Leveraging the Cloud from a Military Perspective.


1. Multi-Domain Operations

Collect and integrate data from multi-domain sensors and sources to deliver situational awareness in near-real time.

For NATO to respond effectively against advancing threats, its warfighters across all domains (land, air, sea, cyber and space) need near real-time situational awareness and the ability to make sense of rapidly changing events. This requires automated ingestion and analysis of massive data sets to elicit insights and actionable intelligence. Requiring scale, speed, innovation and a secure resilient network provided by the AWS hyperscale cloud. Creating a synergistic, aware ‘team of teams’ able to operate as a whole. This technically enabled warfighting force operating at SECRET is able to automatically identify threats and propose optimised responses based on resources and operating context. Interoperability is enabled through a standardised data and communication mesh, postured to protect data at the core and to the tactical edge. Multiple bearers provided via AWS edge capabilities and AWS partner capabilities providea resilient communications network. Ensuring commanders maintain the decisionadvantage and data supremacy on the battlefield. 

2. Hyperscale Infrastructure

Hyperscale cloud designed to hostsensitive data, regulated workloads, and address the most stringent governmentsecurity and compliance requirements.

Adopting cloud computing is critical to maintaining the technological advantage of the NATO alliance. The Amazon WebServices (AWS) hyperscale cloud offers truly global reach and provides secure, scalable, and cost-efficient solutions that support the Alliance’s ability to meet mission objectives, enable interoperability, increase innovation, and secure mission-critical workloads. 

3. Global Connectivity

Global Connectivity to Maintain Mission Systems.

The AWS Global Infrastructure enables organisations to be extremely flexible and take advantage of the conceptually infinite scalability of the cloud. Customers used to over provision IT to ensure they had enough capacity to handle their operations at the peak level of activity. Now, NATO can provision the amount of resources that they actually need, knowing they can instantly scale up or down, or out, along with the needs of their organisation. This reduces cost and improves the customer's ability to meet end user demands, at base or at the tactical edge. In hyperscale cloud, organisations can quickly spin up resources as necessary, deploying hundreds or even thousands of servers in minutes.

Connectivity is critical in the context of mission. Sharing data from a reconnaissance flight or commercial satellite provider, to a compute stack with the scale and tooling needed to find actionable insights requires data to flow between on-premises infrastructure, cloud infrastructure, edge devices and requires edge to edge connectivity. Data may also need to flow between allies. To enable this, AWS invests heavily in AWS-owned networking capability, including 400GbE dedicated network capacity between Regions and network fabrics to deliver customers' with scale and connectivity. AWS offers 600+ edge locations with local ISP peering and 135 locations that support 200Gb dedicated leased line connectivity from customers to AWS Regions.

All of this is essential to support data capture, analysis and distribution, which offers NATO the global reach and ability to maintain connectivity to their systems from virtually any point on the planet.

4. Reliability

The Most Secure, Extensive, and Reliable Global Cloud Infrastructure, for mission-critical applications.

AWS’ global cloud infrastructure offers customers unmatched security, scale, reliability and performance that you depend upon for your most important applications. For over 17 years, AWS has been continually expanding its services to support virtually any cloud workload. Today, defence customers benefit from more than 200 fully featured services for compute, storage, databases, networking, analytics, AI, IoT, security, hybrid, virtual and augmented reality, and application development, deployment, and management.In defence, every second counts. AWS runs a redundant 400 GbE global network, with private capacity between all AWSRegions. Defence customers can connect to every AWS Region from over 135 AWSDirect Connect Points of Presence (PoP) and our edge networking capability offers customers 600+ PoP in 50 countries, with direct peering to all majorISPs. Whether you need to deploy your application workloads across the globe in a single click, or you want to buildand deploy specific applications closer to your end-users with single-digit millisecond latency, AWS provides you the cloud infrastructure where and when you need it.

