Вы находитесь на странице: 1из 225

Welcome to:

AWS Business Essentials


Why Organizations Are Moving
to the Cloud

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Customers
Over a million customers running every imaginable use case

900+ Government Agencies

3,400+ Education Institutions

11,200+ Nonprofits

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
What is Cloud Computing?
"Cloud Computing" refers to the on-demand delivery of IT resources and
applications via the Internet with pay-as-you-go pricing.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Increased Agility

Speed
Experimentation
Culture of innovation

Hotels Music Storage Magazines

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Agility: Speed

Go global in minutes.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Why Agility Matters: Experimentation

To invent you must experiment often and fail with lower


risk. With AWS you can:

Spin up servers in minutes for experimenting


Return or repurpose servers for other experiments

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Increase Innovation
Experiment quickly with low cost and low risk.

On-Premises
$ Millions Nearly $0
Experiment infrequently Experiment often

Failure is expensive Fail quickly at a low cost

Less Innovation More Innovation

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Agility and Instant Elasticity
Easily Scale Up and Down

Quickly deploy new applications.


Instantly scale up as the workload grows.
Instantly shut down resources that are no
longer required.
Scale down and dont pay for the infrastructure.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Case Study: Airbnb

150,000 people are hosted on any given night.


A five-person team runs the entire IT operations infrastructure on AWS.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Case Study: Airbnb

Total number of guests

15M

12M

9M

6M
January 2013
3M 4 Million

Mar 2009 Sep 2009 Mar 2010 Mar2011 Sep 2011 Mar 2012 Sep 2012 Mar 2013 Sep 2013 Mar 2014

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Case Study: Airbnb

Total number of guests


Up by over 10 million in one year
15M
June 2014
15 Million
12M

9M

6M

3M

Mar 2009 Sep 2009 Mar 2010 Mar2011 Sep 2011 Mar 2012 Sep 2012 Mar 2013 Sep 2013 Mar 2014 Jun 2014

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Case Study: Airbnb

Total number of Amazon EC2 instances

1,400
1,300
1,050

700
432
350
48
0
2010 2014

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Pay For Infrastructure As You Need it, Not Upfront

On-Premises

No upfront cost
Pay as you go

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Lower Total Cost of IT

Scale allows AWS to AWS is comfortable AWS passes the


constantly reduce costs. running a high volume, savings along to
low margin business. customers in the form
of low prices.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
You Dont Need to Guess Capacity

AWS
Actual demand

Actual demand
Customer
Dissatisfaction
Self
Hosting
Waste
Predicted Demand

Rigid Elastic

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Remove Waste Focus on the Business
30% 70%

On-Premises Your Managing All of the


Infrastructure Business Undifferentiated Heavy Lifting

AWS Configuring
Cloud-Based More Time to Focus on
Your Cloud
Infrastructure Your Business
Assets

70% 30%
Only 30% of your time should be spent architecting for the cloud and configuring your assets.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary

Increase speed and agility.


Go global in minutes.
Benefit from massive economies of scale.
Eliminate guessing on infrastructure capacity needs.
Focus on projects that differentiate your business, not
on managing the assets of your infrastructure.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Why AWS?

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Partner Ecosystem

Thousands of consulting, systems


integrator and technology, and
independent software vendor partners.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Marketplace
AWS Marketplace allows customers to discover, evaluate and purchase IT and
business software optimized for the AWS Cloud.

23 product categories
More than1,900 listings
More than 70 million hours of AWS
Marketplace software per month.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Platform Breadth

A broad and deep platform helps


customers build sophisticated,
scalable applications.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Global Infrastructure

AWS Regions
AWS Edge Locations

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Support Virtually Every Use Case

Pace of innovation Robust platform and geographic breadth

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Continual Iteration and Innovation
AWS continuously upgrades infrastructure, so you dont have to

On-Premises Infrastructure

Upgrades are the Upgrades happen


customers responsibility automatically

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Cost Savings and Flexibility

1 2 3 4

Replace up-front Economies of scale Pricing model choice Save more money as
capital expense with allow AWS to continually to support variable & you grow bigger
low variable cost lower costs stable workloads

Continual Price Tiered Pricing


Reductions
Volume Discounts
Custom Pricing

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
The AWS Price Reduction Philosophy

AWS can take the efficiencies gained


from its global scale and pass that on to
customers in the form of lower prices.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary

AWS Partner Ecosystem provides support for customers


to build a successful cloud business.
AWS Marketplace - immediately use software and
services that run on AWS.
AWS Platform is broad and deep and supports virtually
every use case.
AWS Pricing Philosophy takes the efficiencies gained
from its global scale and passes it on to customers in
the form of lower prices.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
How Enterprises Are Using
the Cloud

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
How Enterprises Use AWS

Augment On-Premises
resources with cloud capacity
(Hybrid Architecture)

Migrate existing apps &


data to the cloud

Build new apps, sites,


services & lines of
businesses

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Development and Testing

Customers can get comfortable with the AWS platform and business model.

SharePoint and SAP Supports 1,000 SAP ERP systems, at 70%


environment developers savings

Oracle environment New apps for faster Development & testing of new
provisioning software products

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Altogether New Applications
Leverage the AWS platform to develop entirely new, innovative applications.

Video Streaming Hotel Booking Product Prototyping & Design

Diagnostics Player Tracking Analytics

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Websites & Digital Transformation

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Analytics

Data Analysis Game and Social Analytics Pension Risk Analysis

Manufacturing Quality Social Media Campaign Hard Drive Design


Improvement Analytics

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Mobile

Mobile services and analytics Web and mobile site Apps for cabin crew staff

Cloud-connected trucks App store Mobile push notifications

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Business Critical Production Applications

SAP HANA HR and legal apps SAP Business Suite

National retail banking Fleet management Solvency simulations

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Migrating Datacenters
Entire data center migration is now happening more and more.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
All-In Migrations

Enterprises

Independent Software
Vendors

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
More Than Two Choices

Enterprises are concerned that there are only two choices.

