Skip to content

Ensuring BIO Compliance through an AWS Landing Zone


 

Introduction

To align with digital sovereignty requirements, and in particular Baseline Informatiebeveiliging Overheid (BIO), the Municipality wanted to implement an AWS landing zone with Frankfurt (eu-central-1) designated as the primary AWS region and Ireland (eu-west-1) as the secondary AWS region. The primary region was to host all necessary components to support active workloads, while the secondary region would serve as a backup replication destination to ensure a higher level of business continuity in the event of a disaster.  

The landing zone was configured to enforce the above-mentioned regions by adding SCPs into the AWS Organization whilst at the same time supporting all the availability zones present in that region. This strategic choice ensures that data remains within these specified regions and countries, adhering to stringent data protection, sovereignty and business continuity standards. 

Design

Regions 
The selection of Frankfurt and Ireland is driven by their status as the most developed AWS regions in Europe, offering a richer feature set and lower pricing. Ireland is designated as the secondary region due to its competitive pricing and early access to new AWS features. By only implementing the minimal required components (backup vaults) in the secondary region, the baseline costs for operating this region can be significantly reduced compared to an active region. Additionally, planning for IP address space is significantly simplified when allocating CIDR blocks for VPCs that operate in an even number of availability zones. Working with increments of four allows for the full utilization of available IP space.  

AWS Security Hub 
AWS Security Hub provides a broad overview of all accounts with an organisation and provides a set of best-practice security rules out of the box. The following security rule sets will be enabled: CIS AWS Foundations Benchmark v1.2.0 and AWS Foundational Security Best Practices v1.0.0. AWS Security Hub has been enabled on all AWS accounts, with the Audit account given delegated administrative privileges to access security alerts for all accounts. This provides a central location for the aggregation of alerts, scans and compliance checks. Numerous other services such as AWS Config and GuardDuty integrate with Security Hub to provide a single location for all security needs.

org-trail-monitoring.drawio

Additionally, AWS Config has been enabled for all accounts and regions in which the Municipality operates. AWS Config findings are now being aggregated in the Audit account. The Log Archive account will maintain historical logs for all AWS Config events. AWS Config is required for deployment of Security Hub. Additionally, the enabling of AWS Config allows operators to understand the timeline of changes during the lifetime of a resource. This can aid investigations related to security or application configuration. Should the Municipality have the requirement for additional compliance rules, either customized or based on existing compliance frameworks, AWS Config can be leveraged to provide such functionality. 

Amazon GuardDuty 
Finally, Amazon GuardDuty has been enabled in all accounts and regions in which the Municipality operates. Amazon GuardDuty findings are centralized in the Audit account to allow security operators to view and manage events from a single point. Amazon GuardDuty provides timely information about suspicious activity within an AWS account. Security, platform or application operators will be able to view these events and perform further analyses on the resources involved to determine how to handle the events.

account-setup.drawio

 

Result 

By choosing Frankfurt and Ireland as the primary and secondary AWS regions respectively, the Municipality effectively balances the need for advanced infrastructure and compliance with digital sovereignty mandates. This strategy provides a robust framework for secure and sovereign data management within the European AWS landscape. The approach ensures business continuity through backup replication while optimizing operational costs by limiting the secondary region to essential components only. Additionally, the planned use of up to four Availability Zones enhances future scalability and failure resilience, with reserved IP address space facilitating seamless expansion. 

Customer story

VodafoneZiggo Upskills Data-Savvy Employees to Become Data Engineers

Xebia partners with the telecommunication company to upskill its professionals and fill critical data engineering positions.

Customer story

Wehkamp's Journey to Cost Optimization with AWS and Xebia

Wehkamp, one of the largest online retailers in the Netherlands, aimed to achieve greater speed, elasticity, and scalability by transitioning to the cloud with AWS and Xebia.

Customer story

Xebia's Collaboration with RTS for Data-Driven Excellence

Xebia and RTS join forces to enhance media impact through an ethical data strategy, unlocking potential and fostering collaboration.

Customer story

Streaming Platform Adds Required Age Verification for International Launch

Xebia helped this Streaming Services client create, execute, and monitor legally binding age verification services in order to launch in specific countries.

Customer story

Dutch Banks Assemble to Fight Financial Crime

TMNL helps Dutch banks monitor suspicious transactions

Customer story

Managing the evolution of CustomerGauge’s AWS Environment at scale

Customer story

Interflon: Adopting the Cloud in Just 6 Months

To increase data security and embrace new business opportunities, a leading lubrication solutions manufacturer decided to move to the Cloud.

Customer story

Energy Consumption Insight Provider processes and generates data faster with scalable cloud architecture

An energy consumption application with over 100,000 users, faced data processing challenges due to the volume of energy meter data, prompting Xebia's assistance in developing a scalable solution using AWS services.

Customer story

Driving Sustainability: Blonk Partners with Xebia for Cloud Carbon Reduction

Xebia employed a dashboard and implemented daily updates to provide Blonk with almost real-time visibility into their AWS carbon emissions, elevating their understanding and management of these emissions.

Customer story

Helping Blonk scale through Cloud Native Development on AWS

Xebia configured the AWS landing zone according to the best practices of the AWS Cloud Foundation. With this modernized infrastructure as a base, Xebia further guided the development team at Blonk by adopting cloud native tools on the AWS platform and formulated a clear innovation path.

Customer story

Abacai: Revolutionizing Insurance with an Omnichannel Experience

A digital-first UK car insurer teamed up with Xebia to challenge a traditional industry with cutting-edge artificial intelligence.

