AWS Identity and Access Management

AWS IAM
(Identity and Access Management)
Control access to AWS services and resources. You can create users, groups, roles, and policies.

AWS IAM Identity Center
(formerly AWS SSO)
Centralized identity for managing access across multiple AWS accounts or apps.

AWS Organizations
Manage permissions and billing across multiple AWS accounts.
|
Threat Detection and Monitoring

Amazon GuardDuty
Amazon GuardDuty is an intelligent threat detection service that continuously monitors AWS accounts and workloads for malicious activity.

AWS CloudTrail
AWS CloudTrail provides comprehensive logging of all API actions across your AWS environment.

Amazon CloudWatch
Amazon CloudWatch is AWS's comprehensive monitoring solution that provides real-time insights into your cloud resources and applications.

AWS Security Hub
AWS Security Hub centralizes security findings across AWS accounts and services.
|
Vulnerability and Data Protection

Amazon Inspector
Amazon Inspector is an automated security assessment service that helps improve the security and compliance of applications deployed on AWS.

Amazon Macie
Finds and safeguards sensitive data, such as PII, in S3 buckets using machine learning.

AWS Certificate Manager
AWS Certificate Manager (ACM) simplifies SSL/TLS certificate management by handling provisioning, renewal, and deployment automatically.
|
Network and Application Protection

AWS WAF (Web Application Firewall)
AWS WAF protects web applications from common exploits by allowing you to create security rules that control bot traffic and block attacks like SQL injection and XSS.

AWS Shield
AWS Shield provides DDoS protection for AWS applications.

Amazon Route 53
Amazon Route 53 is AWS's scalable DNS service that routes users to web applications with high reliability.
|
Data Encryption and Key Management

AWS KMS (Key Management Service)
AWS KMS (Key Management Service) is a managed service that makes it easy to create and control cryptographic keys used to protect your data.

AWS CloudHSM
AWS CloudHSM provides dedicated hardware security modules (HSMs) in the AWS cloud.

AWS RDS
AWS RDS (Amazon Relational Database Service) is a fully managed service that makes it easy to set up, operate, and scale relational databases in the cloud. Not related to Data Encryption and Key Management
|
MSSP Integration & Partner Services

Security Hub integrations
AWS WAF protects web applications from common exploits by allowing you to create security rules that control bot traffic and block attacks like SQL injection and XSS. It integrates seamlessly with CloudFront, ALB, and API Gateway for comprehensive application security.

Third-party tools on AWS Marketplace
For instance, Palo Alto, Splunk, Trend Micro, CrowdStrike, and so on.

MSSP partner programs
MSSPs with expertise in monitoring, detection, compliance, and incident response have been screened by AWS.
|