“We lead in preventing unauthorized access to AWS resources: our customers’ or ours. We continuously assess our systems, identify exposures, evaluate risks, and relentlessly drive mitigations.”
“We escalate appropriately yet aggressively to ensure that security issues are resolved promptly and with high judgement. If in doubt, we will escalate.”
“Escalation within the AWS security organization is free” << Eric Brandwine points out the need to make it a comfortable action to escalate appropriately
“Is now the time to speak up for our customers?", the answer is always “Yes” << you need to build a culture where that is encouraged and widely accepted
“We own security for all of AWS, including 3rd party & oss. We take nothing as a given & extensively test all of our components, even those built by other parts of the co. If something doesn’t work fo run, we will move off to it”
this tenet also demonstrates a choice made for the betterment of the org. it’s not optimal for the security team but is optimal for the organization overall
“We drive our work to focus on the most critical security risks for the business. They will be prioritized 1st for the biz & then for the service teams. We will ensure each expectation is well understood, actionable, & supported by appropriate tooling”
“At our scale, you have to panic strategically”, @ebrandwine
these tenets (and others) help the team focus. when they are internalized by everyone on the team, they are part of the discussion and help everyone work together to meet their goals...
if you're still on site for @awscloud#reinvent this morning, remember it's a great time to catch a few super popular sessions on repeat
sessions run until ~12:30pm pacific!
@awscloud there's overflow for the fully booked, "Introducing Amazon VPC Lattice: Simplifying application networking" (NET215) at the Content Hub in the Venetian at 11:30am pacific
what will the theme of @Werner’s #reinvent keynote be this year? who’s the musical act for @AWSEvents re:Play tonight? what will be your favourite t-shirt of his?