Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Transform Enterprise Security Operations and Co...

Transform Enterprise Security Operations and Compliance with Amazon Frontier Agents

This session, presented at AWS Summit Shanghai 2026, shows how Amazon frontier agents reconstruct cloud security operations and compliance. Faster releases cause config drift, and machine accounts outnumber humans 100-to-1, burying teams in alert storms. We combine three agents: a customized AWS DevOps Agent that unifies DevOps, SOC, and compliance — automating 90%+ of Tier-1 alerts; a Bedrock and Nova evidence-collection agent that cuts evidence time 70%+; and Amazon Security Agent for AI-driven penetration testing. Together they enable point-in-time compliance and shorten PCI DSS certification by months. You'll learn the methodology and architecture to bring continuous, AI-driven compliance and SOC into your own work.

Avatar for Shaoyi Li

Shaoyi Li

June 28, 2026

More Decks by Shaoyi Li

Other Decks in Technology

Transcript

  1. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 ©

    2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 Solutions Architect Amazon Web Services Zhanteng Zhang Shaoyi Li Lead Cloud Engineer PAX Technology Kate Huang Transform Enterprise Security Operations and Compliance with Amazon Frontier Agents BD Manager Amazon Web Services
  2. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 •

    Pain Points in Security Compliance Certification • Compliance Efficiency: Traditional Approach vs. Amazon Frontier Agents • How Amazon Frontier Agent Reconstruct the Security Operations and Compliance Solution • Summary Agenda
  3. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 AWS

    Helps Customers Meet Global Compliance Requirements Alignments & frameworks CIS (Center for Internet Security) CJIS (US FBI) 🇺🇸 CSA (Cloud Security Alliance) Esquema Nacional de Seguridad 🇪🇸 EU-US Privacy Shield 🇪🇺 FISC 🇯🇵 FISMA 🇺🇸 G-Cloud 🇬🇧 GxP (US FDA CFR 21 Part 11) 🇺🇸 ICREA IT Grundschutz 🇩🇪 MITA 3.0 (US Medicaid) 🇺🇸 MPAA 🇺🇸 NIST 🇺🇸 Uptime Institute Tiers Cloud Security Principles 🇬🇧 BioPhorum IT Controls Certifications & attestations Cloud Computing Compliance Controls Catalogue (C5) 🇩🇪 Cyber Essentials Plus 🇬🇧 DoD SRG 🇺🇸 FedRAMP 🇺🇸 FIPS 🇺🇸 IRAP 🇦🇺 ISO 9001 ISO 27001 ISO 27017 ISO 27018 MLPS Level 3 🇨🇳 MTCS 🇸🇬 PCI DSS Level 1 SEC Rule 17-a-4(f) 🇺🇸 SOC 1, SOC 2, SOC 3 ⾏业或国际标准 https://aws.amazon.com/compliance/programs/ Laws, regulations and privacy CISPE 🇪🇺 GDPR 🇪🇺 FERPA 🇺🇸 GLBA 🇺🇸 HIPAA 🇺🇸 HITECH IRS 1075 🇺🇸 ITAR 🇺🇸 My Number Act 🇯🇵 Data Protection Act – 1988 🇬🇧 VPAT / Section 508 🇺🇸 Data Protection Directive 🇪🇺 Privacy Act [Australia] 🇦🇺 Privacy Act [New Zealand] 🇳🇿 PDPA - 2010 [Malaysia] 🇲🇾 PDPA - 2012 [Singapore] 🇸🇬 PIPEDA [Canada] 🇨🇦 Agencia Española de Protección de Datos 🇪🇸
  4. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 Four

    Core Pain Points in Compliance Certification Configuration Drift Continuously Degrades Compliance Status Each release version involves hundreds of changes, all accompanied by configuration drift. Documentation alone cannot reflect the current real compliance status. Examples include temporarily opening security groups, S3disabling S3 encryption, etc. Alert Storms Overwhelm SOC Real Threats Non-human accounts outnumber humans by 100 x, generating thousands of low-value alerts daily, making it impossible for security teams toaccurately and effectively identify real security incidents. Manual Screenshots and Form-Filling Are the Most Time-Consuming Step Traditional audits require manually capturing screenshots across 10+ systems, with each cycle taking 6~8 weeks, with results that vary by person and are difficult to reproduce. Security Testing Is Difficult to Scale and Sustain For example,PCI DSS requires human-led adversarial testing, but traditional methods conduct it only once a year, severely misaligned with CI/CD cadence, allowing vulnerabilities topersist.
  5. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 Data

