accenture security framework for aws - australian prudential regulatory authority (apra) guidelines

10
SECURITY FRAMEWORK FOR AWS AUSTRALIAN PRUDENTIAL REGULATORY AUTHORITY (APRA) GUIDELINES ACCENTURE

Upload: accenture-operations

Post on 12-Apr-2017

517 views

Category:

Business


3 download

TRANSCRIPT

Page 1: Accenture Security Framework for AWS - Australian Prudential Regulatory Authority (APRA) Guidelines

SECURITY FRAMEWORK FOR AWSAUSTRALIAN PRUDENTIAL REGULATORY AUTHORITY (APRA) GUIDELINES

ACCENTURE

Page 2: Accenture Security Framework for AWS - Australian Prudential Regulatory Authority (APRA) Guidelines

Copyright © 2017 Accenture. All rights reserved.

TIME TO GET INTOTHE CLOUD

2

By moving to cloud, Australian FSIs can benefit through :• Enhanced operations• Service efficiency• Cloud services’ scalable, standardized, secure infrastructure

Australian Prudential Regulatory Authority (APRA) has updated risk management requirements and mitigation techniques.See: “Outsourcing Involving Shared Computing Services (Including Cloud)”

Page 3: Accenture Security Framework for AWS - Australian Prudential Regulatory Authority (APRA) Guidelines

Copyright © 2017 Accenture. All rights reserved. 3

ACCENTURE SECURITY FRAMEWORK FOR AWS makes it easier for FSIs in Australia to:• Adopt AWS services and use them as described

within the APRA guidelines.• Secure both sensitive and non-sensitive workloads

on the AWS platform.

FAST-TRACKTHE MOVE

Page 4: Accenture Security Framework for AWS - Australian Prudential Regulatory Authority (APRA) Guidelines

Copyright © 2017 Accenture. All rights reserved. 4

Layered approach to security as required by particular workload:

Network flow controls

Data protection and access management

Auditing and configuration management

THREE LAYERS OFCLOUD SECURITYAccenture Security Framework for AWS

Page 5: Accenture Security Framework for AWS - Australian Prudential Regulatory Authority (APRA) Guidelines

Copyright © 2017 Accenture. All rights reserved. 5

CORE PRINCIPLESOF FRAMEWORK• Guides the creation of an AWS cloud-based environment for

material workloads that follows traditional IT security models

• Leverages agile development methodologies and continuous integration for new approach to security in cloud

Accenture Security Framework for AWS

Page 6: Accenture Security Framework for AWS - Australian Prudential Regulatory Authority (APRA) Guidelines

Copyright © 2017 Accenture. All rights reserved. 6

INNOVATIVE SECURITYIN CLOUD• Provide data security by managing “infrastructure as code”

through software development and deployment lifecycle

• New ways to perform resilience, disaster recovery, backups

Page 7: Accenture Security Framework for AWS - Australian Prudential Regulatory Authority (APRA) Guidelines

Copyright © 2017 Accenture. All rights reserved. 7

APRA KEY CONTROL GUIDELINESView table of APRA key technology controls for Access Control technology components mapped against:

• Accenture Security Framework for AWS • AWS services used to address the controls

Page 8: Accenture Security Framework for AWS - Australian Prudential Regulatory Authority (APRA) Guidelines

Copyright © 2017 Accenture. All rights reserved. 8

MAXIMISECOMPLIANCEAccess the report to:

• Take a simplified approach to implementing the appropriate AWS services and platform

• Address the key controls listed for each of the technology key control requirements set out by APRA

Page 9: Accenture Security Framework for AWS - Australian Prudential Regulatory Authority (APRA) Guidelines

Copyright © 2017 Accenture. All rights reserved. 9

GET STARTED NOWAUSTRALIAN FSIsBENEFIT FROM

Secure and resilient AWS platform

Ability to support all workloads

Manage data securely Support the adoption of cloud-native development

and security technique

Page 10: Accenture Security Framework for AWS - Australian Prudential Regulatory Authority (APRA) Guidelines

DOWNLOADFULL REPORT

https://www.accenture.com/au-en/insight-security-framework-aws.aspx