AWS Well-Architected Security Pillar: the evidence behind every control
63 controls. For each, the artefacts auditors ask for, which ones a system already holds, and the first move to stop evidencing it by periodic review.
Security Foundations
SEC01-BP01Separate workloads using accounts hardSEC01-BP02Secure account root user and properties easySEC01-BP03Identify and validate control objectives hardSEC01-BP04Stay up to date with security threats and recommendations hardSEC01-BP05Reduce security management scope hardSEC01-BP06Automate deployment of standard security controls easySEC01-BP07Identify threats and prioritize mitigations using a threat model hardSEC01-BP08Evaluate and implement new security services and features regularly moderateIdentity & Access Management
SEC02-BP01Use strong sign-in mechanisms easySEC02-BP02Use temporary credentials moderateSEC02-BP03Store and use secrets securely moderateSEC02-BP04Rely on a centralized identity provider easySEC02-BP05Audit and rotate credentials periodically easySEC02-BP06Employ user groups and attributes hardSEC03-BP01Define access requirements hardSEC03-BP02Grant least privilege access hardSEC03-BP03Establish emergency access process moderateSEC03-BP04Reduce permissions continuously moderateSEC03-BP05Define permission guardrails for your organization hardSEC03-BP06Manage access based on lifecycle moderateSEC03-BP07Analyze public and cross-account access moderateSEC03-BP08Share resources securely within your organization hardSEC03-BP09Share resources securely with a third party hardDetection
SEC04-BP01Configure service and application logging easySEC04-BP02Capture logs, findings, and metrics in standardized locations moderateSEC04-BP03Correlate and enrich security alerts moderateSEC04-BP04Initiate remediation for non-compliant resources moderateInfrastructure Protection
SEC05-BP01Create network layers moderateSEC05-BP02Control traffic flow within your network layers moderateSEC05-BP03Implement inspection-based protection moderateSEC05-BP04Automate network protection easySEC06-BP01Perform vulnerability management easySEC06-BP02Provision compute from hardened images hardSEC06-BP03Reduce manual management and interactive access easySEC06-BP04Validate software integrity hardSEC06-BP05Automate compute protection easyData Protection
SEC07-BP01Understand your data classification scheme hardSEC07-BP02Apply data protection controls based on data sensitivity hardSEC07-BP03Automate identification and classification easySEC07-BP04Define scalable data lifecycle management hardSEC08-BP01Implement secure key management moderateSEC08-BP02Enforce encryption at rest hardSEC08-BP03Automate data at rest protection moderateSEC08-BP04Enforce access control moderateSEC09-BP01Implement secure key and certificate management easySEC09-BP02Enforce encryption in transit moderateSEC09-BP03Authenticate network communications easyIncident Response
SEC10-BP01Identify key personnel and external resources hardSEC10-BP02Develop incident management plans hardSEC10-BP03Prepare forensic capabilities hardSEC10-BP04Develop and test security incident response playbooks moderateSEC10-BP05Pre-provision access hardSEC10-BP06Pre-deploy tools hardSEC10-BP07Run simulations hardSEC10-BP08Establish a framework for learning from incidents hardApplication Security
SEC11-BP01Train for application security hardSEC11-BP02Automate testing throughout the development and release lifecycle moderateSEC11-BP03Perform regular penetration testing hardSEC11-BP04Conduct code reviews hardSEC11-BP05Centralize services for packages and dependencies hardSEC11-BP06Deploy software programmatically easySEC11-BP07Regularly assess security properties of the pipelines moderateSEC11-BP08Build a program that embeds security ownership in workload teams moderate