    Source: Industry Average from PCI DSS Level 1 Service Provider with completed ROC Traditional Model Scoping 3 weeks Gap Assessment 5 weeks Remediation 12 weeks Evidence Collection 7 weeks Formal Assessment 6 weeks Continuous Monitoring 4 weeks AI-Native Scoping 2 weeks Gap Assessment 2 weeks Remediation 5 weeks Evidence Collection 1 week Formal Assessment 5 weeks Continuous Monitoring 4 weeks ≈ 37 weeks ≈ 19 weeks Compliance Efficiency: Traditional Approach vs Amazon Frontier Agents PCI DSS Level 1 ROC takes 6 ~ 9 months. After introducing AI Agent, evidence collection time reduced by ~70% , remediation time reduced by ~60%, and the overall cycle shortened by 4 months
  6. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 Compliance

    Certification Trends in AI Era Organizations must not only provide compliance evidence during annual audits, but also be able to demonstrate through continuous evidence that security controls remain effective during any ad-hoc audits. ─── We call this capability as Point-in-Time Compliance Compliance as Code: Making Drift Instantly Visible and Automatically Fixed Compliance as Code Continuous Compliance Real-Time Configuration Check, Generating Compliance Reports Drift as Security Findings, Unified Visualization Automation Runbook Auto-Remediation
  7. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 DevOps,

    SOC and Compliance in a Single AI Agent · MCP Unified Access to Cloud Telemetry Extend the Amazon DevOps Agent event analysis capabilities to SOC through MCP, covering GuardDuty, Macie, Security Hub and other services. · Tier 1 Alert Second-Level Triage 90%+ low-value alerts automatically triaged, enabling security teams to focus on real threats and threat hunting. · Remediation Lambda Auto- Orchestration Actions such as isolating EC2 instances, revoking IAM keys, and remediating S3 public exposure are completed in minutes.
  8. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 AI

    Driven Evidence Collection: Compressing Weeks to Hours · Browser Extension-Based Agent Built on Amazon Bedrock + Amazon Nova, the evidence collection Agent can run on any Web console Agent. · Document-Driven Executable Workflow The Agent automatically parses and generates cross-system execution workflow steps based on uploaded compliance requirement documents. · Timestamped and Traceable Evidence Collected results are stored in S3, uniformly archived and distributed via email, with one-click review for QSA.
  9. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 Internal

    Pre-Audit, Vulnerability Validation, Remediation Regression — Accelerating Security Compliance Certification AI Driven Penetration Testing Integrates SAST + DAST + SCA + autonomous penetration testing into a single unified solution. Context Awareness Ingests your design documents,API,IaC, threat models, user stories, and endpoints to tailor attacks. Validate Security Risks Chains vulnerabilities into verifiable, reproducible attacks, reducing false positives and alert fatigue. Amazon Security Agent
  10. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 D

    E E P E R I N S I G H T S A N D A N A L Y S I S Comprehensive Dashboard Centralized findings view with detailed explanations. Detailed Findings Each penetration test delivers detailed, prioritized findings, analysis, reproducible steps, remediation guidance, and more. 3.Dashboard and Reports
  11. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 D

    E E P E R I N S I G H T S A N D A N A L Y S I S CVSS Risk-Scored Priority Findings Provides each finding with CVSS score. Deeper Findings. Fewer False Positives Delivers fewer false positives through validated, provable security vulnerabilities. Integrated with Amazon Devops Agent for Remediation Automatically remediate findings by integrating with DevOps Agent 4.Finding Remediation
  12. © 2026, Amazon Web Services, Inc. 或其附属公司。保留所有权利。 *前述特定亚马逊云科技生成式人工智能相关的服务目前在亚马逊云科技海外区域可用。亚马逊云科技中国区域相关云服务由西云数 据和光环新网运营,具体信息以中国区域官网为准。 Starting

    from Universal, High-Pain-Point Scenarios Such as Penetration Testing Takeaway 70%+ Reduction in Evidence Collection Time 60%+ Remediation Acceleration 49%- Certification Cycle Reduction Test findings, reproduction steps, remediation records, and regression results continuously improve MakingAgent the Leverage for Improving Compliance Response Speed