Build your own datacenter Replace infrastructure


on-premises with AWS

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
The Cloud Isnt An All or Nothing Choice

On-Premises Cloud
Integration
Resources Resources

Corporate Data
Centers

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Support for Hybrid IT Architectures

Active Directory AWS Identity & Access Mgmt. Users & Access Rules
Network Configuration Amazon Virtual Private Cloud Your Private Network
Encryption AWS Cloud HSM HSM Appliance
Backup Appliances AWS Storage Gateway Cloud Backups

Corporate Data Your On-Premises Apps Your Cloud Apps


AWS Direct Connect
Centers

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Integration with On-Premises Resources

Integrated Integrated Integrated Single pane


networking access control cloud backup of glass

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
What Are Customers Really Looking For?

Private Private Private Private key Governance


network compute storage management

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Customer Testimonial: Mortar

Without AWS we
would have needed
to raise $7.1M to
launch instead of
$1.8M

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Customer Testimonial: Commonwealth Bank

Weve halved
storage costs of
millions of dollars.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Customer Testimonial: U.S. Navy

The move could


save the Navy as
much as 60% versus
the cost of hosting
or managing data in
its own data centers.


2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary

Companies use AWS in 3 main ways:


To augment the IT capacity they run in their own
data center.
To move existing workloads from their own data
center into the cloud.
To build entirely new projects, applications, web
apps, and services.
AWS supports hybrid IT architectures.
Customers maintain the control over their resources.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Module 2: Using The AWS Platform

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Module Overview

Module 2 establishes a foundational level of


knowledge of the AWS platform, its
capabilities, and how it can be used in different
application scenarios.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Learning Objectives

This module is designed to teach you about:

The AWS global infrastructure


Featured AWS services and service categories.
Ways that many of the service categories are being used.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
The AWS Global Infrastructure

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Platform Enterprise Virtual Sharing and
Applications Desktop Collaboration

Analytics App Services Deployment and Management Mobile Services

Queuing and
Hadoop One-Click Identity
Notifications
Web App
Deployment
Workflow
Real-Time
Sync
Streaming
Platform Data App
Streaming Dev/Ops Resource
Services Management
Data Mobile
Transcoding
Warehouse Analytics

Email
Data Resource Push
Pipelines Templates Notifications
Search

Administration Identity Access Usage Key Monitoring


Management Control Auditing Storage And Logs
and Security

Core Compute Storage CDN Databases Networking


Services

Infrastructure Regions Availability Zones Points of Presence

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Global Infrastructure

11 Regions | 28 Availability Zones | 53 Edge Locations


As of March 2015

http://aws.amazon.com/about-aws/globalinfrastructure/

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Regions, Availability Zones
US Regions Global Regions
US East (VA) US West (CA)
Asia Pacific Asia Pacific Asia Pacific China (Beijing)
AZ - A AZ - B (Tokyo) (Singapore) (Sydney)
AZ - A AZ - B
AZ - A AZ - B
AZ - C AZ - D AZ - A AZ - B AZ - A AZ - B AZ
AZ - C

US West (OR) GovCloud (US)


EU (Frankfurt) South America
EU (Ireland)
(So Paulo)
AZ - A AZ - B
AZ - A AZ - B AZ - A AZ - B
AZ - A AZ - B AZ - A AZ - B
AZ - C AZ - C

Note: Conceptual drawing only. The number of Availability Zones (AZ) may vary.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Expansion

2003: Amazon.com 2015:

$7B retail business Every day, AWS adds


7,800 employees enough server capacity to
power this $7B enterprise.
Lots of servers

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary

The AWS platform is a very broad and robust technology that offers more
functionality than you will find anywhere else.

The AWS data center footprint is globalspanning five continentswith


highly redundant clusters of data centers in each region.

This global infrastructure forms the basis of all other layers of the AWS
cloud computing platform.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Core Services

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Amazon Web Services
Enterprise Analytics App Services Deployment and Management Mobile Services
Applications

Amazon Amazon AWS


Platform Amazon
Amazon CloudSearch SES OpsWorks AWS
Amazon
Kinesis IAM Cognito
Services WorkSpaces CloudFormation Amazon
SNS
Amazon
EMR Amazon
SWF Elastic AWS Mobile
Amazon AWS Data Elastic Beanstalk CloudTrail
CloudWatch Analytics
WorkDocs Pipeline Transcoder

Compute Networking Storage Database


Core
Services Amazon EC2
Amazon Amazon Amazon DynamoDB
AWS Direct Elastic Load EBS Glacier RDS
Connect Balancing
Amazon
Amazon VPC Auto Scaling
Route 53 Amazon S3
CloudFront Amazon ElastiCache
Redshift

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Compute Services

EC2

Actual

Amazon EC2 Auto Scaling Elastic Load Balancing

Web service Automatically scale Automatically distribute


providing resizable Amazon EC2 traffic across multiple
compute capacity capacity up or down Amazon EC2 instances

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Broadest Collection of Instance Types

General Compute Storage and IO GPU Memory


Purpose Optimized Optimized Enabled Optimized

M3 C4 I2 HS1 G2 R3

Added M3 C3 I2 G2
Instance
Types

M1 C1 CC2 HI1 HS1 CG1 M2 CR1

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Instance Types

Type Description

General Purpose (M3) Balance of compute, memory, and network resources.

Compute Optimized (C4) Highest performing processors and the lowest price/compute performance.

Memory Optimized (R3) High speed video encoding. Super fast databases.

GPU (G2) Graphics and general purpose GPU (Graphics Processing Unit) compute
applications.
Storage Optimized (I2) Transactional systems, high-performance NoSQL databases.
Very fast SSD-backed instance. High IOPS at low cost.
High Storage Density (HS1) Very high storage density.
Technical computing to grid deployments to analytics workloads.
T2 Low cost with burstable performance.
Reduced costs for modest-demand apps that benefit from bursts of power.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Storage

S3,
Glacier

Images Images
Videos Videos
Files Files
Binaries EBS Binaries
Snapshots Snapshots

Amazon S3 Amazon EBS Amazon Glacier AWS Storage Gateway

A durable, scalable Block storage Low cost storage Integrates on-


object store for use with Amazon for archiving and premises IT and
EC2 backup AWS storage

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Amazon Simple Storage Service (S3)

Store any amount of data.


