๐Ÿ’ก

This post was written 3 years ago, it may be out of date, my opinion might have changed, and/or the writing may be embarrassingly bad. Read with caution.

Stephen Schmidt's Security Leadership Session at AWS re:Invent 2021

Fall/2021 โ€“ 9 min read

The leadership session at AWS re:Invent provide a deeper dive into a specific area of focus. Stephen Schmidt, CISO at AWS takes the stage to talk all things security.

The leadership session at AWS re:Invent provide a deeper dive into a specific area of focus. Stephen Schmidt, CISO at AWS takes the stage to talk all things security.

I missed the first 10 minutes of the session and will update this post when I watch it on demand.

The First 10 Minutes

THe session is now available on demand so I was able to watch the first ten minutes. Here are my takeaways as a list, instead of a tweet storm;

Live Tweets

This ๐Ÿ‘‡ is the Twitter thread of my coverage of the keynoteโ€ฆ

Tweet 1/44 ๐Ÿ‘‡ Next tweet

...ahhh, jumping in late to this one #reinvent https://twitter.com/66780587/status/1466510060784394253

Tweet 2/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

Sarah from @AWSIdentity up nowโ€ฆ #reinvent

Tweet 3/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

โ€œMFA is the best way to secure your work as you buildโ€, Sarah from @AWSIdentity with a Yubikey on her earrings! ๐Ÿ‘‡ her platesโ€ฆ #reinvent

Tweet 4/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

ok, now I want a Yubikey on my earrings too. Sarah recommended this one, the 5c nano: https://www.yubico.com/ca/product/yubikey-5c-nano/ #reinvent

Tweet 5/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

โ€œAll workloads on @awscloud should be multi-account, thatโ€™s how weโ€™ve designed @AWSIdentityโ€ #reinvent #security

Tweet 6/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

โ€œIf you are a human, you should be logging into @awscloud through SSOโ€, Sarah from @AWSIdentity #reinvent #security

Tweet 7/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

#reinvent

Tweet 8/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

more on @AWSIdentity SSO at https://aws.amazon.com/single-sign-on/ #reinvent #security

Tweet 9/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

the โ€œdata perimeterโ€ idea is all about protecting your solutions from all angles #reinvent

Tweet 10/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

Sarah covering some @AWSIdentity recent releases. top of the list: IAM Access Analyzer more at https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html #reinvent #security

Tweet 11/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

โ€ฆthere is also Network Access Analyzer more on that new release at https://aws.amazon.com/blogs/aws/new-amazon-vpc-network-access-analyzer/ #reinvent #securtiy

Tweet 12/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

another one in the list, Access Analyzer policy validation more on that at https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-policy-validation.html #reinvent #security

Tweet 13/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

Sarah also calls out the IAM Access Analyzer policy generation feature released by @AWSIdentity a little while back more at https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-policy-generation.html #reinvent #security

Tweet 14/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

๐Ÿ‘† great list. everyone should be using these tools regularly #reinvent #security

Tweet 15/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

. @StephenSchmidt back up to switch gearsโ€ฆupdates! #reinvent #security

Tweet 16/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

162 checks now in @awscloud Security Hub! + VPC endpoint support (https://docs.aws.amazon.com/securityhub/latest/userguide/security-vpc-endpoints.html) #reinvent

Tweet 17/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

Amazon Detective got support S3 and DNS finding types more at https://aws.amazon.com/about-aws/whats-new/2021/09/amazon-detective-s3-dns/ #reinvent #security

Tweet 18/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

. @awscloud Shield automatically does application layer DDoS mitigation more: https://aws.amazon.com/about-aws/whats-new/2021/12/aws-shield-advanced-application-layer-ddos-mitigation/ #reinvent #security

Tweet 19/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

Amazon Inspector got a big update. I covered that at https://markn.ca/2021/first-look-at-the-brand-new-amazon-inspector/ lots of great stuff in this complete revamp #reinvent #security

