{"id":10906,"date":"2022-03-28T07:23:51","date_gmt":"2022-03-28T07:23:51","guid":{"rendered":"https:\/\/blog.cloudthat.com\/?p=10906"},"modified":"2024-06-25T11:03:27","modified_gmt":"2024-06-25T11:03:27","slug":"aws-well-architected-review-a-war-case-study","status":"publish","type":"blog","link":"https:\/\/www.cloudthat.com\/resources\/blog\/aws-well-architected-review-a-war-case-study","title":{"rendered":"AWS Well-Architected Review: A WAR Case Study"},"content":{"rendered":"<table style=\"height: 245px;\" border=\"3\" width=\"300\">\n<tbody>\n<tr>\n<td>\n<h2><strong><span style=\"color: #000080;\">TABLE OF CONTENT<\/span><\/strong><\/h2>\n<\/td>\n<\/tr>\n<tr>\n<td><a href=\"#introduction\">1. Introduction<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#customerbackground\">2. Customer Background<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#customerchallenge\">3. Customer Challenge<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#proposedsolution\">4. Proposed Solution<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#awsservices\">5. AWS Services Used<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#conclusion\">6. Conclusion<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#aboutcloudthat\">8. About CloudThat<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#faqs\">9. FAQs <\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"introduction\">1. Introduction<\/h2>\n<p>Well-Architected Review (WAR) is done by Authorized AWS partners by using AWS&#8217;s well-architected tool to make sure that the infrastructure and system built on AWS is well-architected. If there are any issues, then we, the consulting partner, recommend the best practices to implement and fix the issues based on the five pillars security, operational excellence, performance efficiency, reliability, and cost optimization.<\/p>\n<p>It is the best approach to consistently measure your architecture against best practices and identify the areas of improvement.<\/p>\n<p>Let us look at an example of WAR executed for one of our clients in detail.<\/p>\n<h3 id=\"customerbackground\">2. Customer Background<\/h3>\n<p>The client is a comprehensive Cloud-based Compliance Management System that tracks and monitors statutory, regulatory, central &amp; state, secretarial, and legal compliances within a company. It helps businesses manage all their compliance documentation activities, conduct audits, track and resolve compliance issues on the cloud. They provide security solutions to businesses and make operational processes more efficient.<\/p>\n<h3 id=\"customerchallenge\">3. Customer Challenge<\/h3>\n<p>The client is not having well-architected competency, there are multiple loopholes in their architecture in terms of Security, High Availability, Scalability, Reliability, Operational Excellence, and performance issues. To adopt AWS best practices, the client approached CloudThat to perform a Well-architected review for their IT environment.<\/p>\n<h3 id=\"proposedsolution\">4. Proposed Solution<\/h3>\n<p>CloudThat\u2019s Well-Architected expert team performed the <a href=\"https:\/\/www.cloudthat.com\/consulting\/expertise\/well-architected-infrastructure\/\">AWS Well-Architected<\/a> review in the account of the customer on below mentioned four pillars and recorded the inputs in the tool based on that \u201cHigh-Risk Indicators\u201d and \u201cMedium Risk Indicators\u201d are generated and we provided our findings and remediation\u2019s to fix those issues:<\/p>\n<ol>\n<li><strong>Security<\/strong>: We found that client infrastructure was not even following the baseline security after our analysis, security groups are not configured as per the best practices, Multi-factor Authentication is not enabled for IAM users, passwords and keys are not rotated periodically, similarly there were many security best practices are missing and we provide the remediation\u2019s to fix all these issues, which helps customer a lot to become a well-architected and compliance infrastructure and application, now their current state after this activity and applying remediation\u2019s is secured and <a href=\"https:\/\/blog.cloudthat.com\/best-practices-for-aws-monitoring-solutions\/\">well-architected<\/a>.<\/li>\n<li><strong>Reliability<\/strong>: We found that client infrastructure was not reliable and not highly available that can cause the application and data availability issues, so to fix that we have recommended some solutions like a load balancer, scheduling backups, and the complete disaster recovery set up by applying the best suitable DR Strategies so that we can make the infrastructure reliable and reduce the impact on business<\/li>\n<li><strong>Operational Excellence<\/strong>: We found that client was performing the patching activity manually, which is time-consuming and also not secured. We have recommended the automated solution of patching and similar to take backups to ease the administration and some other solutions for the automation and maintaining the documents to achieve the operational. Excellence, it is very important to keep our operations easy and time-saving.<\/li>\n<li><strong>Performance Efficiency<\/strong>: We found that the monitoring solution is not enabled to take the utilization for metrics like memory etc. We have recommended creating the metrics and setting up the alarms based on thresholds and setup the actionable solution on incidents, which improved the performance of overall infrastructure and application.