ZS Implements Secure Amazon SageMaker Environment
ZS has established a security-focused Amazon SageMaker infrastructure that balances developer agility with strict oversight, reaching thousands of users across more than 200 domains.
To strike a balance between developer agility and compliance requirements faced by companies in regulated industries, ZS has built a secure and scalable analytics environment on Amazon SageMaker.
Secure Machine Learning Infrastructure
Based on Amazon SageMaker Studio for enterprise operations, ZS enabled data scientists and analysts to access artificial intelligence capabilities in compliance with healthcare sector requirements.
No-Internet Mode and Package Management
The solution architecture operates without internet access by default, utilizing JFrog Artifactory integration and real-time scanning mechanisms for package management.
Details of Multi-Tenant Technical Architecture
The platform is designed with a multi-tenant architecture hosting separate Amazon SageMaker domains for each tenant, offering isolated storage units and network settings.
Three-Tier Identity and Access Structure
Adopting the principle of least privilege, ZS has implemented a three-tier IAM structure consisting of domain, user, and space execution roles, thereby increasing operational flexibility.
Data Protection and Security Integrations
While AWS KMS encryption is enabled by default on resources, CrowdStrike threat detection, Splunk log collection, and AWS CloudTrail audit logs have been integrated into the system.
Measurable Business Impact and Efficiency
With the expansion of the platform, Amazon SageMaker has become the primary ad-hoc analytics tool, ensuring operational efficiency, cost optimization, and security compliance.