Blast Radius describes the potential impact of a security incident. A compromised IAM user with "Action": "*", "Resource": "*" has an unlimited blast radius - the attacker can do anything in the account. A Lambda function with read-only access to one DynamoDB table has a tiny blast radius.
The security principle of granting only the minimum permissions needed to perform a task - no more, no less.
Using multiple AWS accounts to isolate workloads, environments, and teams, providing the strongest security boundary available in AWS.
Dividing a network into isolated segments (subnets, VPCs) to limit lateral movement and contain the blast radius of a security breach.
The structured process of detecting, containing, eradicating, and recovering from a security incident, following frameworks like NIST SP 800-61.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.