Module:6
AWS Security and Compliance
Security
Cloud Security:
• Cloud security is a set of policies, technologies, and controls that protect cloud-based
data, applications, and infrastructure from threats. It's important because cloud
computing is a primary method for both individuals and businesses, and data can be
accessed remotely from anywhere.
Cloud security can help with:
Protecting data
• Cloud security protects data from malware, hackers, and unauthorized access. It also helps with data governance and compliance.
Protecting users
• Cloud security protects users from threats no matter how they access the internet.
Securing hybrid and remote work
• Cloud security protects apps, data, and users in the cloud against compromised accounts, malware, and data breaches.
Blocking threats earlier
• Cloud security solutions can help identify threats faster, so you can stop malware before it spreads.
• Some cloud security services include: Firewall as a service, Cloud-based virtual private networks (VPNs), Key management as a service
(KMaaS), Secure Access Service Edge (SASE), and Zero-trust network access (ZTNA).
Security
• Cloud security at AWS is the highest priority. As organizations embrace the scalability and
flexibility of the cloud, AWS is helping them evolve security, identity, and compliance into key
business enablers.
• AWS builds security into the core of our cloud infrastructure, and offers foundational services
to help organizations meet their unique security requirements in the cloud.
• As an AWS customer, you will benefit from a data center and network architecture built to
meet the requirements of the most security-sensitive organizations.
• Security in the cloud is much like security in your on-premises data centers—only without the
costs of maintaining facilities and hardware. In the cloud, you don’t have to manage physical
servers or storage devices.
• Instead, you use software-based security tools to monitor and protect the flow of information
into and out of your cloud resources.
Benefits of AWS security
• Keep Your data safe — The AWS infrastructure puts strong safeguards in place
to help protect your privacy. All data is stored in highly secure AWS data
centers.
• Meet compliance requirements — AWS manages dozens of compliance
programs in its infrastructure. This means that segments of your compliance
have already been completed.
• Save money — Cut costs by using AWS data centers. Maintain the highest
standard of security without having to manage your own facility
• Scale quickly — Security scales with your AWS Cloud usage. No matter the size
of your business, the AWS infrastructure is designed to keep your data safe.
Compliance
• Cloud compliance is the process of following the regulations, standards, and laws that govern the use of
cloud computing services. The goal of cloud compliance is to ensure that data stored and managed in
the cloud is protected and used responsibly.
Here are some reasons why cloud compliance is important:
Data security
• Cloud compliance helps to ensure that sensitive information is protected and that data privacy is
maintained.
Customer trust
• Cloud compliance helps to build and maintain trust between cloud service providers and their clients.
Legal and financial consequences
• A lack of compliance can lead to legal challenges, penalties, fines, and other negative consequences.
Reputation
• Compliance failures can lead to reputational losses and damage relationships with customers and
investors.
Some common regulatory requirements for cloud compliance include:
• The Health Insurance Portability and Accountability Act (HIPAA)
• Payment Card Industry Data Security Standard (PCI DSS)
• Gramm-Leach-Bliley Act (GLBA)
• The EU's General Data Protection Regulation (GDPR)
AWS Cloud Compliance
• AWS Cloud Compliance helps you understand the robust controls in place at AWS for
security and data protection in the cloud.
• Compliance is a shared responsibility between AWS and the customer, and you can visit
the Shared Responsibility Model to learn more.
• Customers can feel confident in operating and building on top of the security controls AWS
uses on its infrastructure.
• The IT infrastructure that AWS provides to its customers is designed and managed in
alignment with best security practices and a variety of IT security standards.
• The following is a partial list of assurance programs with which AWS complies:
• SOC 1/ISAE 3402, SOC 2, SOC 3 (System and Organization Controls) (International Standard
on Assurance Engagements)
• FISMA (Federal Information Security Modernization Act), DIACAP (Department of Defense
Information Assurance Certification and Accreditation Process), and FedRAMP (Federal
Risk and Authorization Management Program)
• ISO 9001, ISO 27001, ISO 27017, ISO 27018 (International Organization for
Standardization)
AWS Shared Responsibility Model
• Security and Compliance is a shared responsibility between AWS and the customer.
• This shared model can help relieve the customer’s operational burden as AWS operates,
manages and controls the components from the host operating system and virtualization
layer down to the physical security of the facilities in which the service operates.
• The customer assumes responsibility and management of the guest operating system
(including updates and security patches), other associated application software as well as the
configuration of the AWS provided security group firewall.
• Customers should carefully consider the services they choose as their responsibilities vary
depending on the services used, the integration of those services into their IT environment,
and applicable laws and regulations.
• The nature of this shared responsibility also provides the flexibility and customer control that
permits the deployment.
As shown in the chart below, this differentiation of responsibility is commonly referred to as
Security “of” the Cloud versus Security “in” the Cloud.
• AWS responsibility “Security of the Cloud” - AWS is responsible for protecting the
infrastructure that runs all of the services offered in the AWS Cloud. This infrastructure is
composed of the hardware, software, networking, and facilities that run AWS Cloud
services.
