ZS Implements Secure Amazon SageMaker Environment

Serdar HocamAuthor & Editor

ZS has established a security-focused Amazon SageMaker infrastructure that balances developer agility with strict oversight, reaching thousands of users across more than 200 domains.

◉ 0 views
How ZS democratized secure ad-hoc analytics with Amazon SageMaker | Amazon Web Services

To strike a balance between developer agility and compliance requirements faced by companies in regulated industries, ZS has built a secure and scalable analytics environment on Amazon SageMaker.

Secure Machine Learning Infrastructure

Based on Amazon SageMaker Studio for enterprise operations, ZS enabled data scientists and analysts to access artificial intelligence capabilities in compliance with healthcare sector requirements.

No-Internet Mode and Package Management

The solution architecture operates without internet access by default, utilizing JFrog Artifactory integration and real-time scanning mechanisms for package management.

Details of Multi-Tenant Technical Architecture

The platform is designed with a multi-tenant architecture hosting separate Amazon SageMaker domains for each tenant, offering isolated storage units and network settings.

Three-Tier Identity and Access Structure

Adopting the principle of least privilege, ZS has implemented a three-tier IAM structure consisting of domain, user, and space execution roles, thereby increasing operational flexibility.

Data Protection and Security Integrations

While AWS KMS encryption is enabled by default on resources, CrowdStrike threat detection, Splunk log collection, and AWS CloudTrail audit logs have been integrated into the system.

Measurable Business Impact and Efficiency

With the expansion of the platform, Amazon SageMaker has become the primary ad-hoc analytics tool, ensuring operational efficiency, cost optimization, and security compliance.