Slide 1

Slide 1 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Aurangabad (Chh. Sambhajinagar) 2023 Venue Sponsor

Slide 2

Slide 2 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Security Incident Response By: Sankalp Sandeep Paranjpe Aurangabad (Chh. Sambhajinagar) 2023

Slide 3

Slide 3 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AGENDA Aurangabad (Chh. Sambhajinagar) 2023 Introduction to Cybersecurity Security controls, procedures and practices Shared Responsibility Model Amazon GuardDuty and Inspector Incident Response

Slide 4

Slide 4 text

WHOAMI © 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Cloud Captain Final year B.Tech student at MIT ADTU Pune Cloud Security, Application Security 2X AWS Certified EC Council CEH-Practical Certified Sankalp Sandeep Paranjpe

Slide 5

Slide 5 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. AWS Shared Responsibility Model

Slide 6

Slide 6 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. What is a security incident? Event Any observable occurrence in your IT infrastructure File created on a system The user logged in to the system System shut down Incident An Event that negatively affects IT systems and impacts the business System out of memory/disk Power/hardware failure Host/network unreachable Security Incident potentially jeopardizes the CIA Triad of an information system Malware installed on a system Unauthorized access to system Software vulnerability exploited

Slide 7

Slide 7 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Incident Response Aurangabad (Chh. Sambhajinagar) 2023

Slide 8

Slide 8 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Aurangabad (Chh. Sambhajinagar) 2023 Incident response refers to an organization’s processes and technologies for detecting and responding to – cyber threats, security breaches cyberattacks. The goal of Incident Response: To prevent cyberattacks

Slide 9

Slide 9 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Aurangabad (Chh. Sambhajinagar) 2023

Slide 10

Slide 10 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Define the vision, mission, and scope of incident response. Obtaining Management Approval and funding Assess the organizational structure, and security policies and develop an Incident response plan. Developing procedures and building IR Team. Prioritize assets and infrastructure Preparation

Slide 11

Slide 11 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Incident Recording Incident Triage Incident analysis Incident Classification Incident Prioritization Detection and Analysis

Slide 12

Slide 12 text

Containment Disabling the compromised service or system Changing passwords or disabling Accounts Gathering of evidence Forensic Analysis of Evidence

Slide 13

Slide 13 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Eradication of the root cause of the incident. Implement protection tools and techniques such as Firewalls etc. System Recovery after the eradication of incidents. Eradication and recovery

Slide 14

Slide 14 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.

Slide 15

Slide 15 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved.

Slide 16

Slide 16 text

© 2018, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Image caption 1 Image caption 2 Image caption 3 Image caption 4 Image caption 5 Image caption 6 Aurangabad (Chh. Sambhajinagar) 2023 Let's Connect: https://www.linkedin.com/in/sankalp-s-paranjpe/ https://twitter.com/SankalpParanjpe Thank you!