You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Next »

In consultation with Cornell IT Security Office and Cornell financial administrators, two "standard" configurations of AWS accounts have been defined, one for general uses and one for research. Each configuration follows AWS, Cornell, and security best practices.

 

TO DO : nat gateway, ip space, shibboleth, duo, fire walls, security groups, etc.

 

 Link/DescriptionGeneral ConfigurationResearch Configuration
    
    
    
    
Security - AWS Config enabled yy
Security - CloudTrail enabled for all activity in all regions yy
Security - root account protected with multifactor authenticationroot account should not be used for regular administration and MFA key should be locked in secure locationyy
Security - no access keys associated with root account yy
Security/Business - integrated with CloudCheckr yy
Security - user access controlled by Cornell AD group membership and integrated with Cornell Shibboleth y?
Security - access for users with administrative privileges utilize Cornell Duo for authentication y?
    
    
    
    
  • No labels