PeerSpot user
Independent Analyst and Advisory Consultant at Server StorageIO - www.storageio.com
Consultant
Top 20
EFS is NFS version 4 based however it does not support Windows SMB/CIFS, HDFS or other NAS access protocols.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user7707 - PeerSpot reviewer
Owner at a tech consulting company with 51-200 employees
Consultant
Amazon Web Services: Security Processes in the EC2 Cloud

Customer trust and confidence is at the heart of Amazon’s business and with so many customers using Amazon’s platforms to run their business securely and efficiently, Amazon has gone to great lengths to operate and manage a comprehensive control environment. The environment supports secure Amazon Web Services cloud web offerings by ensuring that all necessary policies and processes are used in compliance with AWS certifications.

Within the last few years Amazon Web Services security has achieved notable certifications which include SAS70 Type II audits, PCI DSS Level 1 which involves meeting Payment Card Industry Data Security Standards, ISO 27001 for Information Security Management Systems, and compliance within the Federal Information Security Management Act (FISMA) to properly serve government agency FedRAMP requirements for AWS GovCloud on the Amazon platform.

When Amazon introduced Amazon EC2 it started a process rolling for business customers to run their applications in Amazon’s computing environment. EC2 is the Elastic Compute Cloud which allows business customers to access Amazon’s secure cloud environment through a virtual machine. The platform deploys EC2 security which also supports Amazon Web Services for FedRAMP compliance.

Using Amazon EC2 business customers can create an image of their operating system and applications which is known as an Amazon Machine Image. Once the image is created it is uploaded to Amazon S3 which is Amazon’s Simple Storage Service. The AMI is then registered in Amazon EC2 allowing the customer to summon virtual machines as they are needed. The result is an AWS Virtual Private Cloud for business customers to conduct operations without the exorbitant expense of IT infrastructure. For this reason, Amazon must ensure the environment meets all compliance and security standards hence the acquisition of the certification described earlier.

Amazon EC2 Security Processes

Amazon’s approach to AWS security involves layered security processes which maintain data integrity and provide secure EC2 instances while still maintaining configuration flexibility to meet the individual requirements of EC2 business customers.

  • Administration Hosts: For business customers who require access to the management platform, Amazon uses a level of security to accommodate administration hosts without posing a risk to data integrity and other users. Through the use of AWS Identity and Access Management, this is accomplished by auditing all access activity and using a log to track the activity. If the user accessing the management platform terminates their authentication privileges then the privileges are automatically discontinued which ensures secure AWS applications.
  • Customer Controlled Instances: Amazon EC2 allows for virtual instances which are solely controlled by the customer. Business customers exercise full control and at no time can Amazon intervene by logging in to the customer’s operating system. For this reason, a set of practices is in place to guide the customer on authentication processes for AWS VPC in order to access the virtual instances. This involves designing an authentication and privilege system which can be enabled and disabled according to changing needs of virtual machine users.
  • Firewall: As part of the AWS Security Center, EC2 Business customers have access to a complex firewall solution which can be configured to meet the individual needs of each business customer. For example, the firewall for Amazon EC2 is typically configured by default to block all traffic. If the customer wants to allow inbound traffic they must open the necessary ports to allow inbound traffic while blocking unwanted traffic. The firewall also provides a host of options for setting specific protocols for inbound traffic such as by IP address and other identifications. Added security is in place since the business customer must use their x.509 certificate to change firewall configurations.
  • Xen: Another layer of AWS security for EC2 is the Xen Hypervisor which separates different instances running on the same virtual machine. The firewall is situated in the Xen Hypervisor which means packets for instances must pass through the firewall thereby adding enhanced security to isolated instances.

Finally, Amazon Web Services Cloud uses a layer of security known as Amazon EBS or Elastic Block Storage which restricts access to data snapshots to the specific Amazon Web Services account which created it. Business customers can make the data snapshots available to other AWS accounts however; this process should be carefully considered since there may be files with sensitive information.

Prior to releasing Elastic Block Storage to the customer, Amazon wipes old data in accordance with the National Industrial Security Program guidelines. Plus EBS allows business customers to encrypt their data on the block device using algorithms that comply with individual security standards.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
it_user7707 - PeerSpot reviewer
it_user7707Owner at a tech consulting company with 51-200 employees
Consultant

Hi Henry,

we'll post something on S3 security as well soon. aws.amazon.com

See all 2 comments
Buyer's Guide
Amazon AWS
April 2024
Learn what your peers think about Amazon AWS. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,246 professionals have used our research since 2012.
PeerSpot user
CTO at a healthcare company with 51-200 employees
Vendor
The technical support was a 7 on a scale of 1-10, but dynamic usage and flexibility.

What is most valuable?

Dynamic usage and flexibility in choosing configurations. Also the fact that Amazon’s security team is much larger than anything I could ever assemble gives me reliance that this run time environment is going to be more secure than anything I can deploy.