Amazon S3 holds trillions of objects.
Highly durable.
99.999999999% of durability.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Amazon Elastic Block Store (EBS)
EBS General Purpose Solid State Drive (SSD)

Consistent performance with the ability to burst


up to 3,000 IOPS
SSD backed: the new default for Amazon EC2

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Case Study: Pinterest
Challenge
Rapidly expanding users
Dedicate staff to business, not data center

Being in the cloud and being Why AWS?


able to scale up and down Amazon S3 storage capacity
throughout the day or scale up Amazon EC2 compute power
very quickly and have that Auto Scaling scale up or down
balanced across multiple
availability zones throughout
Amazon EMR big data analysis
the world that is what makes
AWS very cost-effective. Benefits
Ryan Park Able to scale its business
Technical Operations and Store 8 billion objects; 400 terabytes of data
Infrastructure Lead
Pinterest
225,000 instance hours a month
Big data analysis capability
Watch the video

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Database Services

DBA

Amazon RDS
Amazon RDS Amazon DynamoDB Amazon ElastiCache
For Aurora

Managed relational Newest MySQL- Managed NoSQL In-memory caching


database service compatible relational database service service
database engine

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Networking Services

Availability Availability
Zone A Zone B

Amazon VPC AWS Direct Connect Amazon Route 53

Private, isolated Private connectivity Domain Name


section of the AWS between AWS and your System (DNS) web
cloud data center service

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
High Performance Cloud Network

High packets-per- Amazon EBSoptimized


Low jitter
second performance instances

High throughput, Physical placement


Virtual network interfaces low latency optimization

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Network Case Study: Pfizer

The Amazon Virtual Private


Cloud was a unique option that
Challenge
To handle peak computing needs beyond the
dedicated high performance computing systems
offered an additional level of
security and an ability to
integrate with other aspects of Why AWS?
our infrastructure. Additional level of security
Ability to integrate with other aspects of
Dr. Michael Miller
Head of HPC for R&D infrastructure

Benefit
Cost avoidance: able to scale up without investing


in additional hardware for peak loads
Able to invest in other business activities

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary

AWS compute services provide resizable compute capacity that can


automatically scale up or down.

AWS storage services provide low-cost data storage with high


durability and availability for block store, archiving, and backup that
integrates with on-premises IT.

AWS database services provide fully managed relational and NoSQL


database services, fully managed in-memory caching as a service,
and a fully managed petabyte-scale data-warehouse service.

AWS provides a range of networking services that enable you to create a


logically isolated network that you define.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Administration and Security

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Case Study: FINRA
Challenge
To respond to rapidly changing market dynamics
Analyze and store 30 billion market events every day

Why AWS?
Level of functionality at the right layers
Fulfilled security requirements
Automated infrastructure deployment
Big Data processing with Amazon Elastic MapReduce
and Amazon S3

Benefits
Agility and speed
Cost savings: 10-20 million annually
Watch the video Transforming technology and culture

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Comprehensive Security Capabilities

PEOPLE AND PROCESS


SYSTEM

NETWORK
PHYSICAL

Familiar Customer Partner Every customer


security model ecosystem ecosystem benefits

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Gives You Control

Secure key
Secure network Secure compute Secure storage Governance
management

Software- Fine-grained Encrypted Private Geographic


defined private access roles object storage encryption key data locality
network and groups management

Dedicated Software- Encrypted Integrated with Fine-grained


private network defined network block storage AWS products access control
connection isolation

Dedicated Single tenant Built-in auditing In-depth audits


instances block storage

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Identity and Access Control

AWS IAM (Identity AWS Directory AWS


and Access Mgmt) Service CloudHSM

Connect existing Dedicated


Manage users,
on-premises MS hardware security
groups, and
Directory or set up module
permissions
new standalone appliances

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Monitoring and Usage Auditing

Amazon
AWS CloudTrail
CloudWatch

Monitor Records AWS API


resources calls for your
account

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary

AWS has a broad set of identity and access control services that allow
you to manage users, groups, and permissions, connect or set up
Microsoft directories.

AWS provides on-demand infrastructure while also ensuring the security


isolation that customers are accustomed to in their existing, privately
owned environments.

AWS provides security control and governance across the network,


compute and storage services.

AWS has a number of monitoring and auditing capabilities.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Platform Services
Analytics App Services Deployment and Management Mobile Services

Queuing and
Hadoop One-Click Identity
Notifications
Web App
Deployment
Workflow
Real-Time
Sync
Streaming
Data App
Streaming Dev/Ops Resource
Management
Data Mobile
Transcoding
Warehouse Analytics

Email
Data Resource Push
Pipelines Templates Notifications
Search

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Analytics

Amazon Amazon Amazon Elastic


Kinesis Redshift MapReduce

Real-time data Fast, powerful, Process large


stream processing petabyte-scale data amounts of data
warehouse

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Analytics Case Study: Nokia
Nokias Xpress Internet Services platform provides mobile Internet services for
emerging global markets.
Challenge
The volume of data became too large for a
traditional relational database
AWS takes a lot of
Scale the database and generate reports
the burden out of
Why AWS?
having to manage
Using Amazon Redshift, run queries twice as
the databasea huge fast as its previous solution
savings in terms of Benefits
staff and expertise. Use business intelligence tools to mine and
Greg Johnson analyze big data at a 50% cost savings
Head of Analytics
Nokia

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Analytics Case Study: Major League Baseball
Challenge
Lots of data to be processed and delivered
Systems need to evolve quickly
Ever-increasing data set
Why AWS?
Push notifications and media tracking running in
AWS
Flexibility and speed to market are critical
Most reliable and robust cloud provider
Amazon Kinesis
Amazon Redshift
Benefits
AWS Direct Connect Able to spin up compute capacity to process 17 PB
of game data per season
Reduce capacity to lower costs during off-season
Watch the video Flexibility and speed-to-market for Statcast platform

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Application Services

Amazon Amazon Amazon Simple


AppStream Simple Queue Service Notification Service
(SQS) (SNS)

Amazon Simple Amazon Amazon


Email Service (SES) CloudSearch Elastic Transcoder

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Deployment and Management

AWS Elastic AWS AWS


Beanstalk OpsWorks CloudFormation

Automate resource DevOps framework Templates to deploy


management for application and manage
lifecycle management

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Mobile Services

H
i
!

