Listing Thumbnail

    AWS Network and Security Design: VPC, IAM, Firewalls, and Detection

     Info
    Design the network and security foundations your AWS environment will run on, in one engagement instead of two. VSO architects Amazon VPC and subnet layout, AWS Transit Gateway and AWS Cloud WAN topology for multi-account and multi-Region connectivity, Amazon Route 53 DNS, and hybrid links over AWS Direct Connect or AWS Site-to-Site VPN, alongside multi-account structure in AWS Organizations, IAM roles and permission boundaries, federated access through AWS IAM Identity Center, encryption standards on AWS KMS, perimeter protection with AWS Network Firewall, AWS WAF, and AWS Shield, and detection through AWS Security Hub CSPM, Amazon GuardDuty, and Amazon Inspector. Suitable for new environments and for existing estates that have grown past their original design.

    Overview

    Network and security architecture are the two design decisions that are most expensive to change after the fact, and they depend on each other: account boundaries shape the network, and network paths shape what security controls are needed where. VSO designs both together, documenting every requirement and decision so the landing zone build and the migration that follow are implementation rather than rediscovery.

    Network architecture. With this service VSO will:

    • Identify the AWS Regions and Availability Zones to deploy in, balancing cost, redundancy, and performance
    • Design multi-account connectivity with AWS Transit Gateway, and AWS Cloud WAN for designs that span multiple AWS Regions
    • Recommend AWS Direct Connect or AWS Site-to-Site VPN for hybrid access, and document routing to AWS for the future state
    • Plan and allocate CIDR blocks using Amazon VPC IP Address Manager (IPAM)
    • Create and document Amazon VPC and subnet design and the hybrid networking design
    • Design Amazon Route 53 DNS and resolver architecture, including hybrid name resolution, with Route 53 Resolver DNS Firewall to block resolution of malicious domains
    • Apply AWS PrivateLink for private service access where required

    Security architecture. VSO determines when workloads should be separated by AWS account and uses that to build a multi-account organizational design in AWS Organizations, enforced through AWS Control Tower where one is in place. In documenting your security requirements, we define and document:

    • User and administrator management through IAM roles and permission boundaries, validated with IAM Access Analyzer
    • Sign-in guidelines including multi-factor authentication and federated access through AWS IAM Identity Center
    • Data encryption requirements in transit and at rest using AWS KMS, including key rotation and access policy
    • Network security requirements covering security groups, network ACLs, AWS Network Firewall at inspection points, AWS WAF for web-facing applications, and AWS Shield for DDoS protection
    • Application allow listing
    • Detection and response coverage using AWS Security Hub CSPM, Amazon GuardDuty, Amazon Inspector, and AWS Config, with Amazon Security Lake centralizing security data and AWS Audit Manager producing the evidence regulated frameworks require.

    Decisions made early carry lingering risk and cost implications that cloud consumers are often unaware of. VSO makes its AWS network and security experience available in an accessible form, so you reach the level of security your environment needs while staying aware of cost and budget.

    Deliverables

    • Detailed network drawing and documented network design, including decision points
    • Documented multi-account organizational design
    • Documented IAM and defense-in-depth practices
    • Documented encryption requirements and decisions log
    • Network security diagram and network security document
    • Input to the agile backlog for implementation

    Highlights

    • Network and security architecture designed together, so account boundaries, network paths, and controls are consistent before anything is built.
    • Multi-account connectivity on AWS Transit Gateway with Amazon VPC, Amazon Route 53, and hybrid access through AWS Direct Connect or AWS Site-to-Site VPN.
    • Multi-account design in AWS Organizations with IAM roles and permission boundaries, encryption on AWS KMS, perimeter protection with AWS Network Firewall, AWS WAF, and AWS Shield, and detection through AWS Security Hub CSPM, Amazon GuardDuty, and Amazon Inspector.

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Pricing

    Custom pricing options

    Pricing is based on your specific requirements and eligibility. To get a custom quote for your needs, request a private offer.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Support

    Vendor support

    Sales Support: Please reach out to vsoapn@vso-inc.com  with any questions about VSO services, contract options, or pricing terms.

    Technical Support: For help with onboarding, configuration, or ongoing support for your VSO solution, please reach out to aws-support@vso-inc.com .

    Software associated with this service