AWS Security Services
Organizations and SCPs, Artifact, Shield, WAF, KMS, Inspector, GuardDuty, Security Hub and Macie.
What is it?
Beyond IAM and network rules, AWS offers a toolbox of security services. Group them by the job they do.
Governance and compliance
- AWS Organizations: manage many accounts centrally with organizational units (OUs), consolidated billing, and service control policies (SCPs). SCPs set the maximum permissions accounts can have - they never grant access by themselves.
- AWS Artifact: self-service portal for AWS compliance reports and agreements.
- AWS Config / CloudTrail: configuration compliance and audit trail (see monitoring).
Protecting against attacks
- AWS Shield: DDoS protection. Standard is automatic and free for all customers; Advanced adds enhanced detection, response support, and cost protection for protected resources.
- AWS WAF: web application firewall that filters HTTP requests by rules (SQL injection, bad bots, rate limits) on CloudFront, ALB, API Gateway and more.
Protecting data
- AWS KMS (Key Management Service): create and control encryption keys. Encryption at rest protects stored data (S3, EBS, RDS); encryption in transit protects data moving over the network with TLS. Related: Secrets Manager and Parameter Store for secrets, CloudHSM for dedicated hardware modules.
- Amazon Macie: uses machine learning to discover sensitive data (like personal information) in S3.
Detecting threats and weaknesses
- Amazon Inspector: scans workloads such as EC2, containers and Lambda for software vulnerabilities and unintended exposure.
- Amazon GuardDuty: threat detection that analyses logs and network activity for suspicious behavior.
- AWS Security Hub: aggregates and prioritises findings from GuardDuty, Inspector, Macie and others in one place and checks against standards.
- Amazon Detective helps investigate the root cause of findings.
More security services
- AWS Secrets Manager: stores and automatically rotates secrets such as database passwords and API keys.
- AWS Certificate Manager (ACM): provisions, manages and renews public and private TLS certificates for services like CloudFront and load balancers.
- AWS CloudHSM: single-tenant hardware security modules you control, for strict key-control requirements.
- Amazon Cognito: sign-up, sign-in and access control for your web and mobile app users (customer identity), as opposed to IAM for your workforce.
- AWS Directory Service: managed Microsoft Active Directory in AWS, plus AD Connector and Simple AD options.
- AWS Network Firewall: managed stateful firewall and intrusion prevention for VPCs.
- AWS Firewall Manager: centrally configures WAF, Shield Advanced, Network Firewall and security groups across accounts in Organizations.
- AWS Resource Access Manager (RAM): shares resources such as subnets or Transit Gateways with other accounts without copying them.
- Amazon Detective builds a graph of related logs to find the root cause of a finding; AWS Security Hub collects findings; Amazon Macie finds sensitive data in S3; Amazon Inspector scans for vulnerabilities.
Security resources: AWS Trusted Advisor security checks, the AWS Knowledge Center, security blogs, whitepapers and AWS Marketplace security products, plus the Artifact portal for compliance reports.
Explain like I'm 10
Securing an account is like running a museum. Organizations and SCPs are the museum-wide rules no gallery manager can override. Shield and WAF are the barriers and bag checks at the entrance. KMS is the locksmith who keeps the keys to the vitrines. Inspector checks the locks and windows for weaknesses, GuardDuty is the camera system spotting odd behavior, Macie finds valuables left unlabeled on tables, and Security Hub is the control room with one screen of all alerts.
Examples
A service control policy (guardrail)
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenyOutsideApprovedRegions",
"Effect": "Deny",
"NotAction": ["iam:*", "organizations:*", "route53:*", "cloudfront:*", "support:*"],
"Resource": "*",
"Condition": {
"StringNotEquals": { "aws:RequestedRegion": ["eu-west-1", "eu-central-1"] }
}
},
{
"Sid": "ProtectCloudTrail",
"Effect": "Deny",
"Action": ["cloudtrail:StopLogging", "cloudtrail:DeleteTrail"],
"Resource": "*"
}
]
}Attached to an OU, this restricts every account in it to two Regions and prevents anyone, even admins, from switching off auditing.
