Philip Corliss • @pcorliss (Gmail,
Twitter, Github) • Cheese Enthusiast • Engineering Manager • Braintree
BraintreePayments.com
Where We Were/Are • Physical Datacenters • Level 1 PCI
DSS Compliant Service Provider
AWS, The Natural Choice • PCI 1 Firewalls, VPCs •
PCI 9 Physical Access • PCI 10.1 Audibility
Immutable Infrastructure • PCI 6.1 Security Patches • PCI 11.5
File Integrity
Scoped Access • PCI 7 Restrict Access
CVVs • PCI 3.2 Do Not Store CVVs
Secrets & KMS
Greenfield Development
S3 Isn’t Near-Line Storage PCI 10.7 Retain audit trail history
for at least one year, with a minimum of three months immediately available for analysis (for example, online, archived, or restorable from backup).
VPCs • PCI 4: Encrypt Data Across Public Networks
Huge Wins
Evolving Platform
WHO’S THIS GUY? • Philip Corliss • @pcorliss (Gmail, Twitter,
Github) • Cheese Enthusiast • Engineering Manager • Braintree