62. Chained Defense-in-Depthパターン
VPN
Web Web
App App
NAT
Web Web
App App
NAT VPN
WebTierAppTierDBTierPublicFacing
VPN NFW IPS/I
DS
WAF AV
VPN NFW IPS/I
DS
WAF AV
VPN NFW IPS/I
DS
WAF AV
63. ELB End-to-End Encryptionパターン
ELBでSSL termination
SSL処理をELBで実施
証明書の管理が楽
Web Web Web Web
WebTier
Backend-SSLで裏側も暗号化
全通信経路の暗号化
SSL
termination
Backend SSL
69. 参考: Storage/Data Security
EC2
EBS
S3
Glacier
Encryption
Client
Key Management
File
Encryption
Full Disk
Encryption
Database
Encryption
AWS Server
Side
Encryption
Key
Management
File
Encryption
Full Disk
Encryption
Database
Encryption
AWS Server
Side
Encryption
File
Encryption
Full Disk
Encryption
Database
Encryption
AWS Server
Side
Encryption
S3
Glacier
On
premise
Encryption
Client
EC2
On
premise