What should be in your AWS Security Account? (Part 2)

What should be in your AWS Security Account? (Part 2)

This article will be a brief intro to AWS Security Hub.



What is it?

AWS Security Hub is a comprehensive security service that provides centralised visibility (as a dashboard) into your AWS security and helps you identify and remediate security issues across all of your AWS accounts.


What is included?

You'll see information from the following services:

  • Macie
  • GuardDuty
  • Inspector
  • Config
  • IAM Access Analyser
  • Systems Manager
  • AWS Health
  • AWS Firewall Manager


For Security Hub to work you must enable AWS Config.


You can generate EventBridge actions based on the findings in your dashboard and also investigate the findings via Inspector.


Pricing

Security Checks:

Ingestion:

Finding ingestions include both new findings and updates to existing findings.

You are not charged for finding ingestion events associated with Security Hub security checks.?


Automation Rules:

Security Hub automation rules allow you to automatically update or suppress findings in near-real time. You can automatically update various fields in findings, suppress findings, update finding severity and workflow status, add notes, and more. You can set criteria such as finding title or severity to make sure rules act only on relevant findings. This feature is priced by the quantity of automation rule evaluations per month.


To get started you need to set which set of standard rules you want the checks to adhere to. Select as many options as are appropriate to your business:

  • AWS Foundational Best Practices
  • CIS AWS Foundation Benchmark
  • PCI DSS

要查看或添加评论,请登录

Adam King的更多文章

  • Terraform and why you might think twice about CDK or Cloudformation.

    Terraform and why you might think twice about CDK or Cloudformation.

    Multi-Cloud Go try using Cloudformation outside of AWS, go on, in the words of every school teacher "it's your own time…

  • Setting Up Multi-Region Active-Active with AWS Global Accelerator and Aurora Global Database

    Setting Up Multi-Region Active-Active with AWS Global Accelerator and Aurora Global Database

    Ever wondered how to make your app lightning-fast for users around the world while keeping it up and running even if a…

  • What AI services do AWS provide?

    What AI services do AWS provide?

    Firstly some clarity AI is what happens, LLM (large language model) is how. AI has rapidly become more prevalent over…

  • AWS Lambda Limits

    AWS Lambda Limits

    Lambda limits can be found on the service quota page Soft limits Concurrency When invoking Lambda a container is…

  • AWS Lambda Invocations

    AWS Lambda Invocations

    There are two types of invocation Synchronous With synchronous invocation, the request to execute an AWS Lambda…

  • What to do if you lose your EC2 Keys

    What to do if you lose your EC2 Keys

    Whilst many companies have moved onto containerised solutions, there are still a lot around relying on EC2. N.

  • How to connect Github to AWS.

    How to connect Github to AWS.

    Options: Create Access Keys under the root user and add them to the CI/CD as plain text. Option 1 but use Github…

  • The confusion of the DevOps Engineer role

    The confusion of the DevOps Engineer role

    Definition I like to summarise that as "feedback to the business and providing that in a repeated and optimal way". But…

    5 条评论
  • It's time to change.

    It's time to change.

    Let's see how much of this is familiar to the organisation that you are in or have been at in the not too distant past:…

    1 条评论
  • Thoughts on Mentoring

    Thoughts on Mentoring

    For the past few years, I've mentored those around me, with less experience; mostly through an unofficial capacity…

社区洞察

其他会员也浏览了