Security Solutions Optimized for Amazon Web Services
Security in public clouds is different. Are you prepared? Symantec has teamed up with Amazon Web Services to deliver security that is optimized for your AWS applications and instances.
Businesses and public sector organizations are no longer just using the public clouds like Amazon Web Services (AWS) for their test and development environments. Increasingly, they are using public clouds to migrate critical applications running on unsupported on-premise legacy platforms, as well as to deploy new cloud-native applications. A 2014 Forrester survey notes that “cloud-first” policy is increasingly the norm for new workload deployments. Organizations are also turning to public clouds like AWS to burst services, and meet seasonal spikes in demand.
Security and compliance in public clouds are different. Applications in these environments are componentized, preconfigured, and based on a library of templates. These applications are dynamic, mobile, orchestrated, and automated. Architectural differences between public clouds and on-premise infrastructures make it difficult to retrofit on-premise security solutions for public cloud environments. Traditional security solutions require deep expertise, extensive configuration, and long tuning cycles- thus, are not suited for the public cloud. Understanding these differences and challenges, and offering security that is optimized for public cloud architectures are critical to removing barriers to adoption.
Symantec understands the distinct requirements for security in public cloud and offer security products that are optimized for AWS; at the same time, enables customers to simplify management with their on-premise security operations.
By taking the same proven solutions that organizations have come to rely on and extending them to Amazon EC2 and Amazon S3, organizations can now enjoy the peace of mind knowing their people and information are protected by Symantec solutions.
Control Compliance Suite delivers business-aware security and risk visibility so that customers are effectively able to align priorities across security, IT operations, and compliance. It automates continuous assessments and delivers a unified view of security controls and vulnerabilities. Customers can deploy Control Compliance Suite on-premise or on Amazon Web Services (AWS) to assess their AWS instances and applications. With Control Compliance Suite, customers are able to harden the data center, prioritize security remediation, enable the secure migration to the software-defined data center, and support continuous assessments for Cyber Security and Continuous Monitoring.
Symantec Protection Engine for Cloud Services is a flexible and feature rich client/server application that allows customers to incorporate malware and threat detection technologies into almost any application. Protection Engine includes Symantec's proprietary, patented URL categorization technology and industry-leading malware protection for fast, scalable, and reliable content scanning services. These services help organizations protect their data and storage systems against the ever-growing malware threat landscape.
Symantec Endpoint Protection provides defense in depth, whether in the cloud or on-premises. Get machine learning, behavioral, cross-vector protection, and network protection/ firewall as part of complete anti-malware protection. Validated by third-party tests, Symantec Endpoint Protection is the most effective intelligent endpoint security solution available on the market. Reduce the complexity of advanced threat protection with AWS workloads and maximize your AWS protection and performance with Symantec Endpoint Protection. Available two ways - BYOL or metered.
The Symantec Endpoint Protection Manager runs on an EC2 instance. Depending on your instance count, choose a matching instance size: 10 instances - m4.large; 100 instances - m4.xlarge; 250 instances - m4.2xlarge; 500 instances - c4.2xlarge.
Symantec Data Center Security: Server Advanced and Symantec Data Center Security: Monitoring Edition both provide security monitoring of AWS public and hybrid clouds (VPCs). It delivers security configuration monitoring, file integrity monitoring, whitelisting with application control for on-premise and off-premise data centers, and security automation across the cloud environment via REST API.
Symantec Data Center Security: Monitoring Edition is intended to deliver continuous security monitoring and compliance reporting across physical and virtual servers, as well as AWS and Openstack clouds.
Symantec Data Center Security: Server Advanced offers all the features and benefits of the Monitoring Edition but also adds server hardening for physical and virtual servers and OpenStack Keystone, including out-of the-box host IDS and IPS policies, sandboxing and process access Control (PAC), host firewall, compensating HIPS controls, file and system tamper prevention, and application and device control.
Customers that use either Symantec Data Center Security: Server Advanced or Symantec Data Center Security: Monitoring Edition will have the ability to simplify security monitoring and compliance reporting across their hybrid data centers.
Customers can now confidently deploy workloads containing confidential data to the Amazon cloud with Symantec’s market-leading data loss prevention (DLP) solution. Symantec Data Loss Prevention provides comprehensive coverage and unified management of your confidential data across the Amazon Web Services (AWS) cloud and your on-premises environment.
Symantec Data Loss Prevention is a content-aware data security solution that discovers, monitors and protects confidential data stored across the AWS cloud, including AWS-hosted instances of Microsoft Exchange and Microsoft SharePoint. Unlike other security solutions that provide limited DLP controls, Symantec delivers deep content inspection, sophisticated policy and incident management, and proven scalability and performance. With AWS and Data Loss Prevention, businesses can confidently deploy workloads to the cloud without sacrificing control over of their confidential data.
Symantec VIP Access Manager is a next generation access control platform, the foundation for an information protection solution for the cloud; that integrates Single Sign-On (SSO) with strong authentication (Symantec Validation and ID Protection Service and Managed PKI Service), access control, and user management. In the cloud, where a traditional enterprise perimeter does not exist, VIP Access Manager fills the gap by helping enterprises adopt cloud-based applications while maintaining proper risk management and compliance measures to protect enterprise data and follow regulations. Symantec VIP Access Manager is available on-premises or as a hosted service on the Amazon Web Services (AWS) cloud. Virtually any cloud-based application is supported with easy to create connectors. Also included is a built-in user directory for self service provisioning and integration with common identity providers to enforce security and compliance for applications without getting in the way of productivity. The AWS cloud offers a secure, scalable infrastructure to support VIP Access Manager as it scales with an organization's need to manage additional apps, devices, and users.
Cloud computing is an option for computing in which dynamically scalable and often virtualized resources are provided as a service over a network. Hosting services on the internet are referred to as "Public Clouds," while hosting services on an internal network is referred to as a "Private Cloud."
Amazon Web Services (AWS) is an infrastructure-as-a-service provider, serving companies of all sizes. With AWS, companies can requisition compute power, storage, and other services, gaining access to a suite of elastic IT infrastructure services, as business demands them.
The five essential characteristics of cloud computing:
For More information on Cloud Computing, see the NIST Special Publication 800-145, “The NIST Definition of Cloud Computing”.
Symantec recognizes Amazon Web Services (AWS) as a leading cloud infrastructure-as-a-service provider and has partnered with AWS to bring Symantec's products that are optimized for these environments. The Symantec products that support AWS are designed to deliver security at the application and instance levels, which are the subscriber-controlled components in the AWS Shared Security Responsibility Model. Symantec therefore complements the cloud infrastructure and network security that is provided by AWS security services.
Symantec does not endorse or resell AWS offerings nor does AWS resell any of Symantec's products. Customers are encouraged to evaluate the product and service offerings made available by Symantec and AWS, and identify how each solution would benefit a particular use-case.
See the “Products” section for information on Symantec security solutions for AWS.