Shared Responsibility Model
AWS is responsible for some parts of the environment (security of the cloud) and the customer is responsible for other parts (security in the cloud).
Customers (Security in the Cloud)
AWS (Security of the Cloud)
AWS Identity and Access Management (IAM)
Enables you to manage access to AWS services and resources securely.
IAM Users
IAM Policy
A document that allows or denies permissions to AWS services and resources.
IAM Group
A collection of IAM users.
IAM Role
AWS Organizations
Service Control Policies (SCPs)
Enable you to place restrictions on the AWS services, resources, and individual API actions that users and roles in each account can access.
AWS Artifact
A service that provides on-demand access to AWS security and compliance reports and select online agreements.
AWS Artifact Agreements
Agreements can be reviewed, accepted, and managed for an individual account or all accounts in AWS Organizations.
AWS Artifact Reports
Provide compliances reports from third-party auditors.
Customer Compliance Center
Contains resources to help you learn more about AWS compliance.
Denial-of-Service (DoS) Attack
A deliberate attempt to make a website or application unavailable to users.
Distributed Denial-of-Service (DDoS) Attack
AWS Shield
A service that protects applications against DDoS attacks.
AWS Shield Standard
- Protects AWS resources from the most common, frequently occurring types of DDoS attacks.
AWS Shield Advanced
AWS Key Management Service (AWS KMS)
Enables you to perform encryption operations through the use of cryptographic keys.
AWS WAF
Amazon Inspector
Amazon GuardDuty