Managing 
Cloud Infrastructure

Case Study

Executive Summary

Established in 1927, Woh Hup began humbly as a one-man business in Malaya. Today, it is one of Singapore’s largest privately-owned construction and civil engineering specialists.   

The company strives to ensure high standards of safety and quality on every project and aims to create lasting value for its clients. Within the organisation, Woh Hup is committed to maximising opportunities for employees to attain their full career potential.   

Woh Hup continually seeks to spearhead cutting-edge, innovative building solutions in the Singapore market and has forged strategic joint-venture partnerships with overseas counterparts. These efforts have contributed to the company’s market expansion and cemented its position at the forefront of the construction industry, both locally and regionally.  

The Challenges

  • Eliminating the use of static credentials by enforcing the use of temporary, time-bound access to improve security, auditability, and compliance traceability.

  • Ensuring that cryptographic keys are managed securely and that data is encrypted at rest and in transit.

  • Ensuring security and compliance requirements are met by implementing identity-based access controls, enforcing least privilege principles, enabling audit logging, securing data in transit and at rest, and adhering to regulatory standards.

  • Ensuring that detailed logs of all user and system activities are consistently captured and retained to support compliance, traceability, and audit readiness.

Solution

AsiaPac used IAM roles for permissions between services. AWS Access Keys were not hard-coded, and developers used SAML to assume roles defined by the client’s security team. IAM users were created with least privilege policies.

 AsiaPac used AWS managed keys for services like Elastic Block Storage (EBS), Workspaces, and Backup. Data at rest is encrypted using AWS Key Management Service (KMS).    

AsiaPac implemented IAM roles with MFA, monitored the environment with a Cyber Watch Center (CSOC), and followed AWS security best practices. They also conducted a security workshop during the project kickoff.    

AsiaPac followed their internal Standard Operating Procedure (SOP) to enable CloudTrail for every AWS account created. Logs are pushed to S3 with versioning and encryption enabled.  

AsiaPac implemented IAM roles with MFA, monitored the environment with a Cyber Watch Center (CSOC), and followed AWS security best practices. They also conducted a security workshop during the project kickoff.    

AsiaPac followed their internal Standard Operating Procedure (SOP) to enable CloudTrail for every AWS account created. Logs are pushed to S3 with versioning and encryption enabled.  

Results

WohHup benefits from enhanced security through the use of IAM roles, MFA, encryption, and proactive monitoring, ensuring robust protection of resources and data.

Compliance is ensured by adhering to AWS security best practices and regulatory requirements, minimizing the risk of non-compliance penalties.

Operational efficiency is improved by automating credential management, encryption, and monitoring, reducing manual effort. Data protection is prioritized with encryption both at rest and in transit, along with secure key management to safeguard sensitive information.

Proactive threat detection is facilitated by CSOC and CloudTrail, enabling real-time monitoring and rapid response to security incidents.

Knowledge transfer through security workshops empowers internal teams to effectively manage and maintain security practices.