Aws Security
Aws Security
System Hardening
System Hardening
Patch Management
Regularly update the operating system, applications, and firmware with security
patches to address known vulnerabilities.
Firewall Configuration
Configure firewalls to filter inbound and outbound traffic, allowing only essential
communication.
Data Encryption
Encrypt sensitive data at rest and in transit to protect it from unauthorized access.
Patch Manager
Patch Manager
▪ You can use Patch Manager to apply patches for both operating
systems and applications.
Patch Manager
▪ Patch Manager uses patch baselines, which include rules for auto-
approving patches within days of their release, in addition to a list of
approved and rejected patches.
Network
Hardening
Network Hardening
Firewall Configuration
Network Segmentation
Access Control
▪
Encryption
Amazon Inspector
Amazon Inspector
▪ Amazon Inspector: Automated service for assessing
AWS app security and compliance.
▪ Function: Scans for exposure, vulnerabilities, and best
practice deviations.
▪ Results: Provides prioritized security findings by
severity.
▪ EC2 Focus: Checks network accessibility and security
state of EC2 instances.
Amazon Inspector
Benefits
AWS Network
Firewall
Managed Service
Traffic Control
Flexible Rules
Scalability
Stateful Rules
Stateful Rules
▪ Granular Control: Can inspect both the initial request and any
related responses, providing more detailed control over multi-
packet flows.
Stateful Rules
Stateless Rules
Stateless Rules
▪ Stateless rules are simpler, faster, and are typically used for
straightforward allow/deny actions without tracking connection
states.
Combining Stateless
and Stateful
Combining Stateless and Stateful