• Customer responsibility “Security in the Cloud” – Customer responsibility will be
determined by the AWS Cloud services that a customer selects. This determines the
amount of configuration work the customer must perform as part of their security
responsibilities.
• For example, a service such as Amazon Elastic Compute Cloud (Amazon EC2) is categorized
as Infrastructure as a Service (IaaS) and, as such, requires the customer to perform all of the
necessary security configuration and management tasks.
• Customers that deploy an Amazon EC2 instance are responsible for management of the
guest operating system (including updates and security patches), any application software
or utilities installed by the customer on the instances, and the configuration of the AWS-
provided firewall (called a security group) on each instance.
Inherited Controls – Controls which a customer fully inherits from AWS.
• Physical and Environmental controls
Shared Controls – Controls which apply to both the infrastructure layer and customer layers, but in completely
separate contexts or perspectives. In a shared control, AWS provides the requirements for the infrastructure and
the customer must provide their own control implementation within their use of AWS services. Examples
include:
• Patch Management – AWS is responsible for patching and fixing flaws within the infrastructure, but
customers are responsible for patching their guest OS and applications.
• Configuration Management – AWS maintains the configuration of its infrastructure devices, but a customer
is responsible for configuring their own guest operating systems, databases, and applications.
• Awareness & Training - AWS trains AWS employees, but a customer must train their own employees.
Customer Specific – Controls which are solely the responsibility of the customer based on the application they
are deploying within AWS services. Examples include:
• Service and Communications Protection or Zone Security which may require a customer to route or zone data within
specific security environments.
AWS Key Management Service
• AWS Key Management Service (AWS KMS) is an AWS managed service that makes it easy for you to create and
control the encryption keys that are used to encrypt your data.
• The AWS KMS keys that you create in AWS KMS are protected by FIPS 140-2 (Federal Information
Processing Standard Publication) validated hardware security modules (HSM). They never
leave AWS KMS unencrypted. To use or manage your KMS keys, you interact with AWS KMS.
Additionally, you can create and manage key policies in AWS KMS, ensuring that
only trusted users have access to KMS keys.
AWS KMS pricing
• As with other AWS products, using AWS KMS does not require contracts or minimum purchases.
• Each AWS KMS key that you create in AWS KMS costs $1/month. The $1/month charge is the
same for symmetric keys, asymmetric keys, HMAC keys, multi-Region keys.
• For KMS keys that you rotate automatically or on demand, the first and second rotation of the key
adds $1/month (prorated hourly) in cost. This price increase is capped at the second rotation, and
any subsequent rotations will not be billed.
• You are not charged for the following:
• Creation and storage of AWS managed or AWS owned KMS keys. These keys are automatically created
on your behalf when you first attempt to encrypt a resource in an AWS service that integrates with AWS
KMS. You can neither manage the lifecycle nor access permissions on AWS managed keys.
• There is no charge for customer managed KMS keys that you manage and are scheduled for deletion. If
you cancel the deletion during the waiting period, the customer managed KMS key will incur charges as
though it was never scheduled for deletion.
• There is no monthly charge for data keys or data key pairs that AWS KMS generates beyond the charge
for the API call.
• Which type of keys does AWS KMS manage?
a) Public and private keys only
b) Customer master keys (CMKs) / KMS keys
c) Security group keys
d) SSL/TLS certificates
• b) Customer master keys (CMKs) / KMS keys
• AWS KMS integrates with which of the following services for
encryption?
a) Amazon S3
b) Amazon EBS
c) Amazon RDS
d) All of the above
• d) All of the above
• What security standard does AWS KMS comply with for key
management?
a) ISO 9001
b) PCI DSS only
c) FIPS 140-2
d) ITIL
• c) FIPS 140-2
AWS Web Application Firewall
• AWS WAF is a web application firewall that lets you monitor the HTTP(S) requests that are forwarded to
your protected web application resources. You can protect the following resource types:
• Amazon CloudFront distribution
• Amazon API Gateway REST API
• Application Load Balancer
• AWS AppSync GraphQL API
• Amazon Cognito user pool
• AWS App Runner service
• AWS Verified Access instance
• AWS WAF lets you control access to your content.
Based on criteria that you specify, such as the IP addresses that requests originate from or the values of query strings.
How AWS WAF works
• Use AWS WAF to control how your protected resources respond to HTTP(S)
web requests. You do this by defining a web access control list (ACL) and
then associating it with one or more web application resources that you
want to protect.
• The associated resources forward incoming requests to AWS WAF for
inspection by the web ACL.
• In your web ACL, you create rules to define traffic patterns to look for in
requests and to specify the actions to take on matching requests. The action
choices include the following:
• Allow the requests to go to the protected resource for processing and response.
• Block the requests.
• Count the requests.
• Run CAPTCHA or challenge checks against requests to verify human users and standard browser use.
AWS WAF components
The following are the central components of AWS WAF:
• Web ACLs – You use a web access control list (ACL) to protect a set of AWS resources. You create a web
ACL and define its protection strategy by adding rules. Rules define criteria for inspecting web requests and
they specify the action to take on requests that match their criteria.