5. Secure Services

Raiseyour security posture with AWS infrastructure and services

AWS is architected to be the most secure cloud computingenvironment available today. Our core infrastructure is built to satisfy thesecurity requirements for the military, global banks, and otherhigh-sensitivity organisations. With AWS, the NATO alliance will improve itsability to meet and evidence core security and compliance requirements, such asidentity & access management, key management, data locality, encryption andprotection, HSM, and confidentiality with our comprehensive services and features.AWS allows you to automate manual security tasks so you can shift your focus toscaling and innovating against your mission.

6. Compliance

Evolving security & compliance posture to meet mission.

Security and compliance is a shared responsibility between AWS and the customer. This shared model can help relieve the customer’s operational burden as AWS operates, manages and controls the components from the host operating system and virtualization layer down to the physical security of the facilities in which the service operates. To help customers evidence this, AWS supports 143security standards and compliance certifications, including C5, ITAR, CSA,PCI-DSS, HIPAA/HITECH, FedRAMP, GDPR, FIPS 140-2, and NIST 800-171, helping satisfy compliance requirements for virtually every regulatory agency around the globe. AWS is actively engaged with NATO OCIO and NCI Agency to map NATO security controls at NATO Unrestricted and NATO Restricted to AWS hyperscale cloud. Once concluded, this project will demonstrate how NATO and allies can continually evidence compliance with NATO-defined security controls, in the AWS hyperscale cloud.

7. Cloud Resilience

Maintaining operationaleffectiveness in contested environments – resilience.

Resiliency is the state or quality of being resilient, of being able to recover from disruption and maintain the ability to function. A core component of NATO’s ability to deliver the strategic effect of deterrence is resiliency, of which the digital component underpins every function, weapon system, and asset. Digital resiliency is part of operational readiness. In using AWS hyper-scale cloud,NATO can leverage the global inter-connected infrastructure made up of 33 Regions, 100s of edge points of presence and with multiple redundant connections and low latency for worldwide access.  Defence customers can move data around the world via this global network as required based on threat states and mission needs. Additionally, in the event of conflict, the AWS cloud can rapidly scale to meet capacity demands of an escalating mission and build digital interoperable environments as required by allies, formations and partnerships. At the tactical level, AWS edge capabilities (Snow family), AWSGround Station and Kuiper low-earth orbit (LEO) satellites provide compute and storage in contested environments, ensuring forward deployed and isolated unit scan maintain operational effectiveness.

8. AWS TrustedSecure Enclave (TSE)

Secure enclaves in hyperscale commercial cloud

TSE enables customers to build a comprehensive cloud architecture for sensitive workloads in national security & defence. By using a multi-account architecture on AWS, you can deliver your missions while keeping sensitive data and workloads secure. This helps defence customers to meet strict and unique security and compliance requirements, addressing central identity and access management, governance, data security, comprehensive logging, and network design and segmentation in alignment with a number of national security frameworks.


References

9. AWS at the Tactical Edge

Access to real time data can be the difference between mission accomplished and mission failure.

As Task Forces engage in the necessary operations to find, fix and destroy the enemy, they require access to up-to-date, actionable and verifiable intelligence. They require the ability to disseminate this information quickly, where and when needed, and to coordinate efforts to successful outcomes. AWS provides the critical edge computing solutions needed to make mission happen anytime, anywhere.AWS' edge computing capability is further extended by partners, like Anduril as one example. Anduril Lattice runs at edge and on cloud from Restricted to Above Secret, enabling the Alliance, and theAlliance nations to share, fuse, and secure data for exploitation by a range of applications and be functionally shared to ensure that NATO can meet it’s tactical, operational mandates and ensure and assure the security of its members states.