Amazon Amazon Amazon


Cognito Mobile Analytics SNS

User identity and data Collect, visualize, Fully managed push


synchronization and understand app messaging service
service usage data

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Mobile Case Study: Concrete Software

With Amazon Cognito, We


can build games much faster
Challenge
A seamless user experience across devices
and platforms
and provide great user Store and save games in the cloud and
synchronize across all of a users devices
experience to our customers. without creating or hosting a backend
Keith A. Pichelman
CEO, Concrete Software
Benefits
Users securely access AWS resources.
Flexibility to save data in the cloud, cache it
on a users devices, without managing any
backend infrastructure

Concrete Software has been making hit mobile games


like Jellyflop and PBA Bowling Challenge since 2003.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Enterprise Applications

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Enterprise Applications

Amazon Amazon Amazon


WorkMail WorkSpaces WorkDocs

Business email and Virtual desktop Secure enterprise


calendaring service in the cloud storage and sharing
in the cloud

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary

Customers from many different industries are taking advantage of AWS to


perform big data analytics and meet the challenges of the increasing
volume, variety, and velocity of digital information.

Amazon Web Services offers you a variety of managed services to use


with your applications: application streaming, queueing, push notification,
email delivery, searching, and transcoding.

Amazon Web Services provides you with services to help with the
deployment and management of your applications.

Amazon mobile services help you securely manage and synchronize app
data for your users across mobile devices.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Module 3: Cloud Financials

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Module Overview

Module 3 discusses the multiple ways AWS helps you


reduce your overall IT costs as well as the financial impact
the AWS cloud can have on an organizations procurement
cycle, cost management, and contracts.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Learning Objectives

This module is designed to teach you about:

The economic benefits of AWS.


The AWS pricing principles.
The Total Cost of Ownership (TCO) Calculator
The AWS Simple Calculator
The impacts to the procurement cycle change as a result of migration to the cloud.
The impacts to vendors and contract terms.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
The Economic Benefits of AWS

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Reducing Cost and Increasing Business Value

Pay-as-you Lower overall Stop Agility / Avoid Go global


go model costs guessing speed / undifferentiated in minutes
capacity innovation heavy lifting


On-premises/
colocation x x x x x x

Cost Reasons Business Value


Reasons

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Total Cost of Ownership (TCO)

TCO Definition: the entire set of acquisition and operating costs for running an
infrastructure environment end-to-end.

Acquisition
Operating costs
Decommissioning / retiring systems
Opportunity cost

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
How can you achieve lower TCO with AWS?

1 2 3

Replace large upfront Pricing model choice Save more money as


expenditures with pay to support variable & you grow bigger
as you go and only for stable workloads
what you use.
On-Demand Tiered Pricing
Reserved Volume Discounts
Spot Custom Pricing
AWS Enables Lower TCO Than On-Premises Environments

Utilization fundamentally higher in


Cost savings from running AWS cloud
VARIABLE
COSTS Aggregating non-correlated workloads,
internal IT more efficiently
scale, spot market
Amazon specific hardware designs
OEM (original equipment manufacturer)
acquisition of custom servers & net gear
VARIABLE
COSTS Cost savings from moving
Direct purchasing of disk, memory, & CPU
to a public cloud provider
UPFRONT
AWS controlled hypervisor & net protocol
COSTS
layers
VARIABLE
UPFRONT
COST AWS Immense scale
COSTS
UPFRONT New data centers built each year
COSTS
Volume purchasing, highly automated,
Traditional Virtualized AWS supply chain optimization
Data Center Data Center

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Initial Questions to Consider When Exploring TCO
1
How do you plan for capacity?
Capacity
How many servers have you added in the past year? Anticipating next year?
Planning
Can you switch your hardware on and off and only pay for what is used?

2 What is your average server utilization?


Utilization How much do you overprovision for peak load?

Will you run out of data center space some time in the future?
3
Operations What was your last year power utility bill for the Data Center(s)?
Have you budgeted for both average and peak power requirements?

4 Are you on AWS today?


Optimization Is your architecture cost-optimized (Auto Scaling, Reserved Instances, Spot,
Instances turn on/off)?

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Traditional Capacity Planning
Limitations of traditional data centers:

Inflexible physical assets Costs are never in sync

Migration and expansion Cost of unexpected


costs are high inefficiencies

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Inflexible Physical Assets

Large up-front spending


Costs driven by peak, not average
infrastructure requirements
Typically under-utilized environment

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Costs are Never In Sync

Many cost elements


Industry technology cycles
Timing of upgrades and refresh
Changes in networking technology
and virtualization

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Migration and Expansion Costs

Per rack cost on an unplanned move


Cost of an incremental move, expansion, or
large scale event
Business continuity strategy
New global market
Rapid, unexpected growth

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Unexpected Inefficiencies

Under-deployment, over-deployment
Unexpected high demand or low demand
Non-optimal, non-scalable

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
No Capital Intensive Infrastructure

On-Premises (or Co-location) AWS Cloud

Physical space
Cabling
Cooling
Power
Networking
No infrastructure to
Racks
Servers build to get started
Storage
Certification
Labor

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
TCO Calculator
Compare the cost of running your applications in an on-premises or colocation
environment to AWS
Environment Region Servers Virtual Machines Storage

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Three Steps to Comparing TCO
Using the TCO Calculator

1. Describe your existing or 2. Get an instant summary 3. Download a full report


planned on-premises or hosting report which shows you the including detailed cost
infrastructure in four steps, or three year TCO comparison by breakdowns or save the report
enter detailed configurations. cost categories. to share with others.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Customers Are Realizing Lower TCO

$34 million saved in


the first two years


If we were to use the traditional on-premises data center, we would have spent $34
million dollars in hardware and maintenance expenses during the first two years. With
AWS cloud, we met our reliability and performance objectives at a fraction of the cost.
Mr. Chun Kang, Principal Engineer, Samsung

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Customers Are Realizing Lower TCO

Decreased monthly
operating costs by 75%


The AWS-based infrastructure has decreased the publications overall monthly operating costs
by 75%. The publication has also been able to streamline its system administration personnel
by approximately 50%.
Nathan Butler of The Newsweek/Daily Beast Company

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Customer Spotlight: Dow Jones Intl.
TCO analysis is crucial in making a favorable business case

1. Evaluate infrastructure 2. Make business case 3. Enable decision to


costs & architecture move to the cloud

VS

From over 40 data centers down to 6


Migration of thousands of applications
Estimated saving $100M over 3 Years

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary Economic Benefits of AWS

AWS economies of scale provide direct cost benefits


to customers.

Customers can move away from a traditional emphasis


on heavy capital spending on infrastructure to low
variable expense.

