Mark Nunnikhoven Profile picture
Aug 24, 2021 34 tweets 25 min read Read on X
Eric Brandwine up now at @awscloud #reinforce

he’s talking about building a culture of #security
scale quickly became a problem in building the #security organization at AWS

@awscloud #reinforce
Eric realized they couldn’t scale up the team to the size of AWS, it just wasn’t possible

they had to figure out a way to help the organization build the #security culture itself

@awscloud #reinforce
effectively tenets are rules for a culture. hard to write them down but they are critical

@awscloud #reinforce
“Out tenets…unless you know better ones” << love this

@awscloud #reinforce
#security cultural tenets are published internally at AWS. they have to be transparent and open, so people know what the team values

@awscloud #reinforce
1st #security tenet of AWS;

“We lead in preventing unauthorized access to AWS resources: our customers’ or ours. We continuously assess our systems, identify exposures, evaluate risks, and relentlessly drive mitigations.”

@awscloud #reinforce
2nd #security tenet of AWS:

“We constantly provide visibility to senior leadership into the biggest potential risks, backed up with data and carefully prioritized.”

@awscloud #reinforce
key quote, “#security at AWS is a DATA DRIVEN discipline”, Eric Brandwine

@awscloud #reinforce
3rd #security tenet of AWS:

“We escalate appropriately yet aggressively to ensure that security issues are resolved promptly and with high judgement. If in doubt, we will escalate.”

@awscloud #reinforce
“Make high velocity, high quality decisions” << love it

@awscloud #reinforce
“Escalation within the AWS security organization is free” << Eric Brandwine points out the need to make it a comfortable action to escalate appropriately

@awscloud #reinforce
inappropriate escalations => feedback that training, tooling, and data should be improved

@awscloud #reinforce
4th tenet of AWS #security culture:

“We are guardians of customer privacy and trust. We advocate for our customers in all security engagements.”

@awscloud #reinforce
side note: Eric is crushing this talk

(as expected)

@awscloud #reinforce
“Is now the time to speak up for our customers?", the answer is always “Yes” << you need to build a culture where that is encouraged and widely accepted

@awscloud #reinforce
5th tenet of @awscloud #security:

“We own security for all of AWS, including 3rd party & oss. We take nothing as a given & extensively test all of our components, even those built by other parts of the co. If something doesn’t work fo run, we will move off to it”

#reinforce
btw, here’s another great talk from Eric, Leadership Session: Aspirational Security … from #reinforce 2019



@awscloud #reinforce
…and this great interview with @werner, “15 years of Amazon S3 - Security is Job Zero“,

@awscloud #reinforce
…and this one from re:Invent 2018, “The Tension Between Absolutes & Ambiguity in Security”,

@awscloud #reinforce
…always frustrating when I can’t find someone’s twitter handle. Eric is at @ebrandwine…which let’s admit is pretty obscure and hard to figure out 🤣

@awscloud #reinforce
6th tenet of AWS #security:

“We are the one-stop shop for all security questions within AWS. In cases where we don’t own the answer, we own getting the question answered.”

@awscloud #reinforce
this tenet helps avoid ticket “ping pong” << 💯

@awscloud #reinforce
this tenet also demonstrates a choice made for the betterment of the org. it’s not optimal for the security team but is optimal for the organization overall

@awscloud #reinforce
7th tenet of @awscloud:

“We drive our work to focus on the most critical security risks for the business. They will be prioritized 1st for the biz & then for the service teams. We will ensure each expectation is well understood, actionable, & supported by appropriate tooling”
“At our scale, you have to panic strategically”, @ebrandwine

@awscloud #reinforce
some other team’s tenets...

@awscloud #reinforce
2 of the @awscloud crypto team’s tenets 👇

@awscloud #reinforce
these tenets (and others) help the team focus. when they are internalized by everyone on the team, they are part of the discussion and help everyone work together to meet their goals...

@awscloud #reinforce
some @awscloud S3 tenets 👇

@awscloud #reinforce
also of note to event organizers: speakers should always control their own slides

@awscloud #reinforce
all of the current AWS #security tenets on a single slide 👇

@awscloud #reinforce
another amazing talk by @ebrandwine…definitely check it out on the replay on YouTube…hopefully…soon?

@awscloud #reinforce
next up is IAM with Karen Haberkorn…new thread 👇

@awscloud #reinforce

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Mark Nunnikhoven

Mark Nunnikhoven Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @marknca

Dec 2, 2022
if you're still on site for @awscloud #reinvent this morning, remember it's a great time to catch a few super popular sessions on repeat

sessions run until ~12:30pm pacific!
@awscloud there's overflow for the fully booked, "Introducing Amazon VPC Lattice: Simplifying application networking" (NET215) at the Content Hub in the Venetian at 11:30am pacific

#reinvent
ditto for "Introducing Amazon CodeCatalyst" (DOP206) which starts in 30m...this time the overflow is in the Content Hub at Caesars Forum

#reinvent
Read 4 tweets
Dec 1, 2022
the @awscloud #security leadership session featuring @mosescj58 is starting now…

What we can learn from customers: Accelerating innovation at AWS Security

#reinvent Image
@mosescj58 up now, rocking some killer kicks 👟

#reinvent ImageImage
@mosescj58 celebrating 15 years with @awscloud 🥳🥳🥳

congrats CJ!

#reinvent Image
Read 57 tweets
Dec 1, 2022
what will the theme of @Werner’s #reinvent keynote be this year? who’s the musical act for @AWSEvents re:Play tonight? what will be your favourite t-shirt of his?

let’s find out now…

/🧵 Image
dark & stormy, Matrix-style intro video...

#reinvent ImageImage
“The world is asynchronous”, @Werner

#reinvent Image
Read 135 tweets
Nov 29, 2022
here we go! @aselipsky up for today’s @awscloud #reinvent keynote…

/🧵 Image
@aselipsky takes the stage to Sweet Child of Mine 🎸🎵

#reinvent Image
50K in person, ~300K remote attendees

#reinvent Image
Read 77 tweets
Nov 29, 2022
here we go! Monday Night Live with Peter DeSantis is about to kick off at @awscloud #reinvent 2022!

a 🧵👇 (/cc @AWSEvents)
@awscloud @AWSEvents I love how much fun Peter has with this keynote!

#reinvent
Peter reminds everyone that this keynote is all about "how" @awscloud does things. lots of behind the scenes info in this one..

#reinvent
Read 74 tweets
Nov 28, 2022
a few notable, new @awscloud announcements so far today from #reinvent

👇

/cc @AWSEvents

/1
Amazon S3 multi-region access points get new functionality that allows you to shift data access requests to different regions as things hit the fan

#reinvent

aws.amazon.com/blogs/aws/new-…

/2 #reinvent
GAME CHANGER*: @awscloud Config _finally_ allows for proactive rules that can be run BEFORE spinning something up to catch issues

* changes the game in that we can all remove a bunch of Lambda/EventBridge stuff now

aws.amazon.com/blogs/aws/new-…

/3 #reinvent
Read 10 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(