<\/li>\n<\/ol>\n<p>We have checked if the instances are optimized or not to redefine the sizes and hardware of instances.<\/p>\n<h3 id=\"awsservices\">5. AWS Services Used<\/h3>\n<ul>\n<li><a href=\"https:\/\/blog.cloudthat.com\/8-best-practices-of-identity-and-access-management-iam\/?utm_source=blog-website&amp;utm-medium=text-link&amp;utm_campaign=8-best-practices-of-identity-and-access-management-iam\/\" target=\"_blank\" rel=\"noopener\">IAM MFA<\/a><\/li>\n<li>Secret Manager<\/li>\n<li><a href=\"https:\/\/blog.cloudthat.com\/how-to-enable-iam-access-analyzer\/?utm_source=blog-website&amp;utm-medium=text-link&amp;utm_campaign=how-to-enable-iam-access-analyzer\/\" target=\"_blank\" rel=\"noopener\">IAM Access Analyzer<\/a><\/li>\n<li>Security Hub<\/li>\n<li>Guard duty<\/li>\n<li>Web Application Firewall<\/li>\n<li>AWS Macie<\/li>\n<li><a href=\"https:\/\/blog.cloudthat.com\/cloud-trends-2022-aws-kms-multi-region-key\/?utm_source=blog-website&amp;utm-medium=text-link&amp;utm_campaign=cloud-trends-2022-aws-kms-multi-region-key\/\" target=\"_blank\" rel=\"noopener\">KMS (Key Management Service)<\/a><\/li>\n<li>Gamedays simulator<\/li>\n<li>Patch Manager<\/li>\n<li><a href=\"https:\/\/blog.cloudthat.com\/track-your-resource-configuration-and-changes-with-aws-config\/?utm_source=blog-website&amp;utm-medium=text-link&amp;utm_campaign=track-your-resource-configuration-and-changes-with-aws-config\/\" target=\"_blank\" rel=\"noopener\">AWS Config<\/a><\/li>\n<li>AWS ELB<\/li>\n<li><a href=\"https:\/\/blog.cloudthat.com\/how-cloudwatch-synthetics-helps-in-application-monitoring\/?utm_source=blog-website&amp;utm-medium=text-link&amp;utm_campaign=how-cloudwatch-synthetics-helps-in-application-monitoring\/\" target=\"_blank\" rel=\"noopener\">AWS CloudWatch<\/a><\/li>\n<li>AWS Backup<\/li>\n<\/ul>\n<h3 id=\"conclusion\">6. Conclusion<\/h3>\n<p>Through the Well-architect review activity, we have identified the issues in the client\u2019s architecture and provided the recommendations as per best practices, which helps to remediate those issues and not the state of client architecture is Well-Architected and there is no impact on their business, the operation is running smoothly, the client is very satisfied with the CloudThat team and appreciated for our efforts and excellence.<\/p>\n<h3 id=\"aboutcloudthat\">7. About CloudThat<\/h3>\n<p><a href=\"https:\/\/www.cloudthat.com\/\" target=\"_blank\" rel=\"noopener\">CloudThat<\/a> is the authorized AWS Well-Architected Partner, helping other businesses build secure, high-performing, resilient, and efficient infrastructures for their application and workloads.<\/p>\n<p><a href=\"https:\/\/www.cloudthat.com\/\">CloudThat\u00a0<\/a>is also the official AWS (Amazon Web Services) Advanced Consulting Partner and Training partner and Microsoft gold partner, helping people develop knowledge on cloud and help their businesses aim for higher goals using best in industry cloud computing practices and expertise. We are on a mission to build\u00a0a robust\u00a0cloud computing ecosystem by disseminating\u00a0knowledge on technological intricacies within the cloud space.\u00a0Our blogs, webinars,\u00a0case studies, and white papers\u00a0enable all the stakeholders in the cloud computing sphere.<\/p>\n<p>Drop a query if you have any questions regarding Well-Architected Review, AWS WAR Partnership, or consulting opportunity, and I will get back to you quickly. To get started, go through\u00a0our\u00a0<a href=\"https:\/\/www.cloudthat.com\/expert-advisory\/?utm_source=blog-website&amp;utm-medium=text-link&amp;utm_campaign=expert-advisory\">Expert Advisory\u00a0<\/a>page\u00a0and\u00a0<a href=\"https:\/\/www.cloudthat.com\/managed-services-packages\/\">Managed Services Package<\/a>\u00a0that is\u00a0<a href=\"https:\/\/cloudthat.com\/?utm_source=blog-website&amp;utm-medium=text-link&amp;utm_campaign=cloudthat.com\/\">CloudThat<\/a>\u2019s\u00a0offerings.<\/p>\n<h3 id=\"faqs\">8. FAQs<\/h3>\n<ol>\n<li><span style=\"text-decoration: underline;\">How do I access the Well-Architected tool?<\/span><br \/>\nYou can access the AWS Well-Architected Tool by signing into the AWS Management Console with your AWS account. After accessing the AWS Well-Architected Tool, we can define the workload.<\/li>\n<\/ol>\n<ol start=\"2\">\n<li><span style=\"text-decoration: underline;\">There are any charges for using the Well-Architected tool?<\/span><br \/>\nNo, there are no charges.<\/li>\n<\/ol>\n","protected":false},"author":219,"featured_media":11036,"parent":0,"comment_status":"open","ping_status":"open","template":"","blog_category":[3606,3607],"user_email":"prarthitm@cloudthat.com","published_by":"324","primary-authors":"","secondary-authors":"","acf":[],"_links":{"self":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog\/10906"}],"collection":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/users\/219"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/comments?post=10906"}],"version-history":[{"count":1,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog\/10906\/revisions"}],"predecessor-version":[{"id":42715,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog\/10906\/revisions\/42715"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/media?parent=10906"}],"wp:term":[{"taxonomy":"blog_category","embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog_category?post=10906"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}