Simplify Governance Third Party Assessments Using Aws Marketplace Mkt201

Title

AWS re:Invent 2023 - Simplify governance & third-party assessments using AWS Marketplace (MKT201)

Summary

  • Arun Saxena, Karthik Balakrishnan, and Krish Chalakarai discussed improving governance and assessment of third-party solutions using AWS Marketplace and AWS services.
  • The session covered the dynamic nature of the software industry, the challenges in procurement, and the high cost of poor software quality.
  • AWS Marketplace offers a wide selection of software, data services, and industry solutions, with features to streamline procurement, security assessments, and governance.
  • Vendor Insights, standardized license terms, and entitlements management are some of the features that help in reducing friction in the software supply chain.
  • Krish Chalakarai shared Gilead Sciences' approach to vendor management and how AWS Marketplace aids in their procurement and governance processes.
  • The session concluded with guidance on getting started with AWS Marketplace, including familiarization with the platform, piloting Vendor Insights, and leveraging private offers and private marketplaces.

Insights

  • The software industry's rapid growth and innovation have led to a "hyper-choice" situation, where organizations face challenges in selecting the right software efficiently while managing risks and costs.
  • AWS Marketplace has evolved to not only be a catalog of software but also a governance service, addressing procurement inefficiencies and providing a single source of truth.
  • Features like Vendor Insights and standardized license terms can significantly reduce the time and effort required for security assessments and contracting.
  • Gilead Sciences' case study illustrates the practical application of AWS Marketplace features in a real-world scenario, highlighting the benefits of streamlined vendor management and procurement processes.
  • The session emphasized the importance of balancing speed and agility in software procurement with appropriate governance and controls, which AWS Marketplace facilitates.
  • AWS Marketplace's integration with AWS services like IAM, Control Tower, and CloudTrail provides a comprehensive governance framework for organizations.
  • The talk suggested that organizations should start by experimenting with AWS Marketplace features to understand their potential impact on the software supply chain and governance processes.