Security Pillar

The security pillar focuses on protecting information and systems. Key topics include confidentiality and integrity of data, identifying and managing who can do what with privilege management, protecting systems, and establishing controls to detect security events.

The Security pillar includes the ability to protect information, systems, and assets while delivering business value through risk assessments and mitigation strategies.

Security Questions

AWS Services for Security

AWS Identity and Access Management (IAM)

Enables you to manage access to AWS services and resources securely.

Amazon GuardDuty

Provides intelligent threat detection for your AWS accounts and workloads.

AWS Security Hub

Gives you a comprehensive view of your security alerts and security posture across your AWS accounts.

Amazon Inspector v2

Provides enhanced automated vulnerability management for EC2 instances, container images, and Lambda functions with improved scanning speed, broader coverage, and integration with software bill of materials (SBOM).

AWS Security Lake

Automatically centralizes security data from AWS environments, SaaS providers, on-premises, and cloud sources into a purpose-built data lake stored in your account. Provides normalized security data in Open Cybersecurity Schema Framework (OCSF) format.

AWS Config (Enhanced Capabilities)

Provides enhanced configuration management and compliance monitoring with expanded rule coverage, advanced remediation capabilities, improved multi-account support, and enhanced organizational compliance features.

AWS Key Management Service (KMS)

Makes it easy for you to create and manage cryptographic keys and control their use.

AWS Shield

Provides protection against DDoS attacks for applications running on AWS.

Amazon Macie

Uses machine learning to automatically discover, classify, and protect sensitive data in AWS, providing data security and data privacy capabilities.

AWS CloudTrail

Provides governance, compliance, operational auditing, and risk auditing of your AWS account with enhanced insights and advanced event selectors.

AWS WAF

Helps protect your web applications or APIs against common web exploits and bots that may affect availability, compromise security, or consume excessive resources.


Table of contents