SEC01-BP08: Evaluate and implement new security services and features regularly
Evaluate and implement security services and features from AWS and AWS Partners that allow you to evolve the security posture of your workload.
Implementation guidance
AWS regularly releases new security services and features to help you improve your security posture. By staying informed about these releases and evaluating them for your workloads, you can continuously enhance your security capabilities and address evolving threats.
Key steps for implementing this best practice:
- Stay informed about new security services and features: - Subscribe to the AWS What’s New announcements
- Follow the AWS Security Blog
- Attend AWS events like re:Invent, re:Inforce, and AWS Summits
- Join AWS security webinars and virtual workshops
- Follow AWS security experts on social media
- Participate in AWS security communities and forums
 
- Establish a process for evaluating new security services: - Create a security roadmap aligned with your business objectives
- Define criteria for evaluating new security services
- Assign responsibility for monitoring and evaluating new services
- Establish a regular cadence for security service reviews
- Document evaluation results and decisions
 
- Test new security services in non-production environments: - Set up dedicated test accounts for security evaluations
- Create proof-of-concept implementations
- Test integration with existing security tools and processes
- Evaluate the impact on performance, cost, and operations
- Document findings and lessons learned
 
- Implement new security services strategically: - Prioritize services that address your highest security risks
- Develop an implementation plan with clear milestones
- Start with low-risk workloads before expanding to critical ones
- Monitor and measure the effectiveness of new security services
- Adjust your implementation based on results
 
- Continuously improve your security posture: - Regularly review the effectiveness of implemented security services
- Stay informed about updates to existing security services
- Retire outdated or redundant security controls
- Adjust your security strategy based on evolving threats
- Share knowledge and best practices across your organization
 
Implementation examples
Example 1: Security service evaluation framework
CODE SNIPPET WILL BE PROVIDED SOON –>
Example 2: Security services implementation roadmap
CODE SNIPPET WILL BE PROVIDED SOON –>
Example 3: Automated security service deployment
CODE SNIPPET WILL BE PROVIDED SOON –>
AWS services to consider
Benefits of regularly evaluating and implementing new security services
- Enhanced security posture: Access to the latest security capabilities
- Proactive threat mitigation: Stay ahead of evolving security threats
- Operational efficiency: Leverage new automation and integration capabilities
- Cost optimization: Take advantage of more efficient security solutions
- Compliance support: Address new compliance requirements with purpose-built services
- Reduced security debt: Avoid accumulating outdated security practices
- Competitive advantage: Implement security innovations faster than competitors