AWS Security Blog

Two New Documents to Help You Navigate Australian Prudential Regulation Authority (APRA) Requirements

AWS has published two new documents to help Financial Services customers understand how to operate in the cloud within the requirements of the Australian Prudential Regulation Authority (APRA). These documents continue AWS’s efforts to help customers navigate Australian regulatory requirements in a shared responsibility environment. The two new APRA-related documents are: AWS User Guide to […]

Read More

The Top 20 Most Viewed AWS IAM Documentation Pages in 2017

The following 20 pages were the most viewed AWS Identity and Access Management (IAM) documentation pages in 2017. I have included a brief description with each link to explain what each page covers. Use this list to see what other AWS customers have been viewing and perhaps to pique your own interest in a topic you’ve […]

Read More

The Top 10 Most Downloaded AWS Security and Compliance Documents in 2017

The following list includes the ten most downloaded AWS security and compliance documents in 2017. Using this list, you can learn about what other AWS customers found most interesting about security and compliance last year. AWS Security Best Practices – This guide is intended for customers who are designing the security infrastructure and configuration for applications […]

Read More

How to Encrypt Amazon S3 Objects with the AWS SDK for Ruby

Recently, Amazon announced some new Amazon S3 encryption and security features. The AWS Blog post showed how to use the Amazon S3 console to take advantage of these new features. However, if you have a large number of Amazon S3 buckets, using the console to implement these features could take hours, if not days. As […]

Read More

AWS Updated Its ISO Certifications and Now Has 67 Services Under ISO Compliance

AWS has updated its certifications against ISO 9001, ISO 27001, ISO 27017, and ISO 27018 standards, bringing the total to 67 services now under ISO compliance. We added the following 29 services this cycle: • Amazon Aurora • Amazon S3 Transfer Acceleration • AWS Lambda@Edge • Amazon Cloud Directory • Amazon SageMaker • AWS Managed […]

Read More

How to Set Up Continuous Golden AMI Vulnerability Assessments with Amazon Inspector

As companies mature in their cloud journey, they implement layered security capabilities and practices in their cloud architectures. One such practice is to continually assess golden Amazon Machine Images (AMIs) for security vulnerabilities. AMIs provide the information required to launch an Amazon EC2 instance, which is a virtual server in the AWS Cloud. A golden […]

Read More

AWS Organizations Now Supports Self-Service Removal of Accounts from an Organization

Today, AWS Organizations made it easier for you to remove AWS accounts from an organization. You can remove accounts from an organization without requiring assistance from AWS Support, and the accounts you remove can operate as standalone accounts or be invited to join another organization. For example, you could remove graduating students’ AWS accounts from […]

Read More

Videos and Slide Decks from the AWS re:Invent 2017 Security, Compliance, & Identity Track

Whether you want to review a Security, Compliance, & Identity track session you attended at AWS re:Invent 2017, or you want to experience a session for the first time, videos and slide decks from the Security, Compliance, & Identity track are now available. Introductory SID201: IAM for Enterprises: How Vanguard Strikes the Balance Between Agility, Governance, […]

Read More

How to Enhance the Security of Sensitive Customer Data by Using Amazon CloudFront Field-Level Encryption

Amazon CloudFront is a web service that speeds up distribution of your static and dynamic web content to end users through a worldwide network of edge locations. CloudFront provides a number of benefits and capabilities that can help you secure your applications and content while meeting compliance requirements. For example, you can configure CloudFront to […]

Read More