Overview
The Security Built-in Cloud service integrates configuration management and vulnerability management for cloud environments, providing an environment in which IT infrastructure provisioning and security operations are built in from the start.
This professional service is provided in relation to the AWS services used in each customer's environment, such as Amazon Inspector, AWS Security Hub, and AWS Systems Manager.
The benefits of this service and the capabilities delivered to customers are as follows.
Benefits (Value Delivered):
-
Reduced workload and greater visibility through integrated infrastructure capabilities — Capabilities that strengthen operational resilience are delivered as an integral part of the cloud platform. Tasks that were previously manual—such as collecting system configuration information and continuously scanning for hard-to-spot vulnerabilities—are automated, significantly reducing the effort for IT asset management and audit response while improving visibility.
-
Efficient vulnerability response through risk prioritization — Every day, a large number of new vulnerabilities are disclosed publicly. For these vulnerabilities, SSVC (stakeholder-specific prioritization) reports are provided, enabling efficient decisions on whether and how to respond.
-
Reduced burden through automated patching and non-regression testing — The service provides mechanisms that lower the effort of applying patches and performing post-patch non-regression (impact verification) testing. In addition to a dedicated patch repository, it provides automation code (e.g., Ansible), procedure templates, and testing guidelines—eliminating the effort of obtaining patches and continuously improving both productivity and security quality.
-
Early-stage threat detection and advanced response support by a SOC — Logs collected from systems and networks are analyzed in real time with a SIEM, detecting early indicators and abnormal behavior before actual damage occurs. For containment and removal of cyberattacks and for implementing measures to prevent recurrence, response is carried out with the support of a dedicated SOC (Security Operation Center), achieving both operational efficiency and high quality.
-
Strategic prevention and process maturity — By taking a holistic view of the entire security operations process, the service strengthens the alignment of governance, system development, and security operations. By providing a foundation for security measures from the system planning and development stages, it contributes to the strategic prevention of threats.
Capabilities Delivered to Customers:
The service delivers capabilities along two main axes: Vulnerability Management and Threat Detection.
Vulnerability Management:
-
Configuration management: Automatically collects software and configuration information directly from servers, cloud environments, and containers, and manages it in a consolidated view. Collected information can be output as reports or as an SBOM (Software Bill of Materials).
-
Vulnerability alerts: Monitors whether configurations deviate from policy baselines (e.g., CIS Benchmarks) and raises alerts. It also runs daily scans against public vulnerability databases and notifies alerts together with priority.
-
Vulnerability ticket management and dashboard: Detected software vulnerabilities and configuration violations are logged as tickets, and their response status is managed and visualized on a dedicated vulnerability dashboard.
-
Patch application tools: Provides a local repository of patch modules, along with patch application and non-regression test procedure templates, automation code, and guidelines.
Threat Detection (Cyberattack Detection):
-
Event and log monitoring: Continuously collects various events and system logs from target systems.
-
Cyberattack alerts: Stores and analyzes the collected logs in a SIEM to detect early indicators of cyberattacks and notify them as alerts.
-
Cyberattack ticket management: Detected threats are managed as tickets; users can track ticket status and, with the provider's support, perform investigation on the actual systems and implement countermeasures.
Highlights
- Automated, low-effort operations: integrated IT infrastructure and security functions automate configuration collection and continuous vulnerability scanning, greatly reducing manual management and audit effort. High-precision prioritization: a large volume of vulnerabilities is ranked using SSVC (prioritization based on each organization's environment), so teams focus on the risks that truly matter and respond efficiently.
- Reduced patch operations and testing burden: In addition to a dedicated patch repository, the service provides automation code and procedure templates for patch application and non-regression (impact verification) testing, greatly reducing the on-site effort required to respond.
- Early threat detection and SOC-backed response support: Through SIEM-based log analysis, cyberattacks are detected at the early-indicator stage, before actual damage occurs. With the support of a dedicated SOC, the service delivers high-quality response—from rapid containment through to recurrence prevention.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.