Feeds

AWS CISO needs permission to visit his data centres

He doesn't mind and you shouldn't either because they're not that interesting

Internet Security Threat Report 2014

Amazon Web Services' General Manager and Chief Information Security Officer Stephen E. Schmidt is not allowed to make unannounced visits to the company's data centres.

Speaking at the AWS Summit 2012 in Sydney today, Schmidt explained that he has to ask for permission from the relevant Vice-President before visiting a data centre, as part of the company's security regime.

That regime means customers are also verboten from visits, a stance Schmidt says the company prefers because “tours are not instructive.” There are only so many ways to set up and secure a data centre, Schmidt says. Those methods are well-documented, AWS is aware of them, has deployed those it deems sensible and feels customers cannot learn anything useful from a visit.

Schmidt also said most AWS employees are kept ignorant of its data centres' locations. Addresses for the facilities are not listed on the company's intranet, a security-through-obscurity strategy Schmidt said “helps with protection.” Another obscurity strategy sees the company deliberately construct nondescript buildings.

Employees who can visit the facilities have that privilege revoked and formally re-instated every ninety days and must use “two or more levels of two factor authentication” to enter the building.

AWS also, Schmidt said, reviews log files proactively and a little obsessively.

“We review the logs to ensure we see what we expect, and to check for things we do not expect,” he said. The security team also checks to make sure logs are present, as absent logs or missing entries are eloquent descriptors of security incidents.

Schmidt also said the company has developed a special process to help penetration testers take advantage of its cloud. In the past such tests would likely have been flagged as a denial of service attack, but demand for such services means AWS now whitelists designated assets being used during penetration tests. ®

Beginner's guide to SSL certificates

More from The Register

next story
Docker's app containers are coming to Windows Server, says Microsoft
MS chases app deployment speeds already enjoyed by Linux devs
'Hmm, why CAN'T I run a water pipe through that rack of media servers?'
Leaving Las Vegas for Armenia kludging and Dubai dune bashing
'Urika': Cray unveils new 1,500-core big data crunching monster
6TB of DRAM, 38TB of SSD flash and 120TB of disk storage
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
SDI wars: WTF is software defined infrastructure?
This time we play for ALL the marbles
Windows 10: Forget Cloudobile, put Security and Privacy First
But - dammit - It would be insane to say 'don't collect, because NSA'
Oracle hires former SAP exec for cloudy push
'We know Larry said cloud was gibberish, and insane, and idiotic, but...'
Symantec backs out of Backup Exec: Plans to can appliance in Jan
Will still provide support to existing customers
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.