Customer story

Innovative Scale-Up Leverages Data to Insure Small Entrepreneurs

Insify harnesses data resources to offer digital insurance solutions more quickly and competitively through a tailor-made cloud platform

Customer story

C-Facts Realizes Innovative Control Center for Sustainable Cloud Services

Cloud-native provider of insights into digital cloud footprints undergoes a Well-Architected Review of its AWS platform to ensure scalability; implements solutions that result in less downtime and improved time-to-market — and more satisfied customers overall

Customer story

Yell Secures Future With Online Reputation Management

The UK’s leading online directory developed an all-in-one social monitoring tool, enhancing its position as an essential business service

Customer story

Cloud Platform Move Enhances Insurance App’s USP

A migration to AWS Cloud enhanced an SaaS app developer's unique services by improving product response times and features

Customer story

Leading FinTech Brand Retains Market Lead With Cloud Solution

The world-leading FinTech company migrated to AWS Cloud, modernizing its platform to ensure it maintains its strong market position

Customer story

AIXBRO Speeds up Searches With AWS Serverless

The leading Swiss automotive parts distributor used a Proof of Concept to discover how the cloud could secure its future growth

Customer story

Kynetec Improves Automation, Cuts Processing Times by a Quarter

The leading agricultural research organization moved to serverless architecture, allowing data analysts more time to improve the company product

Customer story

Serverless Improves Automotive SaaS Solution at Fraction of Cost

In automating its serverless platform using the AWS Cloud to meet the automotive industry’s needs, metrologx gained widely applicable cost and performance benefits

Customer story

Serverless Architecture Increases Coople Innovation

Europe's largest digital staffing platform moved to Amazon Web Services cloud hosting, enhancing its market-leading web app development

Customer story

Data Security Key to Coople Cloud Integration

Europe’s largest online staffing agency conducted a full audit of its AWS cloud architecture to ensure users’ personal data remains fully secure

Customer story

Hospitality Industry Goes Cloud-First With Foodback

Norwegian startup helps businesses manage feedback in real-time cloud-based hospitality app hosted on AWS

Customer story

AWS Cloud & Machine Learning Help RASP Focus On Quality Content

Innovative Polish publishing house optimizes its publications for commercial partners with image recognition tool that streamlines editorial process

Customer story

Advanced Leverage DevOps Engineers, Accelerate Cloud Migration

Advanced, a leading management software supplier, migrated an acquisition to an in-house AWS infrastructure for greater efficiency, simultaneously upskilling its team

Customer story

Lift & Shift Migration Makes IT More Cost-Effective for Software Provider

Advanced — a dynamic business software and services provider — migrated its Marketplace software to a bespoke cloud solution, resulting in a cheaper and more efficient IT infrastructure

Customer story

Sage Cloud Software Gets Boost With Carbon React

Accounting specialists create a component library that improves client collaboration — and satisfaction

Customer story

Leading Fintech App Optimizes AWS to Give Premium Service

Bizcuit overcomes cloud overwhelm to better serve  customers while keeping the highest compliance standards.

Customer story

EnergyAlert Optimizes Efficiency Using IoT Technology

Dutch Energy monitoring company expands its capabilities with state-of-the-art IoT services and techniques

Customer story

Sparco Saves Time and Cost with New Cloud Platform Initiative

Dutch marketing maverick works its magic with a new cloud platform and enhanced infrastructure

Customer story

Global Leader in Agri-Research Quadruples its Processing Speed Thanks to Improved Automation

Serverless architecture and cloud-based solutions increase Kynetec’s data processing efficiency by 77%

Customer story

Dutch Railway Company Journeys to the Cloud with End-to-End AWS Deployment

NSI migrates to a cloud environment improving design and development along the way

Customer story

B2B Tool Provider, Advanced, Migrates Infrastructure to the Cloud

British business software provider streamlines IT by migrating infrastructure to the Cloud; gives its customers a competitive edge

Customer story

dsm-firmenich Launches “Green” Calculator for Farming Industry

Global science-based company use Amazon Web Services (AWS) to create a highly scalable tool to radically reduce environmental impact of animal farming

Customer story

Luxury IT Company Creates Cloud-Centered Infrastructure to Serve High-end Automotive Retailers

PON IT delivers scalable, security-minded, Agile products and IT services through successful cloud migration

Customer story

Cloud migration and application migration: a structured process towards a solid and reliable application environment.

Dutch health provider ZuidZorg successfully migrates old systems to the cloud in under three months

Customer story

Rail Ticket Agent Gets A Pass with Cutting-Edge Upgrade to Its App

Eurail increases delivery times with upgraded services and app built on AWS cloud architecture

Customer story

Wehkamp new Architecture Automates DevOps Operations

Automating Continuous Integration and Delivery on AWS for Top E-Commerce Biz in the Netherlands

Customer story

Dutch Financial Pension Provider Unlocks Hybrid Cloud Landscape for Future Security

Embracing Agile, MN Pensioen migrates to a hybrid cloud environment while upgrading security features and gaining efficiency

Customer story

Dutch Energy Provider Lights Up Competition with Daring New IoT Platform

Kenter utilizes creative IoT platform as an innovative, affordable measure of energy use, giving customers more savings options

Customer story

The Largest Digital Marketplace For Floriculture.

World’s largest flower auction company increases purchasing and sales capacities for its member growers and international buyers in the global floral trade

Customer story

Professionalizing BI Processes to Improve the Customer Experience

Learn how entertainment business Pathé professionalized its BI processes, and became better at improving customer experience and predicting customer numbers