Secure and Scale Your Cloud Foundations Using Aws Built in Cfs226

Title: AWS re:Inforce 2024 - Secure and scale your cloud foundations using AWS Built-in (CFS226)

Insights:

  • Automation Focus: The session emphasizes the importance of automation in cloud operations, not just through generative AI but through efficient deployment and integration of services.
  • AWS Built-in Goals: AWS Built-in aims to provide foundational building blocks for cloud security and efficiency, ensuring that customers can automate their cloud environments effectively.
  • Partner Collaboration: AWS collaborates closely with ISV and SI partners to co-build solutions that are continuously validated by AWS, ensuring high standards of security and best practices.
  • Customer Flexibility: Customers have the flexibility to either self-deploy AWS Built-in solutions or engage partners for deployment, making it adaptable to various business needs.
  • Validation Process: The validation process for AWS Built-in solutions involves both automated and manual checks to ensure security and adherence to best practices. This includes static and functional tests.
  • Publishing and Availability: Once validated, solutions are published and made available through GitHub repositories and the AWS Marketplace, providing easy access for customers.
  • Continuous Improvement: The process includes continuous validation and updates, ensuring that solutions remain up-to-date with AWS's evolving features and security standards.
  • Customer Use Cases: AWS Built-in solutions are tailored to specific customer use cases, leveraging AWS services like CloudTrail and GuardDuty, and integrating additional partner capabilities.
  • Marketplace Integration: Customers can find and deploy AWS Built-in solutions directly from the AWS Marketplace, with some partners offering direct integration into their consoles for seamless deployment.

Quotes:

  • "Automation, it's not about Gen AI. It could be about Gen AI someday, but it's basically about how we automate for our customers when they're engaging our partners."
  • "The goal of AWS built-in is really to get the building blocks to cloud right and then to automate for the customer."
  • "AWS ultimately wants our customers to be as secure as possible. And to do that, a couple of things have to happen. We want to be able to help you secure your cloud using our native security services."
  • "Our partners co-build with us and then that code is then validated by AWS. So it's not just code that gets built and then is not validated. It's a continuous validation process with built-in."
  • "If you take someone like a SIM solution and that SIM solution wants you to let's say have guard duty enabled and VPC flow logs enabled and org level trail, our automation template for built-in will do that in let's say half a day."
  • "We provide a modular code for some of the AWS services, right? So if the partner needs to enable some AWS services like CloudTrail or GuardDuty, they can leverage the code that we provide."
  • "Once both approvals are in place is when the publishing phase happens. So this is basically where the code is merged and made available to the public."
  • "With the automation, not only with the new solutions, like every PR that comes in has to go through the same process."
  • "Customers can directly search the product, find this built-in solution from the marketplace, subscribe from here, and launch the template and complete their flow."
  • "It is a true co-build between the partner and AWS. We're also working more and more with SI partners that realize the value of built-in."