A Network Access Control List (NACL) is a subnet-level firewall in a VPC. Unlike security groups, NACLs are stateless (you must create separate rules for inbound and outbound) and support both allow and deny rules.
Best practice: use security groups as the primary firewall and NACLs as an additional defense layer for subnet-level blocking.
A virtual firewall for EC2 instances and other resources that controls inbound and outbound traffic at the instance level using allow rules.
An isolated virtual network within AWS where you launch resources, with full control over IP addressing, subnets, route tables, and network gateways.
A security strategy using multiple layers of controls (network, identity, data, application) so that if one layer fails, others still protect the environment.
Dividing a network into isolated segments (subnets, VPCs) to limit lateral movement and contain the blast radius of a security breach.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.