Glossary

    Security Baseline

    Compliance & Governance

    A Security Baseline is the minimum set of security controls that should be enabled in every AWS account, regardless of workload. It establishes the foundation for defense in depth.

    Essential Controls

    • CloudTrail: enabled in all regions, multi-account via Organizations trail
    • AWS Config: recording all supported resource types
    • GuardDuty: threat detection across all accounts
    • Security Hub: centralized findings with CIS/NIST benchmarks enabled
    • IAM Access Analyzer: detect external access to resources

    Account-Level Settings

    • Root Account: MFA enabled, no access keys, used only for billing/emergency
    • Default EBS Encryption: enabled in every region
    • S3 Block Public Access: enabled at the account level
    • IMDSv2: enforced as default for all new EC2 instances
    • Account-level S3 settings: disable ACLs, enable versioning for critical buckets

    Automation

    • Deploy via Control Tower guardrails or CloudFormation StackSets
    • Use Config Conformance Packs for continuous compliance verification

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.