A web ACL is an AWS WAF resource.
• Rules – Each rule contains a statement that defines the inspection criteria, and an action to take if a web
request meets the criteria. When a web request meets the criteria, that's a match. You can configure rules to
block matching requests, allow them through, count them, or run bot controls against them that use
CAPTCHA puzzles or silent client browser challenges.
• Rule groups – You can define rules directly inside a web ACL or in reusable rule groups.
• Web ACL capacity units (WCUs) – AWS WAF uses WCUs to calculate and control the operating resources
that are required to run your rules, rule groups, and web ACLs.
• Which AWS services can AWS WAF be directly integrated with?
a) Amazon S3
b) Amazon CloudFront and Application Load Balancer
c) Amazon RDS
d) Amazon DynamoDB
• b) Amazon CloudFront and Application Load Balancer
• Which of the following attacks can AWS WAF help mitigate?
a) SQL Injection
b) DDoS
c) Hardware failure
d) Network latency
• a) SQL Injection
• What do you use in AWS WAF to define filtering rules?
a) IAM Roles
b) Web ACLs
c) Security Groups
d) Key Pairs
• b) Web ACLs
AWS Shield
• Protection against Distributed Denial of Service (DDoS) attacks is of primary importance
for your internet-facing applications. When you build your application on AWS, you can
make use of protections that AWS provides at no additional cost.
• Additionally, you can use the AWS Shield Advanced managed threat protection service to
improve your security posture with additional DDoS detection, mitigation, and response
capabilities.
• AWS is committed to providing you with the tools, best practices, and services to help ensure high
availability, security, and resiliency in your defense against bad actors on the internet.
• When you build your application on AWS, you receive automatic protection by AWS against common DDoS
attack vectors, like UDP reflection attacks and TCP SYN floods.
• You can leverage these protections to ensure the availability of the applications that you run on AWS by
designing and configuring your architecture for DDoS resiliency.
• Security is a shared responsibility between AWS and the customers.
• The shared responsibility model describes this as security of the cloud and security in the cloud.
• Which statement is TRUE about AWS Shield tiers?
a) AWS Shield only has one standard version
b) AWS Shield has Standard (free) and Advanced (paid) tiers
c) AWS Shield requires manual activation for Standard
d) AWS Shield Advanced is free for all AWS accounts
• b) AWS Shield has Standard (free) and Advanced (paid) tiers
AWS Security Best Practices
• Objective of AWS Security Best Practices
• AWS Security Best Practices Documentation offers guidelines to build secure and resilient environments on
AWS.
• Helps organizations protect data, manage access control, monitor activities, and ensure compliance.
• Core Pillars of AWS Security
• Identity and Access Management (IAM): Control who can access what.
• Infrastructure Protection: Secure networks, host environments, and maintain control over traffic.
• Data Protection: Encrypt data at rest and in transit to protect against unauthorized access.
• Logging and Monitoring: Track user actions and system events for auditing and compliance.
• Compliance and Frameworks
• AWS aligns with global security standards, such as ISO 27001, SOC(Security Operations Center) and HIPAA
(Health Insurance Portability and Accountability Act) helping businesses maintain regulatory compliance.
CONT
Identity and Access Management (IAM) Best Practices
• Principle of Least Privilege
• Define fine-grained permissions to ensure that users and applications only have the permissions
needed for specific tasks.
• Regularly review and remove unnecessary permissions to reduce risk.
• Enable Multi-Factor Authentication (MFA)
• Enforce MFA on all IAM users, especially root accounts, to add an extra layer of security.
• Use hardware MFA devices for high-sensitivity accounts, such as root or critical user roles.
• IAM Roles and Temporary Credentials
• Use IAM roles instead of creating IAM users for applications and services. Assign roles to
resources to avoid sharing credentials.
• Implement AWS STS (Security Token Service) to grant temporary, time-limited access, reducing
the risk of credential compromise.
• Best Practice Policies
• Use AWS-managed policies as a baseline for permissions but create custom policies for specific
needs.
• Regularly review policies and use tools like IAM Access Analyzer to ensure policies do not allow
overly permissive access.
CONT
Data Protection and Monitoring Best Practices
Data Encryption
• Encrypt sensitive data in transit and at rest using AWS KMS (Key Management Service).
• Enable Server-Side Encryption (SSE) for data stored in services like Amazon S3 and RDS databases.
• For advanced security, use Customer Managed Keys (CMK) in AWS KMS, providing you more
control over key rotation and permissions.
Automated Data Backup and Recovery
• Set up automated backups using services like AWS Backup and enable versioning for Amazon S3 to
safeguard data against accidental deletion.
• Use cross-region replication for disaster recovery to ensure data availability even in the event of a
regional outage.
Incident Response Preparedness
• Implement incident response processes, leveraging AWS tools like AWS CloudFormation to
automate incident recovery.
• Regularly test security configurations and run simulations to ensure rapid recovery and minimize
impact in case of a breach.