How has it helped my organization?

I needed to stand up a prototype server that did not conform to my corporate IT standards. By using AWS I was able to stand up my prototype in a few hours, run my demo and be done.

What needs improvement?

The connection between the billing console and the management console is not obvious so shutting down a machine was hard to find initially and resulted in excess billing.

For how long have I used the solution?

I have been using this solution for 5 years.

What was my experience with deployment of the solution?

No issues with deployment.

What do I think about the stability of the solution?

No issues with stability.

What do I think about the scalability of the solution?

No issues with scalability.

How are customer service and technical support?

Customer Service: Customer service was pretty good. It was responsive but it took 2-3 iterations on the billing/Management issue before they understood the problem I ran into.Technical Support: The technical support was a 7 on a scale of 1-20

Which solution did I use previously and why did I switch?

I have used Amazon Elastic Beanstalk and Windows Azure. My primary choice to use AWS was because the prototype server stack was specified as an AMI (Amazon Machine Image).

How was the initial setup?

If you have not used AWS, its not as straightforward as it could be to choose what stack configuration a particular AMI requires before loading it. OTOH the “Amazon Web Service Pricing Calculator” is currently the gold standard for cloud vendors.

What about the implementation team?

We implemented in-house.

What was our ROI?

Not applicable, the ROI came from the agility to quickly standup the environment I needed.

What's my experience with pricing, setup cost, and licensing?

Approximately $200/mo.

Which other solutions did I evaluate?

I have used Azure, and Horuko.

What other advice do I have?

Use the AWS pricing calculator to understand how the services fit together.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Project Manager at a consultancy with 11-50 employees
Real User
Consistent and reliable cloud computing that could use an improved interface
Pros and Cons
  • "Amazon has a much better understanding of the workflow of data scientists and machine learning processes. This is seen by their SageMaker which offers different versions of the models to be used."
  • "I think that the interface could be improved."

What is our primary use case?

Propension ML model implementation, so the tech stack involves ETL, storage and computation capabilities for model design, implemented solution also involves pipelines and events handler for automated runs

How has it helped my organization?

Development of the product has been consistent which is beneficial for data engineers unlike Azure which has changed a lot, causing them much confusion.

What is most valuable?

Amazon has a much better understanding of the workflow of data scientists and machine learning processes. This is seen by their SageMaker which offers different versions of the models to be used.

What needs improvement?

I think that the interface could be improved.

Additionally, they lack good connectors with services within other clouds. For example, it does not integrate well with Power BI which is a Microsoft service.

Sometimes, some of their services can be too complex/technical. It's almost like they tried taking a microservice approach meanwhile the users want a little more integration

In other words the multi-cloud approach is not robustly promoted as there is a noticeable difference in ease of use.

For how long have I used the solution?

I have been using this solution for eight months.

What do I think about the stability of the solution?

just one event where the whole service was down, although im not sure if it was anticipated by the service due to not being the actual service administrator

What do I think about the scalability of the solution?

very good, the tier we used is one of the most basic and still performed with no problems

How are customer service and support?

never had experience with customer service or support

How would you rate customer service and support?

Neutral

How was the initial setup?

pretty straight forward, although this project was 2nd one to be implemented on this cloud, so the customer company had already been up the adoption curve of the service

What about the implementation team?

we provide the implementation as a consulting company soy neither in house or 3rd party as we are the 3rd party

What other advice do I have?

If you are looking to implement Amazon AWS within your company, I would suggest finding someone that already knows some AWS as it has a harder adoption curve.

I would rate it a six out of ten. 

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Director at HALL MARK GLOBAL TECHNOLOGIES
Reseller
Stable environment on a mature cloud platform
Pros and Cons
  • "Newly introduced features advance capabilities."
  • "A scalable and secure product"
  • "An integrated platform would make it easier for administrators to monitor and manage."

What is most valuable?

The scalability and security of Amazon AWS are the most valuable features.

What needs improvement?

There are multiple operational and administrative services on AWS, I am expecting to see an integrated single platform of all the services so that it will be easier for the administrators to monitor and manage.

For how long have I used the solution?

We are resellers of the production services of AWS. I have been working with Amazon AWS for almost 8 years.

What do I think about the stability of the solution?

The AWS products are stable.

What do I think about the scalability of the solution?

The environment is stable. Every time a new feature is introduced, it advances the capabilities. Once the product is deployed, you can scale up easily.

How are customer service and support?

Technical support has been very good.

How was the initial setup?

The initial set up of AWS is easy and not complex.

What's my experience with pricing, setup cost, and licensing?

The pricing is reasonable and comparable to similar services when run on-premise.

What other advice do I have?

All the services and features provided by AWS are good. They are always improving their features.

