Amazon EC2 unterstützt jetzt Microsoft SQL Server 2019

Amazon EC2 unterstützt jetzt Microsoft SQL Server 2019, die neueste Version von Microsoft SQL Server. Wenn Sie SQL Server 2019 auf Amazon EC2 ausführen, profitieren Sie von der Skalierbarkeit, Leistung und Elastizität der AWS Cloud, während sie die aktuellsten Funktionen, die in Microsoft SQL Server 2019 verfügbar sind nutzen, wie die erweiterte PolyBase und intelligente Abfrageverarbeitung nutzen. Sie können die SQL Server 2019 Always-On Availability Groups für eine verbesserte Verfügbarkeit über mehrere AWS Availability Zones („AZs“) hinweg bereitstellen. Mit AWS profitieren Sie von allen Sicherheitsfunktionen, wie Amazon VPC, Datenverschlüsselung und Integration mit Microsoft AD, während sie die Vorzüge der aktuellsten Sicherheitsverbesserungen, die von SQL Server 2019 bereitgestellt werden, so z. B. Always Encrypted sichere Enklaven, Datenklassifikation, eingebaute Überwachung und Zertifikatverwaltung mit SQL Server Configuration Manager, genießen.  
Quelle: aws.amazon.com

Amazon CloudWatch führt konto- und regionsübergreifende Dashboards ein

Amazon CloudWatch bietet jetzt konto- und regionsübergreifende Dashboards, mit denen Sie allgemeine operative Dashboards erstellen und mit nur einem Klick Drilldowns in spezifischere Dashboards anderer AWS-Konten durchführen können, ohne sich in verschiedenen Konten an- und abmelden oder AWS-Regionen wechseln zu müssen. Die Funktion ist für zentralisierte operative Teams, DevOps-Entwickler und Servicebesitzer konzipiert, die Anwendungen in verschiedenen Regionen und Konten überwachen, analysieren und auftretende Fehler beheben müssen. Durch die Fähigkeit, leistungsbezogene und operative Daten konto- und regionsübergreifend zu visualisieren, zu aggregieren und zusammenzufassen, kann die durchschnittliche Dauer bis zur Problemlösung reduziert werden.
Quelle: aws.amazon.com

4 steps to a successful cloud migration

Digital transformation and migration to the cloud are top priorities for a lot of enterprises. At Google Cloud, we’re working hard to make this journey easier. For example, we recently launched Migrate for Compute Engine and Migrate for Anthos to simplify cloud migration and modernization. These services have helped customers like Cardinal Health perform successful, large-scale migrations to GCP. But we understand that the migration journey can be daunting. To make things easier, we developed a whitepaper on application migration featuring investigative processes and advice to help you design an effective migration and modernization strategy. This guide outlines the four basic steps you need to follow to migrate successfully and efficiently:  Build an inventory of your applications and infrastructure: Understanding how many items, such as applications and hardware appliances, exist in your current environment is an important first step.Categorize your applications: Analyze the characteristics of all of your applications and evaluate them across two dimensions: migration to cloud, and modernization.Decide whether or not to migrate an application to the cloud: Not all applications should move to the cloud quite yet. The whitepaper lists the questions to ask to determine whether or not to migrate a given application.Pick your migration strategy: For the applications you decided to migrate, decide on your ideal strategy—pure lift and shift, containers, cloud managed services, or a combination thereof.There’s a lot to consider when you start thinking about digital transformation, and every cloud modernization project has its nuances and unique considerations. The secret to success is understanding the advantages and disadvantages of the options at your disposal, and weighing them against what you want to transform and why. To learn how to migrate and modernize your applications with Google Cloud, download this whitepaper.
Quelle: Google Cloud Platform

An update on Chronicle: Continuing to give good the advantage

In June, we announced Chronicle was coming to Google Cloud. Since then, we’ve been hard at work and wanted to give you an update on our progress as well as a sneak peak of what’s to come. Chronicle’s mission has always been to give good the advantage. We’ve done this with our products VirusTotal and Backstory. The same mission underpins how we build and deliver Google Cloud security solutions that work on our platform and across multi-cloud deployments. As a result, we’ve consolidated our security solutions into a single group, enabling teams working on cloud-native controls, security integrations with partners and security analytics (i.e. Backstory) to collaboratively deliver next generation enterprise security services. In one week we’ll take the stage at Next UK, where we are sharing how we are connecting Chronicle and Google Cloud to create a comprehensive security business that will benefit all of our customers. During the opening keynote at Next UK, we’ll be announcing multiple new native capabilities, and also demonstrating upcoming features in Chronicle’s Backstory product, Google Cloud’s flagship offering for hybrid security analytics. Tune into to watch live, or feel free to catch a replay after the event. NCR is an example of a customer already seeing benefits with Chronicle. “We recently became a Backstory customer, and so far, we have been impressed with the innovation we are seeing from Chronicle,” says Bob Varnadoe, CISO of NCR. “With Backstory, we can do in minutes what used to take days with our previous SIEM.”In addition to customer momentum, partners who have been previewing our new capabilities are excited about the investments in the product they are seeing since Chronicle joined Google Cloud:”As an early strategic partner of Chronicle, we work very closely with the Backstory team and I can tell you first hand it has been full steam ahead. We’re excited by the technology and the new capabilities we are building together with Chronicle and Google,”  says Gary Fish, CEO of Fishtech Group.Security is one of the key solutions we are focused on delivering at Google Cloud, and with Chronicle, we’ll reimagine enterprise security services to keep customers safe on GCP, on premises, or on other clouds.See you in London!
Quelle: Google Cloud Platform

FedRAMP Moderate Blueprints helps automate US federal agency compliance

We’ve just released our newest Azure Blueprints for the important US Federal Risk and Authorization Management Program (FedRAMP) certification at the moderate level. FedRAMP is a key certification because cloud providers seeking to sell services to US federal government agencies must first demonstrate FedRAMP compliance. Azure and Azure Government are both approved for FedRAMP at the high impact level, and we’re planning that a future Azure Blueprints will provide control mappings for high impact.