Customers gain improved flexibility to grow (or


contract) with a lower overall TCO.

Use the TCO Calculator to compare the cost of running


your applications in an on-premises or colocation
environment to AWS.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Pricing Principles

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Pricing Principles
Customers pay for exactly the amount of resources that they actually use

No up-front investment Pay as you go Pay less when you reserve

Pay less by using more Pay per use Pay less when AWS grows

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Demand-driven operating model for IT

Customers pay for exactly what they use


Customers do not pay for unutilized feature
or services
Charge is based on infrastructure and
services consumed
Customers have control of how they utilize
Metered, Pay As You Go AWS products and services, which leads to
Pricing Model control over cost expenditures
Turn cloud resources off and on

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Pay Less Per Unit When You Use More
Volume discounts on overall bill when revenue hits certain thresholds.

Storage (S3) Data Transfer (Bandwidth)


Tiered Pricing Tiered Pricing
$0.030
$0.030 $0.12
$0.029
$0.029 $0.09
$0.028 $0.07
$0.028 $0.05

1-10 TB 10- 50 TB 50- 150 TB 150 - 500 TB


<1 TB <50 TB 50-500 TB 500-1000 1000-5000 >5000 TB
TB TB

Pricing as of February 2015


2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Compute Purchasing Models

Free Tier On-Demand Reserved Spot Dedicated

Get Started on AWS Pay for compute Make a low, one-time Bid for unused capacity, Launch instances within
with free usage & no capacity by the hour payment and receive a charged at a Spot Price Amazon VPC that run
commitment with no long-term significant discount on which fluctuates based on hardware dedicated
commitments the hourly charge on supply and demand to a single customer

For POCs and For spiky workloads, For committed For time-insensitive or For highly sensitive or
getting started or to define needs utilization transient workloads compliance related
workloads

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Reserved Instances (RI)
Reserve capacity for one or three years
Pay a low, one-time fee for the capacity reservation
Receive a significant discount on the hourly charge for your instance

For example:

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Reserved Instance Payment Options Explained
No Upfront option:
Up to a 55% discount compared to On-Demand
Does not require upfront payment
Low hourly rate for the RI on an ongoing hourly basis

Partial Upfront option:


Balances the payments of an RI between upfront and hourly
Provides a higher discount (up to 76%) compared to the No
Upfront option
Pay a very low hourly rate upfront for every hour in the term
regardless of usage

With the All Upfront option:


Highest discount compared to On-Demand (up to 77% off).

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Reserved Instance vs. On-Demand
What are the break-even points of each of these options in relation to
purchasing instances On-Demand?

m3.xlarge 1yr OD/RI Break Even


Utilization
$3,000
$2,500
$2,000
$1,500
$1,000
$500
$-
30% 40% 50% 60% 70% 80% 90% 100%
Utilization Over a Year

On Demand No Upfront Partial Upfront All Upfront

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spot instances
What are Spot instances?
Spare EC2 instances bid on in hourly increments
One hour at a time
Behave exactly like a regular instances

Cost Benefits
Up to 92% off regular on-demand prices per hour

What is the trade-off?


May be interrupted if that instance is needed for a
EC2 capacity
No charge for any partial hour due to termination

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spot Pricing Use Case: Honda
AWS Spot Accelerates Innovation
Cloud offers us an opportunity, as we can innovate faster
than before.
- Ayumi Tada, IT System Administrator, Honda R&D

Scalable Materials Simulations at Honda


Before:
80 in-house HPC nodes, 1 year to complete all needed simulations
After:
Scalable, on-demand HPC cluster on AWS
Up to 1000 Spot Instances, 16,000 cores
Able to run more simulations, faster, with more accurate results

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
The Simple Monthly Calculator

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
The Simple Monthly Calculator
Customers can effectively estimate the costs of running their specific project on AWS

Estimate monthly charges based on:


Architecture
Usage of each service
Features for each service in each region

http://aws.amazon.com/calculator

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Calculating the Cost of Launching a Web Application
Access the Simple Monthly Calculator
Choose the right region

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Calculating the Cost of Launching a Web Application
Choose the EC2 service from the service options in the left-hand menu of the Simple Monthly Calculator

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Calculating the Cost of Launching a Web Application
Add A New Row to add an EC2 server to your estimate
Determine the number of hours per month the server is likely to run. To determine this, you have a number of choices.
Calculating the Cost of Launching a Web Application

Select the Instance Type you need and


the Operating System (& Database)
required.

In this case, we are going to choose an


m3.medium instance packaged with
Windows and Std (Edition) SQL Server.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Calculating the Cost of Launching a Web Application

We plan on running this server


24x7 so we should choose a
pricing model to minimize the
cost of running it.

1yr Heavy Reserved Instance


as we anticipate an upgrade of
the application and database
in 12 months and unsure of
the server requirements at that
point in time.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Calculating the Cost of Launching a Web Application
Add persistent storage to your instance, you should add an EBS (Elastic Block Store) to your instance.
Click on Add New Row under Storage: Amazon EBS Volumes

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Calculating the Cost of Launching a Web Application
Choose the size of your volume. If youd like to backup this volume to S3, choose the
snapshot size youd like captured

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Calculating the Cost of Launching a Web Application
There are some other inputs/options you need to consider when providing an estimate for
an EC2 instance.

If you want your instance to maintain the


same IP address even after it has stopped or
been terminated, you should use Elastic IPs.

AWS will charge for Elastic IPs if they are


not attached to an EC2 instance.

Data transfer into AWS is free, however, data


transfer out of AWS incurs a charge

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Calculating the Cost of Launching a Web Application
Click on the Estimate tab at the top of the screen to check estimate..

To remove Reserved Instance upfront fee and


reveal ongoing monthly estimates, check the box
at the top of the screen.

To share this estimate, click on the Save and Share button.

Once completed, a unique URL of your estimate will be created.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary Pricing Principles

Customers pay for the amount of resources that they


actually use.

Customers pay less per unit the more they use AWS.

AWS offers several purchasing models to support different


needs and cost requirements (e.g., for compute: On-
Demand, RI, Spot).

