EC2 Security encompasses the controls needed to protect virtual machines running in AWS. EC2 instances are a top target because they often hold application code, data, and credentials.
0.0.0.0/0 on SSH (port 22) or RDP (port 3389)A virtual firewall for EC2 instances and other resources that controls inbound and outbound traffic at the instance level using allow rules.
An AWS identity with temporary credentials that can be assumed by users, services, or applications to perform actions without long-term access keys.
Protecting stored data by encrypting it on disk so that it cannot be read without the encryption key, even if the storage media is compromised.
Dividing a network into isolated segments (subnets, VPCs) to limit lateral movement and contain the blast radius of a security breach.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.