Azure Blueprints is a free service that helps enable customers to define a repeatable set of Azure resources that implement and adhere to standards, patterns, and requirements. Azure Blueprints allow customers to set up compliant environments matched to common internal scenarios and external standards like ISO 27001, Payment Card Industry data security standard (PCI DSS), and Center for Internet Security (CIS) Benchmarks.

Compliance with standards such as FedRAMP is increasingly important for all types of organizations, making control mappings to compliance standards a natural application for Azure Blueprints. Azure customers, particularly those in regulated industries, have expressed a strong interest in compliance blueprints to help ease the burden of their compliance obligations.

FedRAMP was established to provide a standardized approach for assessing, monitoring, and authorizing cloud computing services under the Federal Information Security Management Act (FISMA), and to help accelerate the adoption of secure cloud solutions by federal agencies.

The Office of Management and Budget now requires all executive federal agencies to use FedRAMP to validate the security of cloud services. The National Institute of Standards and Technology (NIST) 800-53 sets the standard, and FedRAMP is the program that certifies that a Cloud Solution Provider (CSP) meets that standard. Azure is also compliant with NIST 800-53, and we already offer an Azure Blueprints for NIST SP 800-53 Rev4.

The new blueprint provides partial control mappings to important portions of FedRAMP Security Controls Baseline at the moderate level, including:

Access control (AC)

 AC-2 account management (AC-2). Assigns Azure Policy definitions that audit external accounts with read, write, and owner permissions on a subscription and deprecated accounts, implement role-based access control (RBAC) to help you manage who has access to resources in Azure, and monitor virtual machines that can support just-in-time access but haven't yet been configured.
 Information flow enforcement (AC-4).Assigns an Azure Policy definition to help you monitor Cross-Origin Resource Sharing (CORS) resources access restrictions.
 Separation of duties (AC-5). Assigns Azure Policy definitions that help you control membership of the administrators group on Windows virtual machines.
 Remote access (AC-17). Assigns an Azure Policy definition that helps you with monitoring and control of remote access.

Audit and accountability (AU)

 Response to audit processing failures (AU-5). Assigns Azure Policy definitions that monitor audit and event logging configurations.
 Audit generation (AU-12). Assigns Azure Policy definitions that audit log settings on Azure resources.

Configuration management (CM)

 Least functionality (CM-7). Assigns an Azure Policy definition that helps you monitor virtual machines where an application whitelist is recommended but has not yet been configured.
 User-installed software (CM-11). Assigns an Azure Policy definition that helps you monitor virtual machines where an application whitelist is recommended but has not yet been configured.

Contingency planning (CP)

 Alternate processing site (CP-7). Assigns an Azure Policy definition that audits virtual machines without disaster recovery configured.

Identification and authentication (IA)

 Network access to privileged accounts (IA-2). Assigns Azure Policy definitions to audit accounts with the owner and write permissions that don't have multi-factor authentication enabled.
 Authenticator management (IA-5). Assigns policy definitions that audit the configuration of the password encryption type for Windows virtual machines.

Risk assessment (RA)

 RA-5 Vulnerability scanning (RA-5). Assigns policy definitions that audit and enforce Advanced Data Security on SQL servers as well as help with the management of other information system vulnerabilities.

Systems and communications protection (SC)

 Denial of service protection (SC-5). Assigns an Azure Policy definition that audits if the distributed denial-of-service (DDoS) standard tier is enabled.
 Boundary protection (SC-7). Assigns Azure Policy definitions that monitor for network security group hardening recommendations as well as monitor virtual machines that can support just-in-time access but haven't yet been configured.
 Transmission confidentiality and integrity (SC-8). Assigns Azure Policy definitions that help you monitor cryptographic mechanisms implemented for communications protocols.
 Protection of information at rest (SC-28). Assigns Azure Policy definitions that enforce specific cryptograph controls and audit the use of weak cryptographic settings.

System and information integrity (SI)

 Flaw remediation (SI-2). Assigns Azure Policy definitions that monitor missing system updates, operating system vulnerabilities, SQL vulnerabilities, and virtual machine vulnerabilities.
 Malicious code protection (SI-3). Assigns Azure Policy definitions that monitor for missing endpoint protection on virtual machines and enforces the Microsoft antimalware solution on Windows virtual machines.
 Information system monitoring (SI-4). Assigns policies that audit and enforce deployment of the Log Analytics agent, and enhanced security settings for SQL databases, storage accounts, and network resources.

Azure tenants seeking to comply with FedRAMP should note that although the FedRAMP Blueprints controls may help customers assess compliance with particular controls, they do not ensure full compliance with all requirements of a control. In addition, controls are associated with one or more Azure Policy definitions, and the compliance standard includes controls that aren't addressed by any Azure Policy definitions in blueprints at this time. Therefore, compliance in Azure Policy will only consist of a partial view of your overall compliance status.

Customers are ultimately responsible for meeting the compliance requirements applicable to their environments and must determine for themselves whether particular information helps meet their compliance needs.

Learn more about the Azure FedRAMP moderate Blueprints in our documentation.
Quelle: Azure