Before building, you must understand the rules of the road
1. Foundational Rules
Acceptable Use Policy (AUP): The “house rules” you agree to when creating an AWS account. For example, you cannot run malicious attacks or perform penetration testing on certain services without prior AWS permission.
Least Privilege Access: The golden rule of security. Only give users or systems the exact permissions they need to do their job, and nothing more. (e.g., Don’t give a developer “Admin” access if they only need to read files from an S3 bucket).
2. The Shared Responsibility Model
Security in the cloud is a team effort.
AWS is responsible for “Security OF the Cloud”: Protecting the physical data centers, hardware, network infrastructure, and the hypervisor that runs virtual machines.
You (the Customer) are responsible for “Security IN the Cloud”: Encrypting your data, managing user passwords (IAM), configuring firewalls (Security Groups), patching your operating systems (if using EC2), and writing secure code.
3. The AWS Well-Architected Framework (6 Pillars)
A checklist of best practices for building great cloud systems:
Operational Excellence: Running and monitoring systems to deliver business value (e.g., automating deployments).
Security: Protecting information and assets (e.g., using encryption and least privilege).
Reliability: The system’s ability to recover from disruptions (High Availability & Fault Tolerance).
Performance Efficiency: Using computing resources efficiently to meet requirements (e.g., choosing the right instance type).
Cost Optimization: Avoiding unnecessary costs (e.g., deleting unused resources).
Sustainability: Minimizing the environmental impact of your cloud workloads (e.g., using energy-efficient hardware).
4. High Availability (HA) vs. Fault Tolerance (FT)
High Availability (HA): The system stays up and running during a failure, though users might experience a brief hiccup. (Analogy: A car with a spare tire. You can fix it and keep driving). Achieved in AWS by using Multiple Availability Zones (AZs).
Fault Tolerance (FT): The system continues to operate perfectly without any interruption even if a component fails. (Analogy: An airplane with multiple engines; if one fails, the others seamlessly take over). Achieved using services like Amazon SQS or Route 53.
5. Compliance
AWS complies with strict global standards (PCI DSS for credit cards, HIPAA for healthcare, SOC 1/2/3, FedRAMP for US Gov).
AWS Artifact: Your self-service portal to download AWS compliance reports (e.g., “Give me the PCI DSS report for my bank auditors”).
AWS Config: Checks if your resources comply with your internal rules (e.g., “Alert me if an S3 bucket is public”).
Amazon GuardDuty: Intelligent threat detection that monitors for malicious activity.
Scenario Spotlight
A bank needs the official PCI DSS compliance report for AWS. ➔ AWS Artifact.
You want to know who is responsible for encrypting your database? ➔ You (Customer), per the Shared Responsibility Model.
What framework should you review to ensure your new app follows AWS best practices? ➔ AWS Well-Architected Framework