Securely Manage Apps from Multiple Business Unit on AWS

Executive Summary

One of Syariah Bank in Indonesia engage with Mastersystem Infotama, a major IT consultancy and an Amazon Web Services (AWS) Partner, to help them design and implement infrastructure in AWS to manage their Identity and Access Management in AWS Cloud before running and migrating apps to AWS.

Customer Challange

One of the customer challenge is managing multiple applications from different business unit/owner. Security vulnerabilities also pose a serious risk of data breaches and compliance failures, while the lack of a high-availability strategy increases the likelihood of downtime, potentially eroding customer trust and damaging market reputation.
By adopting AWS, specifically through an AWS Landing Zone, the customer can establish a secure, scalable, and well-managed cloud foundation. AWS Landing Zone provides a standardized multi-account setup with built-in security guardrails, automated governance, and compliance best practices. Services like AWS Auto Scaling ensure seamless scalability, while AWS Identity and Access Management (IAM), AWS Security Hub, and AWS Control Tower enforce security and regulatory policies. Additionally, AWS’s global infrastructure and multi-AZ architecture enhance high availability and disaster recovery. With AWS, the customer can mitigate operational risks, improve agility, and maintain market trust, ensuring long-term success.

Solution

To address the customer’s challenges, Mastersystem Infotama implements an AWS Landing Zone with a multi-account architecture to enhance security, governance, and operational efficiency. This setup enforces security best practices using AWS Identity and Access Management (IAM), AWS Security Hub, and automated compliance policies, ensuring a robust security posture.
The AWS Landing Zone is created using AWS Control Tower while AWS Organization serves as the account’s orchestrator, allowing the customer to centrally manage multiple accounts and applications in AWS. Access rights are granted and managed through AWS IAM Identity Center to ensure only authorized users can access designated resources. To maintain audit trail and visibility, AWS CloudTrail logs and VPC Flow Logs are collected and stored centrally in Amazon S3.

Regarding network and application security, Mastersystem Infotama deploys and manages a third-party Next-Generation Firewall (NGFW) within a dedicated Inspection Account, routing all inbound and outbound traffic through deep packet inspection before reaching workload accounts. Amazon GuardDuty continuously monitors all accounts for malicious and unauthorized activities, with findings correlated against CloudTrail logs and aggregated in AWS Security Hub for centralized prioritization. When security events are detected, the operations team follows documented runbooks to triage, contain, and remediate incidents according to severity, with every action tracked in Jira Service Management and closed only after resolution is confirmed. Compliance findings such as publicly exposed S3 buckets are automatically surfaced by AWS Config and remediated following the same structured process.

To ensure data resilience and business continuity, AWS Backup is configured within a dedicated Backup Account as part of the Landing Zone architecture. Backup policies are centrally managed across all workload accounts with retention periods aligned to customer requirements and regulatory obligations, ensuring critical workloads can be recovered in a controlled and auditable manner.

Communication between environments is established through AWS Transit Gateway, while Amazon Direct Connect and Site-to-Site VPN provide connectivity to the onpremises data center. One of the workload environments consists of Amazon ECS Cluster for containerized workloads with auto-scaling, Amazon Managed Streaming for Apache Kafka (MSK) for historical data streaming, Amazon Bedrock for GenAI capabilities, RDS PostgreSQL as the primary database, AWS KMS for encryption key management, AWS Certificate Manager for SSL certificates, and Amazon SageMaker as a web-based IDE for data processing tasks.

Outcome

With this solution, the customer gains a centralized and scalable environment to efficiently manage multiple applications from various business owners. The AWS Landing Zone with a multi-account architecture enables organized governance and streamlined management while maintaining robust security and compliance across diverse workloads. This structure ensures that each business owner can operate independently within their own account while adhering to consistent security policies, supported by an operations model that covers detection, response, and recovery across the entire environment.

Discover more from AWS Mastersystem Infotama

Subscribe now to keep reading and get access to the full archive.

Continue reading