A Security Baseline is the minimum set of security controls that should be enabled in every AWS account, regardless of workload. It establishes the foundation for defense in depth.
A security strategy using multiple layers of controls (network, identity, data, application) so that if one layer fails, others still protect the environment.
A prescriptive security configuration checklist from the Center for Internet Security that defines best practices for securing AWS accounts.
A managed service that automates the setup and governance of a secure, multi-account AWS environment based on AWS best practices (landing zone).
Using multiple AWS accounts to isolate workloads, environments, and teams, providing the strongest security boundary available in AWS.
The framework defining that AWS is responsible for security of the cloud (infrastructure), while customers are responsible for security in the cloud (data, access, configuration).
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.