As more organizations move their applications into the cloud, the key challenge is “being able to have the skilled people within their companies that honestly know how to respond to these different incidents that the [security] tools are telling them to,” according to Ryan Orsi, worldwide security/managed security services provider (MSSP) practice lead at Amazon Web Services (AWS).

That’s why AWS introduced the Level 1 MSSP Competency program, which provides experts “that really understand how to enrich a security finding with other sources of information and indicators of compromise to be able to determine if it's a false negative, a false positive, or an actual true security incident that requires additional triage,” Orsi added.

According to ​​AWS, the new competency program makes it easier for customers to find validated MSSP partners qualified to deliver Level 1 managed security services, which is a new baseline standard of quality that users can refer to when choosing an AWS partner. And those MSSP partners are required to repeat the AWS validation process annually. 

Orsi noted the AWS security experts found “there's no lack of security tools out there that do … either prevention, detection, or response.” However, AWS users still need guidance to help figure out which tools to use that allows them to have a holistic solution to manage security services, added Mona Chadha, director of AWS marketplace category management. 

“Operationalizing security is not easy,” echoed Doug Yeum, head of worldwide channels and alliances at AWS. It requires companies to assess and deploy AWS native security services and the third-party solutions and have the right response system for alerts from those solutions that monitor the security of their applications. 

Additionally, public-cloud users need to better understand the shared-responsibility model when it comes to securing their data in the cloud. “As the platform provider, we are responsible for the infrastructure and the needed services that we offer, but the customers are responsible for the applications that they build on top of the service platform,”  Yeum explained. “And that's where the shared responsibility model comes in.” 

This requires a mix of cloud-native security services and tools as well as the third-party products that secure and monitor applications. 

However, “not every customer has that expertise,” Yeum said, adding that the combination of AWS’s security competency and the MSSP partners can help customers with the security posture.

Level 1 MSSP Competency Partners

To get MSSP partners’ feedback, AWS ran a pilot competency program for about 12 months. “One thing that we were very intentional and deliberate about was the fact that we want to have wide-ranging partners as part of the pilot and the launch partners,” Yeum said.

The vendor identified 27 launch partners from the largest global technology solution providers including Accenture, Deloitte, and IBM, as well as companies like Sophos that specialize in the small to midsized businesses space, according to Yeum.

AWS offers a benefit package for Level 1 MSSP Competency partners, including additional market development funding, access to the annual AWS re:Inforce security conference, technical training workshops, and AWS security partner success virtual conferences, as well as eligibility for promotion to internal AWS sales teams.