Credential Compromise occurs when AWS credentials (access keys, secret keys, session tokens, console passwords) are exposed to unauthorized parties. This is the most common and dangerous AWS security incident.
A long-term credential pair (access key ID + secret access key) used to authenticate programmatic requests to AWS. Should be replaced with IAM roles wherever possible.
Short-lived AWS credentials (access key, secret key, session token) issued by STS that expire automatically, eliminating the risk of permanent credential exposure.
A security mechanism requiring two or more forms of verification (password + device/token) before granting access to an AWS account or resource.
The structured process of detecting, containing, eradicating, and recovering from a security incident, following frameworks like NIST SP 800-61.
A step-by-step documented procedure for handling specific security incidents - from detection through containment, eradication, recovery, and lessons learned.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.