Eric Brandwine up now at @awscloud #reinforce

he’s talking about building a culture of #security
scale quickly became a problem in building the #security organization at AWS

@awscloud #reinforce
Eric realized they couldn’t scale up the team to the size of AWS, it just wasn’t possible

they had to figure out a way to help the organization build the #security culture itself

@awscloud #reinforce
effectively tenets are rules for a culture. hard to write them down but they are critical

@awscloud #reinforce
“Out tenets…unless you know better ones” << love this

@awscloud #reinforce
#security cultural tenets are published internally at AWS. they have to be transparent and open, so people know what the team values

@awscloud #reinforce
1st #security tenet of AWS;

“We lead in preventing unauthorized access to AWS resources: our customers’ or ours. We continuously assess our systems, identify exposures, evaluate risks, and relentlessly drive mitigations.”

@awscloud #reinforce
2nd #security tenet of AWS:

“We constantly provide visibility to senior leadership into the biggest potential risks, backed up with data and carefully prioritized.”

@awscloud #reinforce
key quote, “#security at AWS is a DATA DRIVEN discipline”, Eric Brandwine

@awscloud #reinforce
3rd #security tenet of AWS:

“We escalate appropriately yet aggressively to ensure that security issues are resolved promptly and with high judgement. If in doubt, we will escalate.”

@awscloud #reinforce
“Make high velocity, high quality decisions” << love it

@awscloud #reinforce
“Escalation within the AWS security organization is free” << Eric Brandwine points out the need to make it a comfortable action to escalate appropriately

@awscloud #reinforce
inappropriate escalations => feedback that training, tooling, and data should be improved

@awscloud #reinforce
4th tenet of AWS #security culture:

“We are guardians of customer privacy and trust. We advocate for our customers in all security engagements.”

@awscloud #reinforce
side note: Eric is crushing this talk

(as expected)

@awscloud #reinforce
“Is now the time to speak up for our customers?", the answer is always “Yes” << you need to build a culture where that is encouraged and widely accepted

@awscloud #reinforce
5th tenet of @awscloud #security:

“We own security for all of AWS, including 3rd party & oss. We take nothing as a given & extensively test all of our components, even those built by other parts of the co. If something doesn’t work fo run, we will move off to it”

#reinforce
btw, here’s another great talk from Eric, Leadership Session: Aspirational Security … from #reinforce 2019



@awscloud #reinforce
…and this great interview with @werner, “15 years of Amazon S3 - Security is Job Zero“,

@awscloud #reinforce
…and this one from re:Invent 2018, “The Tension Between Absolutes & Ambiguity in Security”,

@awscloud #reinforce
…always frustrating when I can’t find someone’s twitter handle. Eric is at @ebrandwine…which let’s admit is pretty obscure and hard to figure out 🤣

@awscloud #reinforce
6th tenet of AWS #security:

“We are the one-stop shop for all security questions within AWS. In cases where we don’t own the answer, we own getting the question answered.”

@awscloud #reinforce
this tenet helps avoid ticket “ping pong” << 💯

@awscloud #reinforce
this tenet also demonstrates a choice made for the betterment of the org. it’s not optimal for the security team but is optimal for the organization overall

@awscloud #reinforce
7th tenet of @awscloud:

“We drive our work to focus on the most critical security risks for the business. They will be prioritized 1st for the biz & then for the service teams. We will ensure each expectation is well understood, actionable, & supported by appropriate tooling”
“At our scale, you have to panic strategically”, @ebrandwine

@awscloud #reinforce
some other team’s tenets...

@awscloud #reinforce
2 of the @awscloud crypto team’s tenets 👇

@awscloud #reinforce
these tenets (and others) help the team focus. when they are internalized by everyone on the team, they are part of the discussion and help everyone work together to meet their goals...

@awscloud #reinforce
some @awscloud S3 tenets 👇

@awscloud #reinforce
also of note to event organizers: speakers should always control their own slides

@awscloud #reinforce
all of the current AWS #security tenets on a single slide 👇

@awscloud #reinforce
another amazing talk by @ebrandwine…definitely check it out on the replay on YouTube…hopefully…soon?

@awscloud #reinforce
next up is IAM with Karen Haberkorn…new thread 👇

@awscloud #reinforce

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Mark Nunnikhoven

Mark Nunnikhoven Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @marknca

2 Sep
containers on @awscloud: a rant 🧵

problem: I want to run a single container every so often

☁️ #cloud #devops
I start with a search. the first result is straight forward and promising

I click on "Containers on AWS"

☁️🧵 #cloud #devops
I land here. it's not bad though a bit of a pitch, "AWS is the #1 place for you to run containers and 80% of all containers in the cloud run on @awscloud" << but will MINE?!?

☁️🧵 #cloud #devops
Read 45 tweets
24 Aug
next up is IAM with Karen Haberkorn

@awscloud #reinforce
…and the challenge of virtual events rears it ugly head. other more pressing matters popped up and I’ve missed what seems like a great talk and discussion on IAM 😔

@awscloud #reinforce
…but the upside of the virtual event is that I should be able to watch this on replay soon enough!

@awscloud #reinforce
Read 17 tweets
24 Aug
new thread to cover, “Governance, Risk, & Compliance”

@awscloud #reinforce
Anil starts things off with compliance landscape…

@awscloud #reinforce
lots of different legislation out there around data protection and #privacy. combined with a push to the cloud, lots of change in a traditionally slow area of GRC

@awscloud #reinforce
Read 15 tweets
24 Aug
up now at @awscloud #reinforce, “Data Protection & Privacy” with @JKenBeer, @jennybrinkley, & @clean_freak

☁️ #cloud #devops
. @StephenSchmidt introduces the session, which is a “fireside chat”

@awscloud #reinforce
Jenny is co-ordinating the chat. Anne is the director of Alexa Trust. Ken is the GM of AWS KMS

@awscloud #reinforce
Read 37 tweets
24 Aug
. @awscloud #reinforce // here we go…

🎙🧵

☁️ #cloud #security #devops
Adam Selipsky (CEO, AWS) up first with an opening message for @awscloud #reinforce
“Security is job ZERO at @awscloud”, Adam Selipsky. he’s referring to the fact that it is required as a baseline before building or doing anything

he goes on to say that #security is critical to AWS’ success and customer success

#cloud #devops
Read 121 tweets
13 Aug
yesterday I spun up 36x @awscloud EC2 instances to build out a weird sample data set

today, trying to get an exact cost for that work, it hits home (again) why @quinnypig has a very successful business

a story...



🧵 ☁️ #cloud #devops
ok, so I spun up the instances via python/boto3 (all old-school like) because I had a unique user-data script to each to execute and then shutdown

super simple 👇

🧵 ☁️ #cloud #devops
of course, the execution of this script took a while. about 6 hours. so I ran a couple quick, smaller scale tests and when I had things locked. I ran the script 👆

🧵 ☁️ #cloud #devops
Read 25 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!

:(