Security & Compliance

IAM

AWS Identity and Access Management (IAM) allows you to securely manage access to AWS services and resources. You can use IAM to create and manage AWS users and groups, as well as utilize permissions to grant and deny them access to AWS resources. AWS Identity and Access Management (IAM) allows you to securely manage access to AWS services and resources. You can use IAM to create and manage AWS users and groups.

The core benefits are:

  • Fine-grained access control to AWS resources
  • Multi-factor authentication for highly privileged users
  • Analyze access
  • Integrate with your corporate directory

Resource Access Manager

AWS Resource Access Manager (RAM) is a tool that allows you to share AWS resources with any AWS account or inside your AWS Organization in an easy and secure manner. RAM may be used to share AWS Transit Gateways, Subnets, AWS License Manager settings, and Amazon Route 53 Resolver rules.

The core benefits are:

  • Reduce Operational Overhead
  • Improve Security and Visibility
  • Optimize Costs

Cognito

Amazon Cognito makes it simple to add user sign-up, sign-in, and access management to your online and mobile apps. Amazon Cognito enables sign-in with social identity providers such as Apple, Facebook, Google, and Amazon, as well as enterprise identity providers through SAML 2.0 and OpenID Connect.

Secrets Manager

AWS Secrets Manager assists you in safeguarding secrets required to access your apps, services, and IT resources. The service makes it simple to rotate, manage, and recover database credentials, API keys, and other secrets at any point in their lifespan. Secrets Manager APIs are used by users and programs to retrieve secrets, removing the need to hardcode sensitive information in plain text.

The core benefits are:

  • Rotate Secrets safely
  • Manage access with fine-grained policies
  • Secure and audit secrets centrally

AWS Single Sign-On

AWS Single Sign-On (SSO) enables you to centrally manage access to numerous AWS accounts and business apps, as well as offer users with single sign-on access to all of their allocated accounts and applications from a single location. With AWS SSO, you can centrally control access and user rights for all of your AWS Organizations accounts.

AWS SSO automatically configures and maintains the essential rights for your accounts, needing no additional configuration in the individual accounts.

The core benefits are:

  • Centrally manage access permission to AWS account
  • Create users in AWS SSO or connect to your existing identities
  • Access accounts and applications from one place

WAF & Shield

The Amazon Web Application Firewall (AWS WAF) is a web application firewall that allows you to monitor HTTP and HTTPS requests routed to an Amazon CloudFront distribution, an Amazon API Gateway REST API, an Application Load Balancer, or an AWS AppSync GraphQL API. AWS WAF also allows you to restrict who has access to your material. Depending on the constraints you provide, such as the IP addresses from which requests come or the values of query strings, Amazon CloudFront, Amazon API Gateway, Application Load Balancer, or AWS AppSync responds to requests either with the requested content or with an HTTP 403 status code (Forbidden).

AWS Firewall Manager

AWS Firewall Manager is a security management solution that enables you to centrally define and manage firewall rules across your AWS Organizations accounts and applications. As new apps are developed, Firewall Manager makes it simple to bring them into compliance by enforcing a standard set of security rules. You now have a single service for creating firewall rules.

The core benefits are:

  • Simplify management of firewall rules across your accounts
  • Ensure compliance of existing and new applications
  • Easily deploy managed rules across accounts
  • Centrally deploy protections for your VPCs