たとえば、データベース管理のフルマネージド化 Power, HVAC, net Rack & stack Server maintenance OS patches DB s/w patches Database backups Scaling High availability DB s/w installs OS installation App optimization Power, HVAC, net Rack & stack Server maintenance OS patches DB s/w patches Database backups Scaling High availability DB s/w installs OS installation App optimization Power, HVAC, net Rack & stack Server maintenance OS patches DB s/w patches Database backups Scaling High availability DB s/w installs OS installation App optimization オンプレミス On EC2 マネージドサービス お客様
Power, HVAC, net Rack & stack Server maintenance OS patches DB s/w patches Database backups Scaling High availability DB s/w installs OS installation App optimization Power, HVAC, net Rack & stack Server maintenance OS patches DB s/w patches Database backups Scaling High availability DB s/w installs OS installation App optimization Power, HVAC, net Rack & stack Server maintenance OS patches DB s/w patches Database backups Scaling High availability DB s/w installs OS installation App optimization オンプレミス On EC2 RDS お客様 たとえば、データベース管理のフルマネージド化 抽象度の⾼いサービスの パッチ適⽤はAWSの責任 インフラストラクチャサービスのパッチ適⽤はお客 様の責任
Flow Logs • VPC内通信のヘッダ情報 • ENI/Subnet/VPC単位で有効化 AWS account Source IP Destination IP Source port Destination port Interface Protocol Packets Bytes Start/end time Accept or reject
rights reserved. 参照リソース1 Center for Internet Security (CIS) Benchmark for AWS https://www.cisecurity.org/cis-benchmarks/ CIS Benchmarks for EC2 instance types https://www.cisecurity.org/cis-benchmarks/ AWS Security Best Practices https://d1.awsstatic.com/whitepapers/ja_JP/Security/AWS_Security_Best_Practices.pdf AWS Security Checklist https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Checklist.pdf AWS Well-Architected Framework: Security Pillar https://d1.awsstatic.com/whitepapers/architecture/AWS-Security-Pillar.pdf