Search for Well Architected Advice
< All Topics
Print

Keep up-to-date with security recommendations

Staying up-to-date with both AWS and industry security recommendations is crucial for evolving the security posture of your workload. AWS Security Bulletins, as well as industry security advisories, provide essential information about security vulnerabilities, updates, and privacy notifications, helping ensure your environment remains secure and compliant.

  1. Monitor AWS Security Bulletins: Regularly check AWS Security Bulletins for important updates related to security and privacy. These bulletins can provide insights into vulnerabilities, patches, or configuration changes required to maintain a secure environment.
  2. Follow industry best practices: Stay informed about industry-wide security recommendations and standards, such as those from the National Institute of Standards and Technology (NIST), Center for Internet Security (CIS), or ISO standards. These guidelines help ensure your security measures are aligned with the latest best practices.
  3. Implement updates promptly: When new security recommendations or patches are released, ensure they are applied in a timely manner. Delayed implementation of security updates can expose your workload to unnecessary risk.
  4. Review AWS Well-Architected Framework: Regularly consult the AWS Well-Architected Framework’s Security Pillar to assess and improve your workload’s security. This framework provides best practices for building and maintaining secure, resilient cloud architectures.
  5. Automate updates and recommendations: Where possible, automate the process of applying security recommendations, patches, and updates to reduce the risk of human error and ensure timely implementation of the latest security measures.

Supporting Questions:

  • How often do you review AWS Security Bulletins for updates relevant to your workload?
  • What processes are in place to track and implement industry security best practices?
  • How do you ensure timely updates based on security recommendations from AWS and other industry sources?

Roles and Responsibilities:

Security Officer:

  • Responsibilities:
    • Monitor AWS Security Bulletins and industry security advisories regularly.
    • Ensure that industry security best practices are reviewed and adopted as appropriate.
    • Coordinate the timely implementation of security updates across the organization.

Cloud Administrator:

  • Responsibilities:
    • Apply security updates and recommendations promptly within the AWS environment.
    • Automate patching and updates to reduce manual efforts and improve security.
    • Use tools such as AWS Systems Manager to ensure compliance with security recommendations.

Artefacts:

  • AWS Security Bulletin Alerts: Notifications from AWS about security and privacy vulnerabilities and updates.
  • Security Update Logs: Records of when security patches and recommendations were implemented.
  • Compliance Reports: Documentation that demonstrates adherence to AWS and industry security standards and best practices.
Table of Contents