Estimate your monthly bill using the AWS Simple Monthly


Calculator.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Cost Optimization

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Optimizing with AWS

Choose the right Instance Utilization Monitor and turn off


instance types unused instances

Offload architecture Leverage AWS Leverage AWS tools


application services

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Choose the Right Instance Types

Architecture Amazon Auto Scaling Current Generation


Review CloudWatch Instances

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Instance Utilization

Stop idle instances Identity Instance Tagging


Access Management
(AWS IAM)

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Reserved Instances and Spot Instances

Reserved Spot Instances Reserved Instance


Instances Analysis Tool

Steady State Workloads Time-insensitive Compare on-demand


stateless workloads with reserved instances

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Offload Your Architecture

Reevaluate Leverage AWS Leverage


Architecture application services AWS tools

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Trusted Advisor
Further reduce costs

Inspects your AWS environment


Recommends opportunities to save money
Eliminates unused and idle resources

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary

Use our best practices to optimize for cost on AWS, including:


Choose the right Instance size
Auto scaling
Turn off un-used Instances
Use Reserved Instances
Use Spot Instances
Leverage Storage Classes
Offload your architecture and reduce cost by using application services
(SQS, SES, etc.)
Leverage AWS Tools Trusted Advisor, EC2 Usage Reports

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Procurement and Contracts

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Simplifying Procurement
AWS provides customers with a flexible set of tools to simplify procurement.

AWS empowers customers to be self service


without complex contracts and agreements.

Customers can grow and adapt to their


needs without complex transactions.

Understand your organizations


procurement culture.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
The Role of Procurement

Govern and control purchasing Rationalize the number of vendors

Manage price negotiations Broker relationships

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Contract Simplicity
AWS has a single contract available online
Create a customized enterprise agreement

Simple contractual Flexibility to tailor Continual purchases


model contracts without amendments or
contract changes

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Single Online Agreement

Customers can move swiftly if they decide to


change direction.
Acquire services directly from the website.
Work with AWS with minimal overhead.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Enterprise Agreements
Larger customers might prefer an enterprise agreement.

Flexibility not limited by purchasing, legal,


and contractual constraints.
Discuss the best agreement model.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Module 4: Security and Compliance

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Module Overview

This module discusses the comprehensive AWS


security best practices, capabilities, controls, and
assurances in place to maintain security and data
protection.

Additionally, it discusses the security measures and


areas that the customer is responsible for, what they
need to do to ensure that they are compliant, and the
support AWS can provide to ensure this outcome.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Learning Objectives

This module is designed to teach you about:

The benefits of the pace of innovation of AWS as it applies to security and


compliance.
The shared responsibility model.
The robust built-in security features of the AWS platform and services.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Security Innovation

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Platform
Enterprise Virtual Sharing and
Applications Desktop Collaboration

Analytics App Services Deployment & Management Mobile Services

Queuing and
Hadoop 1-click Web Identity
Notifications
App
Deployment
Workflow
Real-Time
Sync
Streaming
Platform Data App
Streaming Dev/Ops Resource
Services Management
Data Mobile
Transcoding
Warehouse Analytics

Email
Data Resource Push
Pipelines Templates Notifications
Search

Administration Identity Access Usage Key Monitoring


Management Control Auditing Storage And Logs
and Security

Core Compute Storage CDN Databases Networking


Services

Infrastructure Regions Availability Zones Points of Presence

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Rapid Pace of Security Innovation

Security, compliance, governance, and audit-related launches and updates


514

280
159
82
48 61

2007 2008 2009 2010 2011 2012 2013 2014

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Security and Compliance Requirements from Every Industry

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
A Constantly Improving Security Baseline

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Expert Audits: Transparency and Accuracy

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Layers of Security Controls in AWS

Optimized
Network/OS/App Controls
Security in the cloud
Service-Specific Controls

Managed by
customer Cross-Service Controls

Cloud Service Provider


Controls Security of the cloud

Request reports at:


Managed by aws.amazon.com/compliance/#contact
AWS

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Case Study: Vodafone
Vodafone built a mobile payment application.
Payment Card Industry (PCI) and Data Security
Standard (DSS) compliance was essential.
Launched in three months.
Reduced CapEx by 30%.
Deployed to seven channels, including Facebook. Payments

Amazon Web Services was the


clear choice in terms of security.

Stefano Harak
Online Senior Product Manager

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Topic Summary

A third of the features that AWS launches every year


are directly related to security, governance, compliance,
and auditing.

AWS customers also bring their own auditors, each with


their own perspective on how to meet their individual
compliance objectives.

AWS has a constantly improving security baseline.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Security Controls

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Security Shared Responsibility Model

Watch the Video

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Security and Compliance is a Shared Responsibility

Customer applications and content

Customers
Platform, Applications, Identity and Access Management Customers are
Operating System, Network, and Firewall Configuration
responsible for their
security IN the cloud
Client-Side Data Server-Side Data Network Traffic
Encryption Encryption Protection

AWS Foundation Services

Compute Storage Database Networking


AWS is
responsible for
the security OF
AWS Global Availability Zones
Edge the cloud
Infrastructure Locations
Regions

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
You Always Have Full Ownership and Control

AWS makes no secondary use of customer content.


Manage your privacy objectives any way you want.
Keep data in your format and move it or delete it at any time.
There is no automatic replication of data outside of your
chosen AWS region.
Encrypt your content any way you want.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
You Decide Where to Put Your Content and Applications

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Every Network Has Fine-Grained Security Built In

Virtual Private Cloud AWS Network Security


Your section of the AWS cloud AWS network will prevent
is private and isolated. spoofing and other common
layer 2 attacks.
Availability Zone A

Availability Zone B
Every VPC has a private IP
address space you define. Every compute instance gets
multiple security groups
Create your own subnets and (stateful firewalls).
control all internal and
external connectivity. Every subnet gets network
access control lists (NACL).

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Create Multi-Tier Architectures

Load
balancing
Availability Zone A

Web Web Web


E
C
2

Database Jump
App
EC2 Log
host

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Connect Privately to Your Existing Data Centers

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Create Flexible Multi-VPC Hybrid Environments

Your organization

Internal Storage/
Digital/
Enterprise Backup
Websites
Apps
Project Teams Marketing

Amazon
S3

Dev and Redshift


Test EMR
Amazon
Analytics
Glacier Business Units Reporting

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Encrypt Your Sensitive Information

Amazon Elastic Block Store: Encrypt EBS volumes any


way you like.

Amazon S3: Offers either server or client-side encryption.

Amazon Redshift: 1-click disk encryption as standard.

Amazon RDS: Supports transparent data encryption.