References

10. Snow Family

Highly-secure, portable devices to collect and process data at the edge, and migrate data into and out of AWS 

AWS: Snow Products

The AWS Snow Family helps customers run operations in remote, non-data centre environments where there could be a lack of consistent network connectivity, and where the environment may be unsuitable for traditional server hardware. AWS Snowball Edge offers portable, ruggedized hardware appliances that bring AWS compute and storage services to edge locations. The AWS Snow Family is part of the continuum of AWS Hybrid Cloud services that extend AWS infrastructure and services into the edge, helping customers run low-latency applications, and meet data security requirements close to where data originates, is processed, and must be acted upon. 

SnowFamily devices can be deployed in locations with denied, disconnected, intermittent, or limited (DDIL) network connectivity to AWS. You can use AWSSnowball Edge as an IoT Hub, to run data, imagery and video analytics for content generated at the edge, or to run AI/ML inference at the edge. Some large data transfer examples include cloud migration, disaster recovery, data centre relocation, and remote data collection projects. AWS Snowball supports specific Amazon EC2 instance types and AWS Lambda functions, so you can develop and test in the AWS Cloud, then deploy applications onto devices in remote locations to collect, pre-process, and ship the data to AWS. Common use cases include data migration, data transport, image collation, IoT sensor stream capture, and machine learning.


References

11. Data Migration

Flexible data transfer back to Command leading to faster decision cycles.

AWS DataSync

AWS DataSync, simplifies and accelerates the transfer of large data volumes between on-premises storage and various AWS services, including Amazon S3, Amazon Elastic File System (AmazonEFS), and Amazon FSx for Windows File Server. By automating tasks such as scripting copy jobs, scheduling transfers, monitoring data movement, and optimizing network utilization, DataSync streamlines migrations and reduces theburden on IT operations. The DataSync software agent seamlessly connects toNetwork File System (NFS) and Server Message Block (SMB) storage protocols, eliminating the need for application modifications. With the ability to transfer hundreds of terabytes and millions of files at speeds up to 10 times faster than open-source tools, DataSync offers unparalleled efficiency over th einternet or AWS Direct Connect links. Organisations can leverage DataSync for avariety of use cases, including migrating active datasets or archives to AWS, transferring data for timely analysis and processing in the cloud, and replicating critical data for business continuity.


References

12. Data Storage & Computing

Processing, storing and transferring data from the edge.

As NATO enhances itstraining environments with data from the battlespace, AWS can support ongoingtraining and mission rehearsal requirements. Data collected at the edge can beused to develop up-to-date mission scenarios. Providing warfighting units withfresh data-driven feedback on their performance, as well as predictions on howunits could perform in different environments and contexts, thus preparingwarfighting formations for the future fight. 

13. En-route to Mission

Connecting to the edge.

Once a unit is deployed, the ability to receive mission updates can become difficult in low-latency environments and remote locates. AWS helps solve this capability gap by providing access to the cloud using fully managed services like AWS Ground Station, which provides direct access to AWS services and the AWS Global Infrastructure including a low-latency global fibre network. Amazon’s Project Kuiper will provide global broadband access through a constellation of 3,236 satellites inlow Earth orbit (LEO). Providing resilient communication while en-route, and to the remotest locations. This enables commanders to stay informed whilst on the move and situationally aware from the moment they land. 


References

14. AWS Mission Command

Securely enabling defence and national security missions with cloud computing.

From training, to logistics, medical to procurement, flight line to supporting the front line, AWS can provide solutions to help solve the challenges formations, units and allies face. More than just providing compute and storage capability in the cloud, AWS can help intelligence, planning, and operations teams leverage newer, cost effectiveAI/ML, analytics, simulations and other technologies. 

15. AI-Enhanced Decision Making

AI-enhanced Decision Making

Allied forces collect an abundance of data from sensors, sources and other information assets. Forces must sift through the noise, to identify the information needed, then disseminate that information quickly where needed. With AWS, allies will design data centric architectures and approaches that leverage key AI/ML solutions, automate processes and drive efficiencies in human intervention and decision making, to speed data gathering, analysis, delivery, improve accuracy and enhance current and future mission success.


References

16. Compute Power

Price performant ML infrastructure to reduce deep-learning training time from months to minutes, whilst reducing costs.

