You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 18 Next »



Quick link to this page: https://bit.ly/cornell-aws-security


See "Resources" sections below for links to workshop and exercise materials.

Summary

This AWS training will cover many aspects of security in AWS, mostly focused on Identity and Access Management (IAM). The first session provides a basic introduction to IAM concepts and best practices. The second session covers intermediate and advanced IAM topics. Both sessions include hands-on exercises and coverage of Cornell-specific security configurations and tools. Both sessions are jointly presented by AWS and Cornell staff. Sessions are remotely presented over about 4 hours, including breaks and hands-on exercises.

Details

Session 1

Session 2


Agendas

Session 1 – AWS Security - Introduction & Basic Topics

TimeTopicDetails
9:00-9:10Welcome & Introduction
9:10-9:40Shared Responsibility Model
9:40-11:00Identity best practices on AWS
  • IAM concepts
  • How to use IAM properly, best practices, and guidance
  • Resource policies versus IAM policies
  • Using roles
11:00-11:15Break
11:15-11:30Using CloudShell
11:30-1:00Practical AWS Security Basics
  • Cornell-specific account access
  • Trusted Advisor
  • S3 public access
  • Network security
  • CloudCheckr Best Practices reporting

(Optional)

1:00-1:30

Optional Q&A



Session 1 Resources


Session 2 – AWS Security - Intermediate & Advanced Topics

TimeTopicDetails
9:00-9:10

Welcome & Introduction


9:10-10:10IAM and Identity best practices on AWS – Intermediate/Advanced Topics
  • Permission boundaries
  • Policy validation
10:10-11:00CloudTrail
  • Introduction to CloudTrail
  • Cornell standard CloudTrail configuration
11:00-11:15Break
11:15-1:00AWS Security at Cornell
  • Cornell-specific account access (repeated from Session 1)
  • AWS Config
  • IAM Access Analyzer
  • Exposed Access Keys

(Optional)

1:00-1:30

Optional Q&A



Session 2 Resources


  • No labels