Module:6
AWS Security and Compliance
Security
Cloud Security:
Cloud security is a set of policies, technologies, and controls that protect cloud-based data, applications, and
infrastructure from threats. It's important because cloud computing is a primary method for both individuals
and businesses, and data can be accessed remotely from anywhere.
Cloud security can help with:
Protecting data
Cloud security protects data from malware, hackers, and unauthorized access. It also helps with data governance and compliance.
Protecting users
Cloud security protects users from threats no matter how they access the internet.
Securing hybrid and remote work
Cloud security protects apps, data, and users in the cloud against compromised accounts, malware, and data breaches.
Blocking threats earlier
Cloud security solutions can help identify threats faster, so you can stop malware before it spreads.
Some cloud security services include: Firewall as a service, Cloud-based virtual private networks (VPNs), Key management as a service
Security
Cloud security at AWS is the highest priority. As organizations embrace the scalability and
flexibility of the cloud, AWS is helping them evolve security, identity, and compliance into key
business enablers.
AWS builds security into the core of our cloud infrastructure, and offers foundational
services to help organizations meet their unique security requirements in the cloud.
As an AWS customer, you will benefit from a data center and network architecture built to
meet the requirements of the most security-sensitive organizations.
Security in the cloud is much like security in your on-premises data centers—only without
the costs of maintaining facilities and hardware. In the cloud, you don’t have to manage
physical servers or storage devices.
Instead, you use software-based security tools to monitor and protect the flow of
information into and out of your cloud resources.
Benefits of AWS security
• Keep Your data safe — The AWS infrastructure puts strong
safeguards in place to help protect your privacy. All data is
stored in highly secure AWS data centers.
• Meet compliance requirements — AWS manages dozens of
compliance programs in its infrastructure. This means that
segments of your compliance have already been completed.
• Save money — Cut costs by using AWS data centers. Maintain
the highest standard of security without having to manage
your own facility
• Scale quickly — Security scales with your AWS Cloud usage.
No matter the size of your business, the AWS infrastructure is
designed to keep your data safe.
Compliance
Cloud compliance is the process of following the regulations, standards, and laws that govern the
use of cloud computing services. The goal of cloud compliance is to ensure that data stored and
managed in the cloud is protected and used responsibly.
Here are some reasons why cloud compliance is important:
Data security
Cloud compliance helps to ensure that sensitive information is protected and that data privacy is maintained.
Customer trust
Cloud compliance helps to build and maintain trust between cloud service providers and their clients.
Legal and financial consequences
A lack of compliance can lead to legal challenges, penalties, fines, and other negative consequences.
Reputation
Compliance failures can lead to reputational losses and damage relationships with customers and investors.
Some common regulatory requirements for cloud compliance include:
The Health Insurance Portability and Accountability Act (HIPAA)
Payment Card Industry Data Security Standard (PCI DSS)
Gramm-Leach-Bliley Act (GLBA)
The EU's General Data Protection Regulation (GDPR)
AWS Cloud Compliance
AWS Cloud Compliance helps you understand the robust controls in place at AWS
for security and data protection in the cloud.
Compliance is a shared responsibility between AWS and the customer, and you
can visit the Shared Responsibility Model to learn more.
Customers can feel confident in operating and building on top of the security
controls AWS uses on its infrastructure.
The IT infrastructure that AWS provides to its customers is designed and managed
in alignment with best security practices and a variety of IT security standards.
The following is a partial list of assurance programs with which AWS complies:
SOC 1/ISAE 3402, SOC 2, SOC 3 (System and Organization Controls) (International
Standard on Assurance Engagements)
FISMA (Federal Information Security Modernization Act), DIACAP (Department of
Defense Information Assurance Certification and Accreditation Process), and
FedRAMP (Federal Risk and Authorization Management Program)
ISO 9001, ISO 27001, ISO 27017, ISO 27018 (International Organization for
Standardization)
Why Cloud Security & Compliance?
Cloud Security & Compliance
AWS Provides reliable and secure services that help companies to
store sensitive data, applications, and authentication more securely.
Cloud Security & Compliance
Customer Compliance Center
AWS Audit Manager
AWS Config
Summary
AWS Shared Responsibility Model
Security and Compliance is a shared responsibility between AWS and the customer.
This shared model can help relieve the customer’s operational burden as AWS operates,
manages and controls the components from the host operating system and
virtualization layer down to the physical security of the facilities in which the service
operates.
The customer assumes responsibility and management of the guest operating system
(including updates and security patches), other associated application software as well
as the configuration of the AWS provided security group firewall.
Customers should carefully consider the services they choose as their responsibilities
vary depending on the services used, the integration of those services into their IT
environment, and applicable laws and regulations.