AWS-owned ML chips 

Over the last five years, AWS has invested in our own silicon to push the envelope on performance and price for demanding workloads like ML training and inference. Our AWS Trainium and AWS Inferentia chips offer the lowest cost for training models and running inference in the cloud. This maximizes performance and control costs, whilst also delivering energy efficiencies to customers to support with sustainability objectives. In addition, our collaboration with leading industry providers, like NVIDIA offers scale to customers that are exploring digital twin and advanced modelling and simulation capabilities. 

17. AWS Analytics

Fastest way to get insights from your data.

AWS provides the broadest and deepest portfolio of purpose-built analytical tools. Intelligence teams can leverage our analytics suite to optimise analysis for specific Request for Information(RFIs) and/or data sets. Enabling rapid elicitation of insights and understanding to support mission. All of our analytics services support open file formats like Apache Parquet, so users can store it once in a standard format and then analyze it using whatever tool or technique is most appropriate.

18. Enhanced Field Operations

Run AWS infrastructure and services on premises for a truly consistent hybrid experience.

Sometimes a smaller digital footprint is needed with the ability to run disconnected to support fast, agile and discreet operations. Deployed operators must be able to move as the mission demands with the data needed to enable mission success.With AWS, forward deployed teams can leverage cloud and edge computing operations to reduce footprint, RF signature and time to setup/tear down, all while maintaining the commanders’ situational awareness to operate effectively. 


References

19. Integrating Data

Interoperate using shared data repository, to meet mission, at scale AWS Data Lake

Information is the lifeblood of military organisations, with massive amounts of data collected every day. This abundance of data creates the opportunity for unprecedented insights and data-driven decision making, both locally and across allies, enabling interoperability. AWS enables data lakes to be built in days with AWS Lake Formation, rapidly enabling users to turn information into timely insights. This value is exploited by making it accessible to users who need it wherever they are deployed. A centralised data lake enables different functions to leverage the data for different mission needs, and provides near real-time sharing across allies and domains (land, air, maritime, space and cyberspace). 


References

20. Military SaaS Providers Offer Scale

Meet mission with agility, efficiency and at scale by working with specialist vertical providers and dual-use capabilities.

Recognising the importance of defence industrial base suppliers and military SaaS providers, AWS has invested in dedicated headcount to manage our global defence partner business. We actively manage relationships with industry-leading military SaaS providers who support end customers meet mission objectives with specialist vertical capabilities in theC2, Big Data and Analytics, AI, Cloud Migration, DevOps, Geospatial andInformation Assurance, and Security Services domains, amongst others. Commercial innovation runs on AWS. 83% of global unicorns run AWS and 90% of the Cloud Top 100 software companies run AWS. As such, AWS is uniquely positioned – and working actively - to support defence customers to benefit from dual-use technologies with military applicability. AWS actively supports defence innovators. 27/44originally awarded NATO DIANA startups run AWS. Defence Techs have business models that enable them to meet end customer mission with agility and innovation. AWS is actively supporting this community, working to translate demand signals from end customers and offer the defence techs of the future a path to scale.

21. Multi / HybridCloud

Centralize and simplifymanagement and monitoring of hybrid and multi & hybrid environments.

Customers can extend the AWS cloud operations experience across hybrid and other cloud environments for secure and seamless management, compliance, and observability. AWS Systems Manager allows customers to manage, update, and patch servers and virtual machines (VMs) across AWS, on premises, and on other clouds from a single console. AWS Config centralizes configuration management and compliance reporting so that customers can monitor the configurations of tens of thousands of VMs, managed databases, storage, and networking components from AWS and other cloud providers. For observability, customers can use Amazon CloudWatch and Amazon OpenSearch Service to set alarms; collect logs, metrics, and events; and monitor workloads, VMs, and containers across environments. 

Visit the desktop solution for AWS' Leveraging the Cloud from a Military Perspective.
See the Solution