DB
A

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS CloudHSM (Hardware Security Module)

You receive dedicated access to HSM


appliances.
HSMs are located in AWS data centers.
HSMs are managed and monitored by AWS.
Only you have access to your keys and AWS Administrator
Manages the appliance
operations on the keys.
HSMs are inside your VPC, isolated from the
rest of the network.
HSMs use SafeNet Luna SA HSM appliances.
You
AWS Control keys and
CloudHSM crypto operations

Virtual Private Cloud

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Key Management Service
Encryption key management and compliance made easy.

1-click encryption
Centralized key management
(create, delete, view, set policies)
Enforced, automatic key rotation
Visibility into any changes via AWS CloudTrail

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Available, Durable, and Integrated with AWS Products

Keys stored in Integrated with AWS Highly available and


HSMs products durable

(e.g., Amazon S3, Amazon EBS,


Amazon RDS, Amazon Redshift)

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
You Can Enforce Consistent Security on Your Hosts
Control the configuration of your Amazon EC2 compute instances and configure and
harden operating environments to your own specs.
User administration
Use host-based protection software. Whitelisting and integrity
Apply best-practice top five mitigation strategies.
Malware and HIPS
Think about how you will manage administrative users. Vulnerability management
Restrict access as much as you require.
Audit and logging
Build out the rest of your standard security environment.
Hardening
Connect to your existing services, e.g., SIEM, monitoring, patching.
Operating system

EC2
Your instance
AMI catalogue Running instance

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Service Catalog
A service for discovering and provisioning applications in the cloud.

Admins can create End users can Meet compliance Conduct reporting
and share product launch a product needs by and auditing via
portfolios. as a stack of AWS department, cost AWS CloudTrail
resources. code of globally

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Control Access and Segregate Duties Everywhere
With AWS IAM, you get to control who can do
what in your AWS environment, and from
where.
You get fine-grained control of your AWS cloud
with multi-factor authentication.
Integrate with your existing corporate directory
using SAML 2.0 and single sign-on.

AWS account
owner

Network Security Server Storage


management management management management

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Trusted Advisor

Over 1.7 million recommendations


More than $300M in estimated cost
savings
37 checks in 4 categories
Now with Free Tier

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Get Consistent Visibility of Logs That You Can Monitor

Full visibility of your AWS environment


AWS CloudTrail will record access to API calls
and save logs in your Amazon S3 buckets, no
matter how those API calls were made.

Who did what and when and from where (IP


address)
Support for AWS products
Easily aggregate all log information

Several log analysis and SIEM tools are


available from AWS partners like Splunk and
AlertLogic that work with AWS CloudTrail.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spotlight: AWS CloudTrail

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spotlight: AWS CloudTrail
Follow the API activity history and monitor resources.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spotlight: AWS CloudTrail

Review raw JSON output

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spotlight: AWS CloudTrail
AWS CloudTrail raw data feeds go into Amazon S3

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Config
A new resource dependency and auditing service

Security and incident analysis


Continuously monitor the configurations
of resources and evaluate these
configurations for potential security
weaknesses.

Audit and compliance


Designed to help ensure compliance
with internal policies and regulatory
standards by providing visibility into the
configuration of a resource at any time.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Audit and Troubleshoot Configuration Changes

Track a continuous stream of resource


configuration changes.
Review full history of all configuration
changes.
Review configuration change impact across
resources.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spotlight: AWS Config

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spotlight: AWS Config
Copy an Instance ID from running instances.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spotlight: AWS Config
Paste the Instance ID in the resource ID field.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spotlight: AWS Config
View historical data of changes to the Instance.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spotlight: AWS Config
View the full configuration of changes.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Spotlight: AWS Config
AWS Config data is written to a JSON file format which is maintained in Amazon S3.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Accreditation and Compliance: On-Premises and on AWS
On-Premises On AWS

Start with building the data center Start on base of accredited services
Functionally optional Functionally necessary high standard of
requirements
Audits done by an in-house team
Audits done by third-party experts
Accountable to yourself
Accountable to everyone
Typically check once a year
Continuous monitoring
Workload-specific compliance checks
Compliance approach based on all workload
Must keep pace and invest in security scenarios
innovation
Security innovation drives broad compliance

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Module Summary

Security and compliance is a shared responsibility


between AWS and customers.
You always have full ownership and control of the content
you place in AWS.
Every network has fine-grained security built in.
You can encrypt your sensitive information.
You can control access and segregate duties everywhere.
You can audit and troubleshooting configuration changes

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Module 5: Cloud Migration

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Module Overview

This module discusses best practices for


successful implementation of an IT
environment with AWS components.

The framework helps an organization develop a


plan to move from where they are to where
they want to be.

The plan provides guidance to teams on


changes they will make for successful adoption
of AWS solutions.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Learning Objectives

This module is designed to teach you about:

The seven steps to cloud success.


Common use cases on AWS.
Foundational perspectives of the Cloud Adoption Framework.
How to leverage your local AWS team.
What you need to get started with AWS.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Cloud Adoption Journey

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
The AWS Cloud Adoption Journey

Create a
Gain Create
Educate Cloud
Executive Hybrid
Staff Center of
Sponsorship Architecture
Excellence

Develop a Establish
Experiment Shared Plan Cloud-First
Standard

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Steps of the Journey: Executive Sponsorship

Create a Establish
Gain Center Develop Create Hybrid Cloud-
Educate
Executive Experiment of a Shared Architecture First
Staff
Sponsorship Excellence Plan Standard

Making it Real

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Executive Sponsorship

Follow path of least resistance


Own the business case
Manage the risk
Navigate the internal politics
Start from the bottom if necessary

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Align on the Outcome
Executive Priority AWS Value

Competitive advantage
CEO Save money
Business alignment Experience
CIO Move faster, more efficiency Pace of Innovation
Improved cash flow
CFO Service Depth and Breadth
Save money
Respond to market changes Pricing Philosophy
CMO Run more experiments Ecosystem
Better analytics
Global
CISO Visibility
Auditability control
CRO Get more products to market
Move faster, more efficiency
2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Steps of the Journey: Educate Staff

Create a Establish
Gain Develop Cloud-
Educate Center Create Hybrid
Executive Experiment a Shared First
Staff of Architecture
Sponsorship Plan Standard
Excellence

Making it Real

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Educate Staff

Attend industry events Talk with industry peers Run workshops Invite the AWS team

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Training and Certification

Self-Paced Labs Training Certification

Try products, gain new Skill up and gain Demonstrate your skills,
skills, and get hands-on confidence to design, knowledge, and expertise
practice working with develop, deploy, and with the AWS platform
AWS technologies manage your applications
on AWS
aws.amazon.com/training/
aws.amazon.com/training aws.amazon.com/certification
self-paced-labs

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Steps of the Journey: Experiment

Create a Establish
Gain Develop
Educate Center Create Hybrid Cloud-
Executive Experiment a Shared
Staff of Architecture First
Sponsorship Plan
Excellence Standard

Making it Real

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Experiment

Identify your first projects:


Test and Development
Digital
Storage
Backup

Practice on low-risk workloads.