The nature of this shared responsibility also provides the flexibility and customer control
As shown in the chart below, this differentiation of responsibility is
commonly referred to as Security “of” the Cloud versus Security “in” the
Cloud.
AWS responsibility “Security of the Cloud” - AWS is responsible for
protecting the infrastructure that runs all of the services offered in the AWS
Cloud. This infrastructure is composed of the hardware, software, networking,
and facilities that run AWS Cloud services.
Customer responsibility “Security in the Cloud” – Customer responsibility
will be determined by the AWS Cloud services that a customer selects. This
determines the amount of configuration work the customer must perform as
part of their security responsibilities.
For example, a service such as Amazon Elastic Compute Cloud (Amazon EC2)
is categorized as Infrastructure as a Service (IaaS) and, as such, requires the
customer to perform all of the necessary security configuration and
management tasks.
Customers that deploy an Amazon EC2 instance are responsible for
management of the guest operating system (including updates and security
patches), any application software or utilities installed by the customer on the
instances, and the configuration of the AWS-provided firewall (called a
Inherited Controls – Controls which a customer fully inherits from AWS.
Physical and Environmental controls
Shared Controls – Controls which apply to both the infrastructure layer and customer layers, but in completely
separate contexts or perspectives. In a shared control, AWS provides the requirements for the infrastructure and
the customer must provide their own control implementation within their use of AWS services. Examples
include:
Patch Management – AWS is responsible for patching and fixing flaws within the infrastructure, but
customers are responsible for patching their guest OS and applications.
Configuration Management – AWS maintains the configuration of its infrastructure devices, but a customer
is responsible for configuring their own guest operating systems, databases, and applications.
Awareness & Training - AWS trains AWS employees, but a customer must train their own employees.
Customer Specific – Controls which are solely the responsibility of the customer based on the application they
are deploying within AWS services. Examples include:
Service and Communications Protection or Zone Security which may require a customer to route or zone data within
specific security environments.
AWS Shared Responsibility Model
Responsibility of AWS Responsibility of a Customer
AWS manages all infrastructure Customers' responsibility is the
layers. security of everything they
make in AWS Cloud.
Some of the infrastructure Customers (you) have complete
layers are: control over your content.
Hardware and software Customer manages AWS
Virtualization services, software, and access to
Networking the data.
Data centers
The AWS shared responsibility model is a concept of dividing
responsibilities between AWS and a Customer.
AWS Customer (you)
Edge locations Networking traffic protection
Availability zones Server-side encryption
Regions Client-side data encryption
AWS global infrastructure Operating systems configuration
Hardware Network configuration
Networking Firewall configuration
Database Platform management
Storage Applications management
Software Access management
Compute Identity management
Customer data
AWS Key Management Service
AWS Key Management Service (AWS KMS) is an AWS managed service that makes it easy for you to create and control
the encryption keys that are used to encrypt your data.
The AWS KMS keys that you create in AWS KMS are protected by FIPS 140-2 (Federal Information Processing
Standard Publication) validated hardware security modules (HSM). They never leave AWS KMS unencrypted. To
use or manage your KMS keys, you interact with AWS KMS.
AWS Key Management Service
AWS Key Management Service (KMS) is a managed service provided by
Amazon Web Services (AWS) that allows companies to create, control
and manage the cryptographic keys that encrypt and protect their data.
Organizations can use the encryption keys and functionality provided by
AWS KMS to protect data in all their applications that use AWS.
The service can also generate data keys that can be used outside of
AWS KMS. Symmetric and asymmetric KMS keys can be generated
for encryption and signing using AWS KMS.
Additionally, you can create and manage key policies in AWS
KMS, ensuring that only trusted users have access to KMS keys.
AWS Key Management Service
AWS KMS allows organizations to better control who can use their AWS
KMS keys and who can access their encrypted data. The service allows
them to use its key management and cryptographic features directly in
their AWS applications or through AWS services integrated with AWS
KMS.
AWS KMS uses hardware security modules (HSM) to protect and validate
all its cryptographic keys under the FIPS 140-2 Cryptographic Module
Validation Program (CMVP). The CMVP is a joint effort between the
National Institute of Standards and Technology (NIST) and the Canadian
Centre for Cyber Security to promote the use of validated cryptographic
modules and provide
Federal agencies with a standardized way to procure equipment
AWS KMS pricing
As with other AWS products, using AWS KMS does not require contracts or minimum purchases.
Each AWS KMS key that you create in AWS KMS costs $1/month. The
$1/month charge is the same for symmetric keys, asymmetric keys,
HMAC keys, multi-Region keys.
For KMS keys that you rotate automatically or on demand, the first and second
rotation of the key adds $1/month (prorated hourly) in cost. This price increase is
capped at the second rotation, and any subsequent rotations will not be billed.
