Tgix’s client is a non-profit organization that is dedicated to finding a cure for Parkinson’s disease through an aggressively funded research agenda and to ensuring the development of improved therapies for those living with Parkinson’s today.
The organization needed to ensure that the AWS environment which housed the core data and applications was secure, compliant, and resilient. Given the sensitive nature of the participant’s PHI data and regulatory compliance requirements, the organization aimed to identify and remediate any vulnerabilities in the cloud infrastructure and applications to protect their data assets and maintain a robust security posture.
The security assessment involved a comprehensive review of the organization’s AWS environment, including production, non-production, and shared services accounts. Interviews were conducted with stakeholders and key IT staff to gather insights along with reviews of various documents and runbooks that were maintained. This was followed by a detailed examination of the infrastructure, both manually and utilizing automated tools to collect and process information pertaining to the AWS accounts and resources in order to validate configurations and identify potential issues.
Tgix’s security team performed the following activities:
The detailed activities ensured a thorough assessment of the organization’s AWS environment, identifying critical issues and providing actionable recommendations to enhance security, compliance, and operational efficiency. A timeline for the remediation effort was put together and shared with the IT team.
Issues that needed immediate attention included implementation of WAF and other advanced security controls, upgrading of AMIs and configuring of robust DR processes. Security training for staff was pointed out as vital for maintaining a robust security posture. The various best practices in the environment were also pointed out, such as the use of infrastructure as code, consistent tagging practices, and up-to-date documentation.
VPC (Network)
EC2 (Compute)
ECS (Containerization)
Lambda (Serverless Compute)
API Gateways (App Delivery),
PostgreSQL RDS (Database),
ALB (Load Balancers),
S3 (Storage),
Route 53 (DNS)
AWS KMS (Key Management)
CloudFront (CDN)
AWS Secrets Manager
AWS CloudWatch, CloudTrail, and Config
If you’re dealing with complex infrastructure, security requirements, deployment speeds, or looking for cost efficiencies, contact us today for a no-obligation brainstorm.
Solutions
© Copyright 2024 – Tgix – All Rights Reserved