Connecting with Amazon Web Services (AWS) cloud accounts with IBM Guardium Exposure Manager

Connect one or more Amazon Web Services (AWS) cloud accounts with IBM® Guardium® Exposure Manager. The connection automatically creates three roles that enable IBM Guardium Exposure Manager to discover sensitive data in the connected AWS cloud accounts. For more information about the roles, see the Results section.

Before you begin

Verify that you have the following before you start connecting your AWS cloud accounts with IBM Guardium Exposure Manager:
  • List of AWS cloud account IDs that you want to connect to IBM Guardium Exposure Manager
  • An admin AWS user to run the CloudFormation scripts

About this task

Use the following steps to connect IBM Guardium Exposure Manager with Amazon Web Services (AWS) cloud accounts.

Procedure

  1. From the main menu, click Management hub > Connections.
  2. On the Connections page, click Add connection.
  3. On the Add connection page, select Amazon Web Services, and then click Next.
  4. In the Add accounts step, provide the cloud account details (Account ID, Account name, and Environment), and then click the plus icon.
    Note:
    • By default, the cloud account that you add at first is tagged as the Primary account where the analyzer is deployed. To know more about the analyzer, see Analyzer.
    • If you want to add more than one cloud account, repeat the account addition process (provide Account ID, Account name, and Environment, and then click the plus icon) as many times as required.
  5. After you have added all the cloud accounts, click Next.
    If you click Cancel instead of Next, then the system displays the status message, Connection pending, signifying that the list of cloud accounts is saved but none of the cloud accounts are connected successfully.
  6. In the Connect accounts step, follow the on-screen instructions to create CloudFormation Stackset for the cloud accounts that you have added, and then click Next.
    Note: If you click Cancel instead of Next, then the system displays either of the following status messages:
    • Connection pending, signifying that the list of cloud accounts is saved but none of the cloud accounts are connected successfully.
    • Progress saved, signifying that the list of cloud accounts is saved but only a few of the cloud accounts are connected successfully.
  7. In the Add regions step, follow the on-screen instructions to add regions for the cloud accounts that you have added, and then click Done.
    Note: If you click Cancel instead of Done, then the system displays one of the following status messages:
    • No regions added, signifying that you have not added any regions. You can click Add regions in the status message or you can add the regions later.
    • Regions partially added, signifying that you have added a few of the regions. You can add the other regions later.
    • All steps completed, signifying that you have completed all the steps successfully and all your data is saved.
    If you click Done, then the system displays the following status message:

    Accounts connected successfully, signifying that you have connected all or a few of the cloud accounts successfully. If you have not added all the regions for the cloud accounts, you can click Add more regions in the status message or you can add the regions later.

Results

When you connect IBM Guardium Exposure Managerwith an AWS cloud account, the following three roles are auto created:
Cross-Account role
Scans and monitors the metadata of the data assets that IBM Guardium Exposure Manager discovers. The Cross-Account role is a read-only role with some create permissions mainly for IBM Guardium Exposure Manager resources that are used for categorization of data.
Analyzer role
Reads the data inside your data stores, allowing the IBM Guardium Exposure Manager analyzer to classify what’s inside the data stores. Only a IBM Guardium Exposure Manager analyzer can access the data stores and the stored data in your cloud account. A t2.large instance type is used as the cloud analyzer by IBM Guardium Exposure Manager.
Log Ingestion role
Enables IBM Guardium Exposure Manager to process your data store logs.