A Security Group acts as a virtual firewall for AWS resources (EC2 instances, RDS databases, Lambda functions in VPCs, ELBs). It controls which traffic is allowed to reach and leave the resource.
A stateless firewall at the subnet level that controls inbound and outbound traffic using numbered allow and deny rules.
An isolated virtual network within AWS where you launch resources, with full control over IP addressing, subnets, route tables, and network gateways.
A security strategy using multiple layers of controls (network, identity, data, application) so that if one layer fails, others still protect the environment.
Dividing a network into isolated segments (subnets, VPCs) to limit lateral movement and contain the blast radius of a security breach.
Toc Consulting: AWS Security & Cloud Architecture
Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.