The vendor presents AWS Control Tower as the easiest way to set up and govern a new, secure multi-account AWS environment. With AWS Control Tower, builders can provision new AWS accounts in a few clicks, while knowing new accounts conform to company-wide policies.
N/A
Trend Micro Deep Security
Score 8.0 out of 10
N/A
Trend Micro™ Deep Security™ software provides comprehensive security for virtual, cloud, and container environments. Deep Security allows for consistent security regardless of the workload. It also provides a rich set of application programming interfaces (APIs) so security can be automated.
We did not look at other vendors because we generally want to try to use AWS native products as much as possible for greater support directly from AWS and to reduce 3rd party priority shifts.
Using AWS Systems Manager and other slightly lower level components has been helpful for us to manage parts of our AWS presence at a more granular level than AWS Control Tower was designed for. It's not at all an apples-to-apples comparison as they solve different use cases, …
We chose this because it could be tied to Apex Central for policy management and tracking of viruses and malware. We could also tie it to the deep discovery analyzer to look and help identify things that may be threats. Plus we could tie this to our smart protection servers so …
I have begun looking at other solutions that are in the same space as Trend Micro Deep Security. However, I am not comfortable yet in this because I don't have the confidence in their application. CrowdStrike in all fairness has an excellent reputation, but I do not believe it …
We selected trend micro to take the AV scans and filtering out of the hands of the Windows and Linux vm's we have deployed and move it to the hypervisor level. This has led us to be able to deploy only a single DSVA per host and can protect all VM"s that are on that hosts. This …
AWS Control Tower is great if you have multiple organizations or disciplines inside a company that needs to be separated for billing purposes or separation of concern. Multiple accounts is part of AWS's well-architected framework and are generally a good idea. AWS Control Tower makes central logging easy which enables those logs to be quickly picked up by a logging tool to provide even more reports and insight. For smaller organizations, AWS Control Tower may seem like an over-engineered solution
So far we, unfortunately, have been using it in a limited scenario but we find that it has been very easy to use and manage in that scenario. Integrating the protection of our few saas applications was actually very simple and being able to use a very light weight agent like deep security agent has been very useful. Other agents ate up a lot of CPU or ram or both but this one is very light.
AWS Control Tower integrates with AWS organizations
AWS Control Tower provides Account Factory to provision preconfigured AWS accounts
AWS Control Tower helps to isolate workloads and billing via AWS accounts separation
AWS Control Tower supports data residency controls out of the box
AWS Control Tower supports post provisioning actions to newly provisioned AWS accounts: for example it can trigger enabling VPC flow logs in the new account
There is no way to easily close an AWS account whether it was created manually or via the AWS Control Tower. It takes too many steps to close it vs to provision a new AWS account
Trend Micro's support is pretty decent, we have had issues in the past and they have been fairly responsive to us and our complaints. Depending on how severe the issue was. Any ticket that had a high priority was handled very shortly especially when we contacted our account rep even if it was after hours, we were still able to get support within a short time period.
Using AWS Systems Manager and other slightly lower level components has been helpful for us to manage parts of our AWS presence at a more granular level than AWS Control Tower was designed for. It's not at all an apples-to-apples comparison as they solve different use cases, but for us, the use case associated with AWS Systems Manager was a better fit for our specific needs and skillsets. We did not need everything that AWS Control Tower was doing for us.
We selected trend micro to take the AV scans and filtering out of the hands of the Windows and Linux vm's we have deployed and move it to the hypervisor level. This has led us to be able to deploy only a single DSVA per host and can protect all VM"s that are on that hosts. This has allowed for more time being spent on other priority security tasks.
100% positive ROI. Without Deep Security we would have to leverage and endpoint protection management solution like Sophos or SEPM (Symantec). Although both are good products, from a cost perspective it would have hit us much harder. Trend Micro Deep Security scales very nicely.
Since Deep Security actually has zero (or at least unnoticeable) resource footprint on monitored VMs, it is a huge cost benefit for us. As previously mentioned, actual antivirus clients installed on each virtual machine (VM) would have significantly affected performance. This would have cost us much more additionally in paying for additional resources to allocate over VMs in the VMware environment. Deep Security is almost completely unintrusive from a resource perspective.
Also, from a layered security perspective, it helps us meet our goals; and since the price of Trend Micro Deep Security quite reasonable, it is that much easier to get approval for this specific internal layer of security.