Security in the AWS Well-Architected Framework
Security is one of the five pillars of the AWS Well-Architected Framework. The framework describes the principles and techniques required to make informed trade-offs when you’re building in the AWS Cloud.
I’ve taught thousands of builders how to build better using the framework on the A Cloud Guru platform. Be sure to check out my course, “Mastering The Well-Architected Framework”
This Twitter thread dives deeper into the Security pillar of the framework…
today, my personal favourite, the Security Pillar
☁️ #cloud #devops
…and yesterdays is up at https://markn.ca/2021/operational-excellence-in-the-aws-well-architected-framework/
☁️ #cloud #devops
it’s not an isolated activity but one that must be considers next to the other four pillars. you need to find a balance here…the framework helps
☁️ #cloud #devops
To make sure that your systems work as intended and ONLY as intended
☁️ #cloud #devops
that covers everything from attacks to mistakes. also, it’s more positive
☁️ #cloud #devops
besides, if you’re only ever trying to STOP things, you won’t see the other advantages, like building reslience
☁️ #cloud #devops
yawn
☁️ #cloud #devops
- identity & access
- detective controls
- infrastructure protection
- data protection
- incident response
☁️ #cloud #devops
-
identity & access == who can do what, when?
-
detective controls == is this normal?
-
infrastructure protection == boundaries & chokepoints
☁️ #cloud #devops
-
data protection == classification, management, & encryption
-
incident response == +fan, time to contain & restore
☁️ #cloud #devops
- identities have the least amount of privileges required
- know who did what, when
- security is a part of everything
- automate all tasks
- encrypt at rest & in transit
- prepare for the worst
☁️ #cloud #devops
there’s a lot more in that document and in the references. but, like anything in the framework, Gamedays and practice will help you understand these concepts the best
/ ☁️ #cloud #devops