You are not charged for the following:
• Creation and storage of AWS managed or AWS owned KMS keys. These keys
are automatically created on your behalf when you first attempt to encrypt a resource
in an AWS service that integrates with AWS KMS. You can neither manage the lifecycle
nor access permissions on AWS managed keys.
• There is no charge for customer managed KMS keys that you manage and
are scheduled for deletion. If you cancel the deletion during the waiting period, the
customer managed KMS key will incur charges as though it was never scheduled for
deletion.
• There is no monthly charge for data keys or data key pairs that AWS KMS
generates beyond the charge for the API call.
What is a key in AWS KMS?
An AWS KMS key is a logical representation of a cryptographic key. It
is a primary resource in AWS KMS.
The following three types of KMS keys can be created in AWS KMS:
Customer managed key. Created by the organization.
AWS managed key. Created by AWS services that use KMS keys to
encrypt the organization's service resources.
AWS owned key. KMS keys created by AWS services in a service
account.
What is a key in AWS KMS?
A KMS key contains the following:
metadata (key ID, key spec, key usage, creation
date, description and key state); and
reference to the key material used when
cryptographic operations are performed with the
KMS key.
Operations of KMS Keys
KMS keys can be used for multiple cryptographic
operations, such as the following:
data encryption, decryption and re-encryption;
message signing and verification;
generating exportable symmetric data keys and
asymmetric data key pairs;
generating and verifying HMAC codes; and
generating random numbers suitable for cryptographic
applications.
AWS WAF (Web Application Firewall)
AWS WAF (Web Application Firewall) is a firewall that helps
you to protect your web application server against a range of
Internet threats.
WAF monitors and controls unusual bot traffic, and blocks
common attack patterns, such as SQL Injection or Cross-site
scripting, etc.
It also lets you monitor the HTTP and HTTPS requests that
are forwarded to an Amazon API Gateway API, Amazon
CloudFront, or an Application Load Balancer.
Amazon WAF
Amazon WAF allows you to control your content by using an
IP address from where the request originates.
Three things make Amazon WAF work – Access control lists
(ACL), Rules, and Rule Groups.
Amazon WAF manages Web ACL capacity units (WCU) for
rules, rule groups, and web ACLs.
Amazon WAF includes a full-featured API that you can use to
automate the creation, deployment, and maintenance of
security rules.
Common Web Attacks
Common Web Attacks
DDoS(Denial-Of-Service) attacks: This is probably the most common attack.
Attackers overload an application by sending bulk requests to the web servers.
Thousands of hosts infected with malware are used in this attack, which utilizes
more than one unique IP address or machine. This slows down the application and
significantly hurt the value of a brand.
SQL injections: SQL injection is a code injection procedure that might destroy
your SQL database. Attackers can run malicious SQL queries on your web
applications.
Cross-Site Scripting: If your application is vulnerable to cross-site scripting, then
the attacker can run or inject malicious scripts, generally in the form of a browser-
side script. These scripts can even rewrite the content of the HTML pages.
AWS WAF Features
Protection Against Web Attacks: With minimum latency impact on incoming
traffic, WAF AWS offers many rules to inspect any element of a web request. WAF
AWS protects web applications against threats by filtering traffic according to the
rules created.
Establish Rules Accordingly: WAF AWS is a versatile and valuable tool for
protecting the infrastructures of applications. And this is because it allows users to
establish rules according to their needs and vulnerabilities that they wish to stop.
Web traffic filtering: WAF allows users to create rules to filter web traffic. It filters
IP addresses, HTTP headers, HTTP bodies, or URI strings from a web request.
Flexible Integration With AWS Services: AWS Firewall offers easy integration
with other AWS services like Amazon EC2, CloudFront, Load balancer, etc.
Monitor Rules: Web Application Firewall AWS allows us to create rules and review
and customize them to prevent unknown attracts.
How AWS WAF works
Use AWS WAF to control how your protected resources respond to HTTP(S) web requests. You
do this by defining a web access control list (ACL) and then associating it with one or more web
application resources that you want to protect.
The associated resources forward incoming requests to AWS WAF for inspection by the web
ACL.
In your web ACL, you create rules to define traffic patterns to look for in requests and to
specify the actions to take on matching requests. The action choices include the following:
• Allow the requests to go to the protected resource for processing and
response.
• Block the requests.
• Count the requests.
• Run CAPTCHA or challenge checks against requests to verify human
users and standard browser use.
AWS WAF components
The following are the central components of AWS WAF:
Web ACLs – You use a web access control list (ACL) to protect a set of AWS resources. You create a web
ACL and define its protection strategy by adding rules. Rules define criteria for inspecting web requests and
they specify the action to take on requests that match their criteria.
A web ACL is an AWS WAF resource.
