Overview
Network and security architecture are the two design decisions that are most expensive to change after the fact, and they depend on each other: account boundaries shape the network, and network paths shape what security controls are needed where. VSO designs both together, documenting every requirement and decision so the landing zone build and the migration that follow are implementation rather than rediscovery.
Network architecture. With this service VSO will:
- Identify the AWS Regions and Availability Zones to deploy in, balancing cost, redundancy, and performance
- Design multi-account connectivity with AWS Transit Gateway, and AWS Cloud WAN for designs that span multiple AWS Regions
- Recommend AWS Direct Connect or AWS Site-to-Site VPN for hybrid access, and document routing to AWS for the future state
- Plan and allocate CIDR blocks using Amazon VPC IP Address Manager (IPAM)
- Create and document Amazon VPC and subnet design and the hybrid networking design
- Design Amazon Route 53 DNS and resolver architecture, including hybrid name resolution, with Route 53 Resolver DNS Firewall to block resolution of malicious domains
- Apply AWS PrivateLink for private service access where required
Security architecture. VSO determines when workloads should be separated by AWS account and uses that to build a multi-account organizational design in AWS Organizations, enforced through AWS Control Tower where one is in place. In documenting your security requirements, we define and document:
- User and administrator management through IAM roles and permission boundaries, validated with IAM Access Analyzer
- Sign-in guidelines including multi-factor authentication and federated access through AWS IAM Identity Center
- Data encryption requirements in transit and at rest using AWS KMS, including key rotation and access policy
- Network security requirements covering security groups, network ACLs, AWS Network Firewall at inspection points, AWS WAF for web-facing applications, and AWS Shield for DDoS protection
- Application allow listing
- Detection and response coverage using AWS Security Hub CSPM, Amazon GuardDuty, Amazon Inspector, and AWS Config, with Amazon Security Lake centralizing security data and AWS Audit Manager producing the evidence regulated frameworks require.
Decisions made early carry lingering risk and cost implications that cloud consumers are often unaware of. VSO makes its AWS network and security experience available in an accessible form, so you reach the level of security your environment needs while staying aware of cost and budget.
Deliverables
- Detailed network drawing and documented network design, including decision points
- Documented multi-account organizational design
- Documented IAM and defense-in-depth practices
- Documented encryption requirements and decisions log
- Network security diagram and network security document
- Input to the agile backlog for implementation
Highlights
- Network and security architecture designed together, so account boundaries, network paths, and controls are consistent before anything is built.
- Multi-account connectivity on AWS Transit Gateway with Amazon VPC, Amazon Route 53, and hybrid access through AWS Direct Connect or AWS Site-to-Site VPN.
- Multi-account design in AWS Organizations with IAM roles and permission boundaries, encryption on AWS KMS, perimeter protection with AWS Network Firewall, AWS WAF, and AWS Shield, and detection through AWS Security Hub CSPM, Amazon GuardDuty, and Amazon Inspector.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Resources
Vendor resources
Support
Vendor support
Sales Support: Please reach out to vsoapn@vso-inc.com with any questions about VSO services, contract options, or pricing terms.
Technical Support: For help with onboarding, configuration, or ongoing support for your VSO solution, please reach out to aws-support@vso-inc.com .
Software associated with this service