Encrypt with KMS
KEY=$(aws kms create-key --description "app data key" --query KeyMetadata.KeyId --output text)
aws kms create-alias --alias-name alias/app-data --target-key-id "$KEY"
aws s3api put-bucket-encryption --bucket zykit-demo-bucket-12345 \
--server-side-encryption-configuration '{
"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"aws:kms","KMSMasterKeyID":"alias/app-data"}}]
}'Which service?
Question Service
---------------------------------------------------- ----------------
Where do I download AWS's SOC / ISO reports? Artifact
Stop a Region or service across 50 accounts? Organizations SCP
Block SQL injection on my website? WAF
Absorb a volumetric DDoS attack? Shield
Manage encryption keys? KMS
Find personal data stored in S3? Macie
Scan EC2 / images for known vulnerabilities? Inspector
Detect odd API calls or crypto-mining traffic? GuardDuty
See all findings in one dashboard? Security HubHow it works
SCP evaluation: an action is allowed only if the account's IAM permissions allow it and no SCP in the path from the organization root to the account blocks it. Envelope encryption in KMS: a KMS key encrypts a small data key, and the data key encrypts your data; services do this for you.
Detection services run continuously: GuardDuty reads CloudTrail, VPC flow logs and DNS logs; Inspector scans on events like new images; Macie samples S3 contents. Findings flow to Security Hub for triage and can trigger automated response through EventBridge and Lambda.
Organization root
|-- OU: Prod ----- SCPs (max permissions)
| '-- accounts
'-- OU: Dev
Edge: Shield + WAF --> CloudFront / ALB
Data: KMS keys --> S3 / EBS / RDS encryption
Detect: GuardDuty + Inspector + Macie --> Security Hub --> alertsWhy does it exist?
Attackers, mistakes and compliance requirements grow with scale. Central guardrails and automated detection let small teams protect many accounts consistently instead of relying on every engineer remembering everything.
When to use it
Use Organizations from the start for multi-account structure, encrypt by default with KMS, put WAF and Shield in front of public apps, and enable GuardDuty, Inspector, and Security Hub as baseline detection.
When not to use it
Do not use SCPs to grant permissions (they only restrict). Shield Advanced is overkill for low-risk internal apps. A WAF is not a substitute for fixing vulnerable code.
Common mistakes
Thinking an SCP gives users access.
Encrypting data but leaving key policies wide open.
Enabling detection services but never reading or routing findings.
Confusing Inspector (vulnerabilities in workloads), GuardDuty (threat detection), and Macie (sensitive data).
Assuming Shield Advanced is required to get basic DDoS protection.
Mixing up Cognito (your app's customers) with IAM Identity Center (your workforce).
Hard-coding database passwords instead of using Secrets Manager.
Practice exercises
- Easy:
Match each to its job: Artifact, KMS, WAF, Macie, GuardDuty, Inspector.
- Medium:
Write an SCP that prevents leaving the organization and explain why attaching it at an OU is safer than at each account.
- Medium:
Explain encryption at rest vs in transit with one AWS example each.
- Hard:
GuardDuty reports an EC2 instance contacting a known malicious IP. Outline a response: isolate, investigate with logs, rotate credentials, remediate.
Interview questions
What is an SCP?
A policy in AWS Organizations that sets the maximum available permissions for accounts in an OU or the organization; it does not grant permissions.
Shield Standard vs Advanced?
Standard is automatic and free for all customers against common network and transport layer attacks; Advanced offers extended protections, 24/7 response team access and cost protection for a fee.
What does KMS do?
Creates, stores and controls cryptographic keys used to encrypt data in AWS services and applications.
Exam-style: Which service finds sensitive data such as PII in S3?
Amazon Macie.
Exam-style: Where can a customer download AWS compliance reports?
AWS Artifact.
Exam-style: Which service rotates database credentials automatically?
AWS Secrets Manager.
Exam-style: Which service manages TLS certificates for a CloudFront distribution?
AWS Certificate Manager.
Exam-style: Which service enforces WAF rules across all accounts in an organization?
AWS Firewall Manager.