Security and compliance on AWS
I review and fix access, network and encryption in your account against the Well-Architected security pillar: least privilege, a second factor, and nothing exposed that should not be.
Get a security assessmentThe quote comes out of the assessment.
01When it makes sense
- Users hold long-lived keys and administrator permissions.
- Nobody knows what is exposed to the internet.
- A customer or an audit asks you to show your controls.
02How the work goes
- 01
Assess
Access, network and encryption against the Well-Architected security pillar. Out comes a prioritised list.
- 02
Access
IAM Identity Center with MFA, and permissions cut back to what each person uses.
- 03
Network and data
Security groups, AWS WAF, and encryption at rest and in transit.
- 04
Handoff
Controls documented and alerts in place.
03What is included
- IAM Identity Center and least privilege.
- Security groups and AWS WAF.
- Encryption with AWS KMS and TLS.
- AWS CloudTrail and activity alerts.
What is not
- Certifying compliance. I leave the controls and the evidence; certification comes from an auditor.
04Records
An account where access and spend were the same problem, and an event with a firewall filtering attacks.
05Questions
- Will you certify us for SOC 2 or ISO 27001?
- No. I implement the controls and leave the evidence; certification comes from an auditor.
- Will anyone lose access?
- It can happen: cutting permissions is noticed. That is why it is done in stages, with a channel to ask for what is missing.
- How much does it cost?
- It comes out of the assessment: with the inventory I put together a quote, and you approve it before anything starts. What AWS bills is pay-per-use and goes straight to AWS.
Tell me what you have today and I will reply, almost always within 24 hours.
Get a security assessment