Rules – Each rule contains a statement that defines the inspection criteria, and an action to take if a web
request meets the criteria. When a web request meets the criteria, that's a match. You can configure rules to
block matching requests, allow them through, count them, or run bot controls against them that use
CAPTCHA puzzles or silent client browser challenges.
Rule groups – You can define rules directly inside a web ACL or in reusable rule groups.
Web ACL capacity units (WCUs) – AWS WAF uses WCUs to calculate and control the operating
resources that are required to run your rules, rule groups, and web ACLs.
AWS Shield
Protection against Distributed Denial of Service (DDoS) attacks is of primary importance for
your internet-facing applications. When you build your application on AWS, you can make
use of protections that AWS provides at no additional cost.
Additionally, you can use the AWS Shield Advanced managed threat protection service to
improve your security posture with additional DDoS detection, mitigation, and response
capabilities.
AWS is committed to providing you with the tools, best practices, and services to help
ensure high availability, security, and resiliency in your defense against bad actors on
the internet.
When you build your application on AWS, you receive automatic protection by AWS
against common DDoS attack vectors, like UDP reflection attacks and TCP SYN floods.
You can leverage these protections to ensure the availability of the applications that you
run on AWS by designing and configuring your architecture for DDoS resiliency.
Security is a shared responsibility between AWS and the customers.
AWS Shield
AWS Shield is a managed AWS Cloud service for DDoS
protection against all known infrastructure (layer 3
and 4) attacks.
AWS Shield is available at two different tiers:
AWS Shield Standard
AWS Shield Advanced,
AWS Shield Advanced has a lot more power and
protection on offer than the Standard version.
AWS Shield
AWS Shield Standard
AWS Shield Standard is free, and it offers DDoS protection against some of the
more common layer 3, the network layer, and layer 4, the transport layer, DDoS
attacks. This protection is applied automatically and transparently to your Elastic
Load Balancers, Amazon CloudFront distributions, and Amazon Route 53.
AWS Shield Advanced
This paid service provides additional DDoS mitigation capability, intelligent attack
detection, and mitigation against attacks at the application (AWS WAF included)
and network layers.
Shield Advanced also provides additional detection and mitigation against large
and sophisticated DDoS attacks and near real-time visibility into attacks
Difference between AWS WAF and AWS Shield
AWS Security Best Practices
• Objective of AWS Security Best Practices
• AWS Security Best Practices Documentation offers guidelines to build secure and
resilient environments on AWS.
• Helps organizations protect data, manage access control, monitor activities, and
ensure compliance.
• Core Pillars of AWS Security
• Identity and Access Management (IAM): Control who can access what.
• Infrastructure Protection: Secure networks, host environments, and maintain
control over traffic.
• Data Protection: Encrypt data at rest and in transit to protect against unauthorized
access.
• Logging and Monitoring: Track user actions and system events for auditing and
compliance.
• Compliance and Frameworks
• AWS aligns with global security standards, such as ISO 27001, SOC(Security
Operations Center) and HIPAA (Health Insurance Portability and Accountability Act)
helping businesses maintain regulatory compliance.
CONT,
Identity and Access Management (IAM) Best Practices
• Principle of Least Privilege
• Define fine-grained permissions to ensure that users and applications only have the permissions needed
for specific tasks.
• Regularly review and remove unnecessary permissions to reduce risk.
• Enable Multi-Factor Authentication (MFA)
• Enforce MFA on all IAM users, especially root accounts, to add an extra layer of security.
• Use hardware MFA devices for high-sensitivity accounts, such as root or critical user roles.
• IAM Roles and Temporary Credentials
• Use IAM roles instead of creating IAM users for applications and services. Assign roles to resources to avoid
sharing credentials.
• Implement AWS STS (Security Token Service) to grant temporary, time-limited access, reducing the
risk of credential compromise.
• Best Practice Policies
• Use AWS-managed policies as a baseline for permissions but create custom policies for specific needs.
• Regularly review policies and use tools like IAM Access Analyzer to ensure policies do not allow overly
permissive access.
CONT,
Data Protection and Monitoring Best Practices
Data Encryption
Encrypt sensitive data in transit and at rest using AWS KMS (Key Management Service).
Enable Server-Side Encryption (SSE) for data stored in services like Amazon S3 and RDS databases.
For advanced security, use Customer Managed Keys (CMK) in AWS KMS, providing you more control
over key rotation and permissions.
Automated Data Backup and Recovery
Set up automated backups using services like AWS Backup and enable versioning for Amazon S3 to
safeguard data against accidental deletion.
Use cross-region replication for disaster recovery to ensure data availability even in the event of a
regional outage.
Incident Response Preparedness
Implement incident response processes, leveraging AWS tools like AWS CloudFormation to
automate incident recovery.
Regularly test security configurations and run simulations to ensure rapid recovery and minimize
impact in case of a breach.