Tweet 20/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

there is a dedicated session on site for Amazon Inspector. will be on demand in a few days #reinvent #security

Tweet 21/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

simple win: update the alternative security contact for your accounts. you can do this via Orgs and the CLI now more on that at https://aws.amazon.com/blogs/security/update-the-alternate-security-contact-across-your-aws-accounts-for-timely-security-notifications/ #reinvent #security

Tweet 22/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

โ€œConsider the Security Pillar of the AWS Well-Architected Frameworkโ€ << โ€ฆand the rest of the framework! thereโ€™s a ton of amazing stuff in there that contributes to security more https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/welcome.html #reinvent #security

Tweet 23/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

Thomas Avant coming up now to talk about security culture at @awscloud #reinvent #security

Tweet 24/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

hereโ€™s another great talk about @awscloud #security culture from re:Inforce 2021: https://www.youtube.com/watch?v=edWC5q-enX0&feature=youtu.be be sure to bookmark this one ๐Ÿ‘‡ and watch it later #reinvent

Tweet 25/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

they regularly remind employees about the importance of #security to the work their doing #reinvent

Tweet 26/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

๐Ÿ”‘ @awscloud is always looking for ways to empower everyone to be a part of the #security team #reinvent #infosec

Tweet 27/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

โ€œ@StephenSchmidt himself gets page if it comes to thatโ€ฆitโ€™s not fun, Iโ€™ve seen itโ€, Thomas Avant #reinvent #infosec

Tweet 28/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

โ€œWeโ€™ve got all the runbooks you would expect @awscloud but weโ€™re also heavily reliant on employees making the best decisions possibleโ€ #reinvent #infosec

Tweet 29/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

๐Ÿ‘† that only works because theyโ€™ve built up that #security culture. itโ€™s hard work but well worth it #reinvent

Tweet 30/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

#reinvent

Tweet 31/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

I โค๏ธ how many times Iโ€™ve heard โ€œbuildersโ€ in this #security session #reinvent

Tweet 32/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

#reinvent

Tweet 33/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

. @StephenSchmidt back up to talk about what sets @awscloud apart from the #security angle #reinvent

Tweet 34/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

first up: containers & code #reinvent #security

Tweet 35/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

โ€œContaining risk through isolationโ€, pun NOT pardoned @StephenSchmidt ๐Ÿคฃ๐Ÿ˜‰ #reinvent #infosec

Tweet 36/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

more on Amazon CodeGuru at https://aws.amazon.com/codeguru/ #reinvent #infosec

Tweet 37/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

thereโ€™s now a nice integration with Amazon CodeGuru + @awscloud Secrets Manager. more on that at https://aws.amazon.com/about-aws/whats-new/2021/11/amazon-codeguru-reviewer-hardcoded-secrets-java-python/ #reinvent #infosec

Tweet 38/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

. @awscloud GuardDuty support for #k8s audit logs coming in early 2022! #reinvent

Tweet 39/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

broader container support coming to other @AWSSecurityInfo services too. no firm ETA but itโ€™s being worked onโ€ฆ #reinvent #infosec

Tweet 40/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

#reinvent

Tweet 41/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

I remember when these slides were just a couple of names. nice to see the expansion of the #security partner community around @awscloud #reinvent


Tweet 42/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

. @awscloud re:Inforce 2022 dates announced! 28 & 29-Jun-2022 in Houston, TX #reinvent #infosec

Tweet 43/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

closing quote from @StephenSchmidt. this was a great leadership session (as expected), canโ€™t wait to catch the first 10m on replay #reinvent #security

Tweet 44/44 ๐Ÿ‘‡ Next tweet ๐Ÿ‘† Start

. @StephenSchmidt even gets in the โ€œPlease complete the session surveyโ€ plug at the end! ๐Ÿคฃ /๐Ÿงต #reinvent #security