AWS re:Inforce Home
Subscribe

re:Inforce 2022

Learn more about attending the premier cloud security conference.
Why attend
Agenda
Keynote
Leadership sessions
Sponsors
Venue
Transportation
Learn
AWS Training and Certification
Breakout content
Gamified learning
Security Learning Hub
Community
Attendee Guides
FAQs
Health measures
Mobile App

Attendee Guides

Governance and compliance By Mark Nunnikhoven, AWS Community Hero

Overview

  • This guide aims to help re:Inforce attendees who are focused on governance and compliance—those people that didn’t just fall asleep hearing the terms “governance” and “compliance.” These areas of security can get knocked unnecessarily, but if I’ve learned anything in my twenty-five plus years working in security, it’s that they are critical aspects of building out a strong security practice. Governance helps set strong guidelines for working in the cloud. It makes sure that the business can innovate safely. All those fancy digital transformation goals will only come to be if you’ve got a strong governance framework in place. And compliance? Compliance simply makes sure that your practice is achieving what you set out to do. Together, they are the foundation that the rest of your practice is built on. Here are my top recommended sessions to learn more about this critical area of security.
Session Type

Breakout Sessions

DPP101 – Building privacy compliance on AWS

This session provides a great baseline for privacy-by-design thinking. This is a key step for identifying the data you’re processing and storing in your business. By adopting this approach, you can set up stronger governance and a continuous compliance practice.

DPP302 – Navigating AWS documents from a data protection and privacy view

We’ve needed this session for a while. The focus is simple: how does AWS help you protect your data in the AWS Cloud? This session lays out what steps AWS takes and where to find the documentation and proof of those activities.

DPP305 – To Europe and beyond: Simplify privacy needs in new markets

The title may not be the most exciting, but this session covers a serious challenge for most global business: navigating compliance with EU data-transfer requirements. In this session, AWS experts will help you understand the requirements and how to navigate them using the tools available in the AWS Cloud.

DPP308 – High assurance with provable security

The AWS provable security initiative has been making waves the past few years. From analyzer products to a ton of improvements behind the scenes, this team’s work has had a major impact whether you know it or not. This session highlights some of the key features built from this initiative and how you can use them to improve your security posture.

GRC201 – Learn best practices for auditing AWS with Cloud Audit Academy

Nothing puts your governance and compliance efforts to the test like an audit. Understanding how audits are conducted is key to making sure that your practice aligns with expectations. This session explores the fantastic content in the Cloud Audit Academy and how it helps shape how auditors approach their work in the AWS Cloud.

GRC205 – Crawl, walk, run: Accelerating security maturity

As much as we’d all like to have a completely automated security practice immediately, that isn’t going to happen. This session walks through a step-by-step roadmap to security automation. It takes a pragmatic approach and explains how to get the most out of the features and functionality already available in the AWS Cloud.

GRC401 – Risk management in machine learning and data science

This in-depth session looks at the unique challenges facing machine learning and data science environments. The vast amounts of data used with these approaches makes governance critical. Learn about how you should be approaching the security of these environments so that you can maximize the return on your investment.

IAM309 – Designing a well-architected identity & access management solution

Identity and access management is the single most important aspect of any security practice in the cloud. This session isn’t focused on compliance or governance but on making sure that your solution is a foundation that you can build on now and moving forward.

NIS306 – Automating patch management and compliance using AWS

Every time there’s a new vulnerability, the first thing you’ll hear from everyone is, “Patch it.” Despite being an easy concept to understand, effective patching is a constant logistics challenge. This session looks at how you can automate much of this process while recording the evidence needed for your continuous compliance needs.

 

Session Type

Builder's Sessions

DPP355 – Codify your compliance: Classifying your data at scale

Classifying your data is one of the top problems when it comes to governance and compliance. This builders’ session explores how you can combine Amazon Macie, Amazon EventBridge, and AWS Step Functions to automate a lot of the heavy lifting for data classification. It’s these types of solutions that really take your practice to the next level.

Session Type

Leadership sessions

SEC203-L – Security mindfulness

You can’t run a strong compliance and governance practice without good people. This leadership session explores how you can identify and invest in security talent to build out a top-notch team.

Conclusion

Security teams often want to focus on the latest zero day or novel attack techniques. That’s important and interesting work, but you’ll make more strides for your business with a strong governance program that includes regular compliance checks. GRC (governance, risk, and compliance) may not be as exciting, but these foundational elements are the key to aligning with the security pillar of the AWS Well-Architected Framework. You can’t build well in the cloud without them.
Home of AWS re:Inforce

A learning conference focused on cloud security, compliance, identity, and privacy.

Thank you for subscribing to re:Inforce updates.

Join the AWS Cloud community

Agenda Code of conduct FAQs Keynote Sponsors Terms and Conditions

Privacy • Site Terms • Cookie Preferences • © 2022, Amazon Web Services, Inc. or its affiliates. All rights reserved.