Cloud Computing and Visualisation Category Banner Image

AWS Security Governance at Scale

  • Length 1 day
Course overview
View dates &
book now

Why study this course

Security is foundational to AWS. Governance at scale is a new concept for automating cloud governance that can help companies retire manual processes in account management, budget enforcement, and security and compliance. By automating common challenges, companies can scale without inhibiting agility, speed, or innovation. In addition, they can provide decision makers with the visibility, control, and governance necessary to protect sensitive data and systems.

In this course, you will learn how to facilitate developer speed and agility, and incorporate preventive and detective controls. By the end of this course, you will be able to apply governance best practices.


Request Course Information


What you’ll learn

This course is designed to teach participants how to:

  • Establish a landing zone with AWS Control Tower

  • Configure AWS Organisations to create a multi-account environment

  • Implement identity management using AWS Single Sign-On users and groups

  • Federate access using AWS SSO

  • Enforce policies using prepackaged guardrails

  • Centralise logging using AWS CloudTrail and AWS Config

  • Enable cross-account security audits using AWS Identity and Access Management (IAM)

  • Define workflows for provisioning accounts using AWS Service Catalog and AWS Security Hub


AWS Partner Logo - Advanced Tier

AWS at Lumify Work

Lumify Work is an official AWS Training Partner for Australia, New Zealand, and the Philippines. Through our Authorised AWS Instructors, we can provide you with a learning path that’s relevant to you and your organisation, so you can get more out of the cloud. We offer virtual and face-to-face classroom-based training to help you build your cloud skills and enable you to achieve industry-recognised AWS Certification.


Who is the course for?

This course is intended for:

  • Solutions architects, security DevOps, and security engineers


Course subjects

Course Introduction

  • Instructor introduction

  • Learning objectives

  • Course structure and objectives

  • Course logistics and agenda

Module 1: Governance at Scale

  • Governance at scale focal points

  • Business and Technical Challenges

Module 2: Governance Automation

  • Multi-account strategies, guidance, and architecture

  • Environments for agility and governance at scale

  • Governance with AWS Control Tower

  • Use cases for governance at scale

Module 3: Preventive Controls

  • Enterprise environment challenges for developers

  • AWS Service Catalog

  • Resource creation

  • Workflows for provisioning accounts

  • Preventive cost and security governance

  • Self-service with existing IT service management (ITSM) tools

Lab 1: Deploy Resources for AWS Catalog

  • Create a new AWS Service Catalog portfolio and product.

  • Add an IAM role to a launch constraint to limit the actions the product can perform.

  • Grant access for an IAM role to view the catalog items.

  • Deploy an S3 bucket from an AWS Service Catalog product

Module 4: Detective Controls

  • Operations aspect of governance at scale

  • Resource monitoring

  • Configuration rules for auditing

  • Operational insights

  • Remediation

  • Clean up accounts

Lab 2: Compliance and Security Automation with AWS Config

  • Apply Managed Rules through AWS Config to selected resources

  • Automate remediation based on AWS Config rules

  • Investigate the Amazon Config dashboard and verify resources and rule compliance

Lab 3: Taking Action with AWS Systems Manager

  • Setup Resource Groups for various resources based on common requirements

  • Perform automated actions against targeted Resource Groups

Module 5: Resources

  • Explore additional resources for security governance at scale

Please note: This is an emerging technology course. Course outline is subject to change as needed.


Prerequisites

Before attending this course, participants should have completed the following:

Required:


Terms & Conditions

The supply of this course by Lumify Work is governed by the booking terms and conditions. Please read the terms and conditions carefully before enrolling in this course, as enrolment in the course is conditional on acceptance of these terms and conditions.


Request Course Information

Personalise your schedule with Lumify USchedule

Interested in a course that we have not yet scheduled? Get in touch, and ask for your preferred date and time. We can work together to make it happen.



Offers

Continue your learning experience online with Lumify Plus
Lumify Plus (formerly DDLS Plus) is your online learning pathway to extend knowledge beyond courses. Get resources to help you practice what you learned and prepare for future courses, exams and certifications.
AWS Jumpstart Bundles
Introducing the latest on AWS courses. Lumify Work delivers a large range of accredited AWS training courses and is an official AWS Training Partner.