Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AWS cloud security is a shared set of controls: AWS secures the infrastructure that runs its services, while customers secure their use of those services. The customer’s exact responsibilities depend on the service and include areas such as identities, data, permissions, configurations, and—where customers manage them—guest operating systems and applications. A secure AWS environment therefore requires more than enabling one security product: it combines identity controls, monitoring, vulnerability management, infrastructure and application protection, data protection, and incident response.

How the AWS shared responsibility model works

AWS describes the division as “security of the cloud” and “security in the cloud.” AWS is responsible for protecting the hardware, software, networking, and facilities that run AWS cloud services. Customers are responsible for securing their use of those services. As AWS’s Well-Architected Security Pillar puts it, “Customer responsibility will be determined by the AWS Cloud services that a customer selects.”

Service example AWS responsibilities Customer responsibilities
Amazon EC2 Underlying cloud infrastructure Guest operating system, its updates and security patches, installed applications or utilities, security-group configuration, and customer data and permissions
Amazon S3 or Amazon DynamoDB Underlying infrastructure, operating system, and platform Data, data classification, permission policies, and encryption choices

This is a service-boundary comparison, not a claim that every workload has identical duties. Integrations, organizational requirements, data sensitivity, and applicable law can add customer obligations. Check the current AWS guidance for each service in use.

Core capabilities in an AWS security program

AWS’s Security Reference Architecture organizes security around capabilities rather than around a single product. Those capabilities align with the AWS Cloud Adoption Framework, AWS Well-Architected, and the Shared Responsibility Model.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration
  • Governance and assurance: establish security expectations, assign ownership, and evaluate whether controls meet organizational and compliance requirements.
  • Identity and access management: control who or what can access AWS resources and which actions they can take.
  • Threat detection: identify suspicious activity and support investigation.
  • Vulnerability management: identify, classify, remediate, or mitigate weaknesses in systems and applications.
  • Infrastructure protection: control access to networks and resources and protect workloads.
  • Data protection: manage data access, encryption, and sensitive-data handling.
  • Application security: protect applications and their traffic as part of the workload’s design and operation.
  • Incident response: prepare to investigate and respond to security events.

The capabilities work together: for example, access controls limit exposure, logging supplies evidence for investigation, and response processes turn findings into action. The precise design depends on the workload and its risk.

Baseline practices for AWS accounts and workloads

Control identities and permissions

  • Protect account credentials and use individual identities rather than sharing credentials among people.
  • Grant each identity only the permissions required for its duties, and review access as responsibilities change.
  • Use multi-factor authentication (MFA).

AWS IAM and IAM Identity Center are examples of services used for identity and permissions; their availability in a design does not replace the need to configure access deliberately.

Rank #2
Wintertion1U/Desktop/Rackmount Firewall Hardware,OPNsense, VPN, Network Security Appliance, Router PCN2600 D2700, 4 x Gigabit LAN, COM, VGA, Fan, 0 RAM, 0 Storage (Desktop Type, 4G RAM 64G SSD)
  • equipped with atom n2600 d2700 processor, compatible with many freebsd based router systems, linux distros, or win.os supported, easy configuration and management
  • Please note, this is a barebone only. A system memory, a storage drive and an operating system are needed to complete this system
  • 13-19 inches 1u, 50w power, with power cord, make sure to use a big brand memory and ssd/hdd with quality assurance
  • Designed with console, 2 x usb, 4 x lan, vga, power switch, size at 290 x 180 x 44mm
  • There are 2 inside reserved fans on chassis, which could be removed freely or be turned on in a high temperature environment to ensure the best function of the product

Keep an audit trail and monitor activity

Use AWS CloudTrail to log API activity and user activity. Logging provides a record that can support monitoring and incident investigation; teams still need to decide how they review and act on relevant activity. Amazon GuardDuty is an example of a threat-detection service, while Amazon Detective is an example of a service for investigation.

Protect data and communications

  • Use encryption solutions appropriate to the data and workload, and make deliberate choices about encryption keys.
  • Use TLS to protect communications in transit. AWS Security Hub’s data-protection guidance says TLS 1.2 is required and TLS 1.3 is recommended; treat that wording as the guidance of that page, not as a universal statement about every service or endpoint.
  • Do not put confidential or sensitive details in resource tags, names, or other free-form fields. Such values may appear in billing or diagnostic logs.

AWS Key Management Service (KMS) and AWS CloudHSM are examples of cryptographic key-management services. Amazon Macie is an example of a service for discovering sensitive data, including data stored in S3.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

Review network exposure

For Amazon VPC, security groups control traffic to resources, while network access control lists (network ACLs) control traffic at the subnet level. Review whether VPCs and subnets are publicly accessible when they do not need to be, and protect traffic in transit. The right rules depend on the workload; the presence of a security group or network ACL alone does not establish that a configuration is secure.

Security services and the jobs they support

AWS’s security catalog includes services that support different parts of a security program. The examples below are not an exhaustive catalog or a recommended architecture; service capabilities, names, availability, and configuration options can change.

Rank #4
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Security job AWS examples Role in the program
Identity and permissions AWS IAM; IAM Identity Center Manage identities and access permissions
Threat detection and investigation Amazon GuardDuty; Amazon Detective Support detection and investigation
Security posture and findings AWS Security Hub Aggregate findings and support posture visibility
Vulnerability assessment Amazon Inspector Assess vulnerabilities
Sensitive-data discovery Amazon Macie Discover sensitive data, including in S3
Cryptographic key management AWS KMS; AWS CloudHSM Support cryptographic key management
Traffic protection AWS WAF; AWS Shield; AWS Network Firewall Support protection of applications, networks, or traffic
Audit trail AWS CloudTrail Log API and user activity

No one service in this list is a complete security program. Services need to be selected, configured, monitored, and integrated with the organization’s processes and workload requirements.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Vulnerability management and patching: who acts?

“AWS handles security” is too broad to answer who patches a particular component. AWS manages and patches its underlying infrastructure. Customers patch guest operating systems and applications they install and manage, such as on EC2. For more managed services, the division can vary: AWS may identify and release service patches while customers review updates and schedule maintenance or restarts; some multi-tenant services may be patched by AWS without customer action.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Identify the service and the layer in question: infrastructure, guest OS, managed platform, or customer-installed application.
  2. Check that service’s current patching and maintenance documentation to determine whether AWS, the customer, or both have an action.
  3. For customer-managed layers, assign responsibility for assessing updates, applying patches, and validating the workload after maintenance.

Vulnerability management is the continuing work of finding weaknesses, classifying their significance, and remediating or mitigating them. The word “vulnerabilities” does not mean every AWS service has the same exposure. The reviewed official material does not establish a specific current exploit, CVE, or named vulnerability affecting AWS as a whole, so this overview does not claim one.

Sources for service-specific decisions

For the current boundary and maintenance expectations, consult the AWS Well-Architected Security Pillar and the documentation for the particular service. AWS Prescriptive Guidance’s Security Reference Architecture describes the security capability model, while AWS Security Hub data-protection guidance covers baseline recommendations including TLS. AWS documentation for managing security responsibilities for Amazon VPC covers VPC traffic controls, encryption in transit, and public-access considerations.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.