Deep Dive on AWS Security Hub - Slides
Deep Dive on AWS Security Hub - Slides
Ric Harvey
SaaS Solutions Architect
Amazon Web Services
[email protected]
@ric__harvey
https://gitlab.com/ric_harvey/
Inspector,
Macie,
GuardDuty
Systems
Manager,
AWS Config
Automate CloudWatch,
Lambda
Snapshot,
Archive
CloudWatch,
Forensic
Cloudtrial
What security challenges are we facing?
https://aws.amazon.com/security/
1 2 3 4
Ensure your AWS Dozens of security Lack of single
Large volume of
infrastructure tools with pane of glass
alerts and the
meets compliance different data across security and
need to prioritize
requirements formats compliance tools
Introducing AWS Security Hub
https://aws.amazon.com/security-hub/
AWS Security Hub benefits
https://aws.amazon.com/security-hub/
Account 1
Account 2
Account 3
EC2 instances that have S3 buckets with stored S3 buckets with public read
missing security patches credentials and write permissions
AWS Security Hub
Services Availability (Regions)
Available in 15 Regions
• US East (N. Virginia) • EU (Paris)
• US East (Ohio) • Asia Pacific (Singapore)
• US West (N. California) • Asia Pacific (Sydney)
• US West (Oregon) • Asia Pacific (Seoul)
• Canada (Central) • Asia Pacific (Tokyo)
• EU (Ireland) • Asia Pacific (Mumbai)
• EU (Frankfurt • South America (Sao Paulo)
• EU (London)
Used by Customers
Firewalls Endpoint
Vulnerability Compliance
SOAR MSSP
SIEM Other
Partner integration examples - CrowdStrike
Partner integration examples -Armor
Simple to Enable
43 fully automated,
nearly continuous
checks
Insights help identify resources that require attention
Customisable response and remediation actions
Event (event-
based)
Rule
Demo
https://github.com/aws-samples/aws-securityhub-to-email
Understand and manage your overall AWS security and compliance posture
Collect and process security findings from multiple accounts within a region
Identify and prioritize the most important issues by grouping and correlating
security findings with Insights
Thank you!
Any Questions?
Ric Harvey
SaaS Solutions Architect
Amazon Web Services
[email protected]
@ric__harvey
https://gitlab.com/ric_harvey/