Read Digital Edition


ADS BY GOOGLE
Top Three Links You Must Click On


Is Amazon EC2 As a Platform Secure?
Security Best Practices for the Amazon Elastic Cloud

Amazon Cloud Journal on Ulitzer

Following on from my last post, Securing Applications on the Amazon Elastic Cloud, One of the biggest questions I often see asked is “Is Amazon EC2 as a platform secure”? This is like saying is my vanilla network secure?  As you do to your internal network you can take some steps to make the environment as secure as you can, such as:

- First read the Amazon Security Whitepaper and the Amazon discussion of Security processes

- Ensure the system key is encrypted at start-up

- Ensure you plan for load balancing in case an instance goes down. Ensure you understand all the security implications of this and harden any other instances.

- Test or emulate the performance of applications deployed to the cloud in all geographies where you plan to deploy them. The latency could vary greatly for each.

- Never ever allow password base authentication for shell access.

- Encrypt all network traffic always.

- Always encrypt everything stored on S3

- Encrypt file systems for Block devices

- Open only the minimum required ports

- Include no authentication information in any AMI images

- Think about how your system can be hardened and what is out there such asSELinuxPAX,  ExecShield etc

- Don’t allows any decryption keys into the cloud – understand the perils of keys and security

- Install host based intrusion detection system such as OSSEC

- Regularly backup Amazon instances and store them securely.

- Use Security Groups. With EC2 security groups, you can completely isolate every tier, even internally to the EC2 cloud. Multiple security groups can be used to lock down the ports and you can use a special security group to allow in-group communication

- Design in a way you can issue security patches to AMI instances

- If you are using private data off-cloud consider Amazon VPC, OpenVPN, or VPN-Cubed

Syndicated from my Cloud Blog.

Read the original blog entry...

About Jim Liddle
Jim is Managing Director of Jana Technology Services and UK Director of Sales and Operations for GigaSpaces. Jim is a regular blogger at SYS-CON.com, covering mobile, Grid, and Cloud Computing Topics.

  Subscribe to our RSS feeds now and receive the next article instantly!
In It? Reprint It! Contact advertising(at)sys-con.com to order your reprints!
Subscribe to the World's Most Powerful Newsletters

ADS BY GOOGLE
But on the web, access to services is implicit in the fact that the business is offering the service...
Gartner told Reuters that it overestimated how many PCs Acer shipped in the last seven quarters by a...
Gartner thinks the server business has stopped sliding into the abyss. Third-quarter sales weren’t a...
Office Web Apps, Microsoft’s answer to Google Apps, are supposed to be out sometime in June along wi...
Behaving like it’s got a future, Sun Monday put out what it calls a significant new version of Virtu...
Intel has put out its promised beta SDK for Windows (C and C++) and Moblin (C) developers working on...
Berlin-based ThinPrint AG, the printer virtualization house, thinks it’s got a cloud solution for th...
Gartner is buying ~$40 million-a-year AMR Research Inc for close to $64 million in cash. AMD special...
InformationWeek stumbled on a Microsoft patent application dating back to 2006 deceptively titled “M...
The second set of charges filed last week against Indian outsourcer Satyam Computer Services founder...
Singed by user reaction to its plans to up the price of its support contracts, SAP Tuesday postponed...
Apparently Google Gears ain’t gonna stick around that long. Google Apps will eventually get their of...
IBM has acquired Guardium, a seven-year-old subsidiary of Israel’s Log-On Software transplanted to M...
Oracle has offered to cordon off MySQL inside a combined Oracle-Sun to get the European Commission t...
Oracle seems to have divided the open source ranks over the MySQL delay it’s having closing its acqu...
The Korean government is going to sink around $172 million into cloud computing next year under a st...
We hear – well, you know how people talk – that Oracle has been quietly meeting with the European Co...
In response to Opera’s complaints Microsoft has reportedly modified the proposed ballot screen that’...
CA is looking for talent in EMEA: associate account managers, directors of solution sales, senior so...
Microsoft has sold the Folio and NXT businesses it got when it bought Fast Search and Transfer, the ...