Take advantage of the free tier.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Experiment Digital

Static Website
Mobile application service
Web application service
Amazon WorkSpaces

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Steps of the Journey: Center of Excellence

Create a Establish
Gain Develop
Educate Center Create Hybrid Cloud-
Executive Experiment a Shared
Staff of Architecture First
Sponsorship Plan
Excellence Standard

Making it Real

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Create a Center of Excellence (COE)

COE develops a framework.


Sets the charter.
Acts as the interface back into the
board and technical teams.
Increases agility, decreases risk and
operating costs.
Provides knowledge management.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Cloud Adoption Framework

Business Platform
Perspective Perspective
Perspectives in planning, creating,
managing, and supporting a modern IT
service.
Maturity People Process Guidelines for establishing, developing and
Perspective Perspective Perspective running AWS environments.
Structure for business and IT teams to
work together.
Operating Security
Perspective Perspective
Whitepaper: http://bit.ly/AWSCAF

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Seven Core Perspectives
Business Perspective People Perspective
Identifying, delivering, and measuring Defining and acquiring the skills needed to adopt the
business impact using architectural AWS cloud platform. Examples include guiding
approaches that align technical delivery to processes of role descriptions, training, certification,
business imperatives. and mentoring.

Platform Perspective Process Perspective


Providing patterns, guidance, and tools for Managing portfolios, programs, and projects to
optimal use of the technology services to deliver expected business outcome on time and
implement. Represents the technology within budget, while keeping risks at acceptable
services of the AWS cloud platform. levels.

Security Perspective
Defining and implementing the required levels of
Maturity Perspective security, governance, and risk management to
Defining the target state architecture of the achieve compliance.
organization and creating the required
blueprints and roadmaps. Operating Perspective
Providing process, guidance, and tools for optimum
operational service management of the AWS
environment. Represents the ongoing management
of the functioning IT environment of AWS.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Steps of the Journey: Develop a Shared Plan

Create a Establish
Gain Center Develop
Educate Create Hybrid Cloud-
Executive Experiment of a Shared
Staff Architecture First
Sponsorship Excellence Plan Standard

Making it Real

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Build Relationships

AWS Executives
AWS Account Executive
AWS Principal Solution Architect
Inside Sales Manager
Customer Experience Manager
Customer Support
Professional Services

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Engage Partners

Consulting Partners

Technology Partners

System Integrators

Specialist Partners
HPC
DevOps
Analytics

Find a suitable partner at http://www.aws-partner-directory.com

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Premier Consulting Partners
AWS Specialists

Security and Compliance

Enterprise Applications

Desktop

Big data/HPC

TCO

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Steps of the Journey: Hybrid Architecture

Create a Establish
Gain Develop
Educate Center Create Hybrid Cloud-
Executive Experiment a Shared
Staff of Architecture First
Sponsorship Plan
Excellence Standard

Making it Real

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Establish Hybrid Architecture

Corporate
data center
Security group

Users

VPC subnet

Availability Zone
Servers

Security group

Data center router

VPC Subnet
AWS Direct
Connect routers Availability Zone
AWS Direct Connect
location

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Set Up the Foundations

Networking Access Control Resource Compliance Backup


Management

Virtual
Directory VCenter AWS
Private AWS
Service Integration Storage
Cloud CloudTrail
Gateway

System
AWS Direct AWS Config
AWS IAM Center
Connect
Integration

Identity
Federation
Steps of the Journey: Cloud-First Standard

Gain Create a Establish


Educate Develop
Experiment Create Hybrid Center Cloud-
Executive a Shared
Staff Architecture of First
Sponsorship Plan
Excellence Standard

Making it Real

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Migration: Recommended Approach

Strategy
Executive Risk and Center of Operations
Educate Staff Foundations
Sponsorship Compliance Excellence Model

Continuous Feedback Future


Cycles of Learning State

Project 1 Project 2 Project 3 Project.

Application Migration/Experiment

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Example Application Migration Plan

Identify, analyze, Determine best Functional and


profile, summarize approach for each business criteria
applications application

Phase Initiate Discover Design Migrate Integrate Validate Operate Optimize

Architect a well-
defined target Architecture, design, deployment of apps to
environment take full advantage of availability, scalability,
and cost benefits
Infrastructure,
application, and
operation

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Enterprise Case Study: Cond Nast
Challenge
Improve organizational creativity, productivity,
agility, flexibility and time to market for digital
content

Why AWS?
Leverage infrastructure
Migrate over 500 servers, 1-PB storage, mission
critical applications, and 100 database servers to
the cloud

Benefits
Reduced costs by 40%
Increased operational performance by 3040%
Watch the video Closed their own data center

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Getting Started

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Meet Your Local Sales Team

Account Manager
Inside Sales
Solutions Architects

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Partner Introductions

Ecosystem Partners

http://www.aws-partner-directory.com

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
AWS Account

Get started immediately

Set up an AWS account.


Identify an AWS champion in your organization.
Identify the initial workload to migrate.
Start experimenting.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Module Summary

There are seven steps along the journey to cloud adoption.


There is no one-size-fits-all way that companies are moving
to the cloud.
Leverage your local AWS team.
The AWS Cloud Adoption Framework (CAF) separates
complex IT environments into manageable areas of focus.
Get to know the resources that are available to you and
reach out to your local AWS team.

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.
Conclusion

Thank You
Hope you enjoyed the training!
Let us know what you think and email us at:
aws-course-feedback@amazon.com

2015 Amazon Web Services, Inc. and its affiliates. All rights reserved.

Вам также может понравиться