AWS environment security
Aceville Publications is one of the UK’s leading and fastest-growing independent magazines publishers, providing over 30 consumer and B2B high-quality specialist magazines and websites.
A digitally advanced organisation, they have a mature hybrid cloud approach and have incorporated public cloud solutions from AWS into their environment since 2010.
As Head of Digital at Aceville, David Coe is focused on growing revenues and audiences and ensuring Aceville delivers increasing ROI for clients. Continuously improving how Aceville uses, protects and controls technology is a key foundation of how they can continue to deliver great value to their digital users.
As both the threat landscape and the opportunities to protect AWS environments continually evolves, David wanted an independent review to provide assurance that Aceville’s services were underpinned by an up-to-date controls and compliance framework.
In June 2020, Brightsolid worked with Aceville to expertly deliver a controls & compliance consulting engagement, which included controlled assessments, reports and recommendations.
The engagement was conducted remotely during Covid-19 lockdown over a 3-day period. It assessed Aceville’s AWS environment against the Brightsolid cloud control framework (evaluating 17 key controls aligned to industry standards such as ISO 2700) as well as running an automated assessment of the environment against CIS AWS benchmark criteria (49 objective and consensus-based guidelines).
A detailed findings report was created, providing an in-depth analysis and easily actionable recommendations. Daniel Gowing, Web Developer at Aceville said of the Brightsolid report; “A very clear and detailed security analysis with excellent deliverable, detailing steps we need to take to secure our solution”.
Brightsolid also provided a management summary for Aceville’s leadership team. David Coe said, “We are delighted with the management summary which ensured a shared understanding and clarity about our next steps for the executive team.” The whole exercise according to David was “a great success, providing a thorough analysis to ensure we have the right, up-to-date controls protecting our AWS environments”.
- Confidence in the Aceville AWS environment, providing piece of mind
- Clear understanding of AWS environments’ compliance to best industry good practice
- Demonstrable understanding of risks and evidencing of strong controls
- Clear, actionable recommendations, creating consensus across the executive team and beyond on next steps