Web Mapping And Security A View From Esri Bonnie Stayer .

Transcription

2013 AWS Worldwide Public Sector SummitWashington, D.C.Web Mapping and Security – A View From EsriBonnie Stayer – Solutions EngineerDan O’Leary – Director, D.C. SoftwareDevelopment Center

Introduction Cloud security affected by many moving parts–––––Cloud security standards evolving – FISMA/FedRAMP“Cloud First” initiativeAdvancing ArcGIS security capabilitiesEvolution of cloud provider capabilitiesMobilization of workforce2013 AWS Worldwide Public Sector Summit

Introduction Choosing an appropriate cloud deployment– Not just technical issues/concerns– Political push/pull issues Cloud First vs. “We don’t trust cloud providers, yet”– No silver bullet for all cloud security concerns Esri provides a roadmap of options and best practices,not just a “Safe” button to push2013 AWS Worldwide Public Sector Summit

Esri – A Global CompanyUS Regional OfficesInternational SatellitesUS SatellitesInternational Distributors2013 AWS Worldwide Public Sector Summit

ArcGIS – A Complete PlatformDesktopWebDevice ArcGISOnlineServerOnline Contentand Services2013 AWS Worldwide Public Sector SummitData ManagementVisualizationAnalysisDissemination

Cloud Implementation OptionsServiceModelNon-CloudIaaSSaaSAGS Your LocationAGS in AWSArcGIS OnlineDeployment On-PremisesModelYour locationManagementModelCommunityHybridAWS GovCloudYour Loc AWSSelf-ManagedManagedYouEsriOn-premises2013 AWS Worldwide Public Sector SummitPublicAWS/AzureCloud

ArcGIS Server Security

Architecture

Deploying ArcGIS Server in AWS Pre-built AMIs– Windows, Linux– Include RDBMS– Launch instance, authorize license, create site Cloud Builder– Desktop application– Simplifies assembly and administration2013 AWS Worldwide Public Sector Summit

ArcGIS IaaS Security Question– If my cloud IaaS is FISMA/FedRAMP accredited and I deploy my app into that cloud,is the overall implementation FISMA/FedRAMP equivalent? Answer– No IaaSFISMADefaultArcGISQuestion – Part 2– Okay, so it’s not FISMA/FedRAMP equivalent, but the IaaS by itself ensures thesolution is “secure enough”, right? Answer– No2013 AWS Worldwide Public Sector Summit

Security ResponsibilityDataCustomerManagedPlatform, Applications, Identity & AccessManagementOperating System, Network, & FirewallServer InfrastructureCloudProviderManaged(Servers, Storage, Racks)Network Infrastructure(Switches, Routers, Cables, SAN)Data Center(Physical facility, UPS, Cooling)2013 AWS Worldwide Public Sector Summit

ArcGIS Online Security

How is it ntArcGISOnlineProfessionalGIS2013 AWS Worldwide Public Sector SummitWorkAnywhereEnterpriseIntegration

Security ResponsibilityApplicationCustomer ConfiguredWeb Admin App(Org-wide settings, Management)ApplicationEsri ManagedEnd-User Org Portal(Create maps, Share, Discover)ArcGIS Online Application(Portal, Map Services, Account Management)Data(Portal, Index, Hosted)OS &MiddlewareMiddlewareEsri & Cloud ProviderManagedOperating SystemServer Infrastructure(Servers, Storage, Racks)InfrastructureCloud ProviderManagedNetwork Infrastructure(Switches, Routers, Cables, SAN)Data Center(Physical facility, UPS, Cooling)2013 AWS Worldwide Public Sector Summit

Deployment IntranetBasemapsIntranetPortalCloud2013 AWS Worldwide Public Sector ses

Hybrid DeploymentArcGISOnlineWeb ew2013 AWS Worldwide Public Sector Summit

Assessment & Authorization

Federal A&A ebServices&MS AzureFedRAMPModCSP orAWSGovCloudFISMAModEsriManagedAWS,CSPQ1 2013Q2 2013ImplementQ4 20132014ATOFISMAUSDAAlignmentFacilitateQ3 ncorporateLessons LearnedFedRAMPMod2013 AWS Worldwide Public Sector SummitAlignmentEstablishAGS FedImage ImplementATO

ArcGIS Online Security Certification Efforts In Place– Esri Data Center Operations - SSAE 16 Type 1– Expanded to Managed Services in 2012– Safe Harbor Self-Certification Currently Pursuing– FISMA Low Accreditation Includes 3rd party assessmentExpected completion over next several monthsFuture– FedRAMP Moderate Incorporates more advanced security controls2013 AWS Worldwide Public Sector Summit

2013 AWS Worldwide Public Sector Summit

Thank You

Cloud Builder – Desktop application – Simplifies assembly and administration . 2013 AWS Worldwide Public Sector Summit ArcGIS IaaS Security . Esri Managed Infrastructure Cloud Provider Managed Server Infrastructure (Servers, Storage, Racks