AWS Account Governance & Management
Who are we?
Where did we start?
One primary AWS account containing entire datacenter
Early Pain Points
IAM (Identity & Access Management) Policies
Early Pain Points
Stemmed from our separation of duties requirement
Separation of Duties
Engineer
Infosec
When do we use Separation of Duties?
Significant actions:
Why Separation of Duties?
To prevent large-scale negative impacts from:
Hackers
Insider Threats
Human Error
Early Pain Points (continued..)
Where are we now:
Where are we now:
Tools we utilize
Honorable Mentions:
Organizations
Organizations
Organizations
Organizations
Organizations
IAM SSO Federation with Okta
AWS IAM Before Federation
AWS IAM After Federation
Federation Obstacles
What about separation of duties?
What if SSO goes down?
Cloudformation
Cloudformation
Allows us to build infrastructure as code
Cloudformation Stack Sets
Cloudwatch Setup
Custom MFA tool for privileged accounts
Why do we need it?
What happens when nobody is near the physical MFA fobs?
Serverless MFA Token Generator
123456
123456
How does it work?
How does it work?
Next Steps
Next Steps
Questions?