ATO on AWS Program – Compliance as Code

No ratings

Presented at ISC2SecureSummit 2019 by

Nearly every customer and/or partner across AWS global public sector community has some compliance or data protection responsibility (e.g. FedRAMP, DoD SRG, Canadian PBMM, DFARS, etc.) and getting through the accreditation/certification process is expensive and time consuming – which causes extensive delays in availability for customers, and causes many solution providers to simply opt out of servicing public sector customers. The ATO on AWS Program accelerates independent software vendors (ISV) and customers through multiple security and compliance certifications and authorizations. The Program consists of varying resources that help expedite the authorization process. Program participants are afforded access to both technical Security Automation and Orchestration (SAO) capabilities as well as direct engagement with highly qualified AWS compliance strategists. Whether you are just beginning your cloud journey or are a cloud veteran, the Program will provide you the necessary guidance and expertise to better migrate, manage and secure your customers’ most highly regulated workloads on AWS. The Program includes: o Training in the AWS Security Automation and Orchestration (SAO) methodology, enabling program participants to: o Constrain, track and publish continuous risk treatments (CRT) and configurations o Configure and assimilate DevOps routines (e.g. continuous integration (CI) and continuous delivery (CD)) into a “Type Accredited” architecture o Leverage the “Type Accreditations” to meet and exceed common security frameworks through the use of security as code practices (e.g. Risk Management Framework (RMF), FedRAMP and DoD CC SRG control baselines, PCI-DSS, IRS 1075, etc.).