What is DevSecOps?
is certainly about security, but it is just as much about the processes you use to build applications and helping to ensure security is built in to those processes by design
Temporary Credentials
Trusted user can:
Not always necessary
AWS security token service
Switching roles
allows practice of least-privilege principle
How to switch roles?
MFA
Multi-factor Authentication - requires users to enter a unique authentication code when accessing AWS website or service:
AWS IAM Policy Validator
Examines IAM policies for compliance with IAM policy grammar
runs automatically when policy is created or updated
checks only JSON policy syntax and grammar
if it policy validation fails, it will not allow you
AWS Config
safety can be added using AWS Config rules
AWS Secrets Manager
AWS Secrets Manager
AWS Systems Manager Parameter Store
What are Secure String parameters?
Secure
The Security Perspective of the Cloud Adoption Framework
Directive
Preventive
Detective
Responsive
The Security Perspective of the Cloud Adoption Framework
Directive
Preventive
Detective
Responsive
Security of the Pipeline
focus on
Threat detection tools
AWS Guard Duty
AWS Security Hub
Amazon Inspector
AWS Security Hub
Centrally manage and aggregate security alerts and compliance status across your AWS accounts, like Amazon GuardDuty, Amazon inspector, Amazon Macie and partner solutions. has a range of tools from firewalls and compliance scanners
Amazon Inspector
automated security assessment service that improves the security and compliance of applications deployed