I recommend implementing the products on Amazon Web Services. It is a stable environment and mature cloud platform. I would rate the product an 8 out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
PeerSpot user
Shehzad Ali - PeerSpot reviewer
Information Security and Compliance Officer at Carnation
Real User
Top 5
Scalable, stable and easy to install with good tech support
Pros and Cons
  • "I like the technical support."
  • "The price of the solution is comparatively quite high in comparison with that of Azure."

What is our primary use case?

We use the solution for managed hosting of the connection servers of some of our clients. 

What is most valuable?

The solution has a vast array of features and services. It offers many upgrades. 

What needs improvement?

The price of the solution is comparatively quite high in comparison with that of Azure. 

For how long have I used the solution?

We have been using Amazon AWS for around two or three years.

What do I think about the stability of the solution?

The solution has good stability.

What do I think about the scalability of the solution?

The solution has good scalability. 

How are customer service and technical support?

I like the technical support.

How was the initial setup?

The initial setup was quite easy. 

What's my experience with pricing, setup cost, and licensing?

The solution could be more cost-effective. 

What other advice do I have?

When it comes to cloud management, I have no complaints at present. 

I am a customer of Amazon. 

As we are, basically, only hosting cloud services, this is geared towards the end user. We manage two or three people.  

I would recommend the solution to others.

Owing to the pricing, I rate Amazon AWS as a nine out of ten. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior System Administrator at KnowledgeNet
Real User
High quality features, flexible, and excellent virtualization capabilities
Pros and Cons
  • "The most valuable features I have found are the Database Migration Service (DMS) for monitoring the host and routing, Route 53, and EC2 tools. The DMS is not available in any other solution that I am aware of. They have a very flexible and professional solution."
  • "If you have not had previous training or studied guides it will be a little difficult to use the solution. However, the difficulty also depends on what you are using the solution for. They can improve by providing more documentation, such as tutorials and videos."

What is our primary use case?

We are using the solution for network virtualization.

What is most valuable?

The most valuable features I have found are the Database Migration Service (DMS) for monitoring the host and routing, Route 53, and EC2 tools. The DMS is not available in any other solution that I am aware of. They have a very flexible and professional solution.

What needs improvement?

If you have not had previous training or studied guides it will be a little difficult to use the solution. However, the difficulty also depends on what you are using the solution for. They can improve by providing more documentation, such as tutorials and videos.

For how long have I used the solution?

I have been using the solution for approximately five years.

What do I think about the stability of the solution?

I have found the stability very good.

What do I think about the scalability of the solution?

The scalability is good.

How are customer service and technical support?

The technical support has been fine in my experience.

What's my experience with pricing, setup cost, and licensing?

The price of the solution is reasonable.

What other advice do I have?

Amazon AWS is the most powerful tool and is at the top for cloud and for virtualization. It has many features and products. It is wonderful and I keep learning from them.

I would highly recommend this solution to others.

I rate Amazon AWS a ten out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Chief Operating Officer at FarEye Digital Logistics
Real User
Solid solution that offers a wide variety of features
Pros and Cons
  • "The main feature that I like the most is the variety of solutions that it provides. It provides some analysis, business information and more. It provides a wide variety of services."
  • "One area that could be improved is in data management. They could improve on the data side. For example, I see others with better cloud services and larger data computing capabilities."

What is our primary use case?

It is on the public cloud and we are using it for multiple purposes, including data storage and production.

What is most valuable?

The main feature that I like the most is the variety of solutions that it provides. It provides some analysis, business information and more. It provides a wide variety of services.

What needs improvement?

One area that could be improved is in data management. They could improve on the data side. For example, I see others with better cloud services and larger data computing capabilities.

For how long have I used the solution?

We have been using Amazon AWS around four or five years now. 

We use it as a customer. 

What do I think about the scalability of the solution?

I think the scalability on the computer side is good, not too much of a challenge. It is sometimes on the database side where we encounter challenges on the scalability. Sometimes it is not easy to scale beyond that point and we get a scalability error on the computer.

We have around 10 people working on it who do the maintenance, automation, and monitoring.

How are customer service and technical support?

I would say support is average.

A lot of times I would prefer a better turnaround time in terms of the response we're getting, it should be faster. Often we have to wait a long time before the problem is solved. So it is generally a very poor product resolution.

How was the initial setup?

My initial setup was quite straightforward.

What about the implementation team?

I implemented it myself with one other person.

What other advice do I have?

I would say to somebody who is moving to the cloud that it is very easy to start with. At the same time it is also important to make sure they have a very strong partner or a very strong team in-house.

On a scale of one to ten, I would rate Amazon AWS an eight on product and technology. But overall I would rate them seven if I include services and support.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Amazon AWS Report and get advice and tips from experienced pros sharing their opinions.
Updated: April 2024
Buyer's Guide
Download our free Amazon AWS Report and get advice and tips from experienced pros sharing their opinions.