Glossary

    Security Pillar

    Architecture & Design

    The Security Pillar is one of six pillars of the AWS Well-Architected Framework. It describes how to protect information, systems, and assets while delivering business value through risk assessments and mitigation strategies.

    Seven Design Principles

    • Implement a strong identity foundation: centralized identity, least privilege, separation of duties
    • Maintain traceability: monitor, alert, and audit all actions and changes
    • Apply security at all layers: defense in depth (network, application, data, OS)
    • Automate security best practices: version-controlled security controls as code
    • Protect data in transit and at rest: encryption, tokenization, access control
    • Keep people away from data: eliminate direct access to production data
    • Prepare for security events: incident response playbooks, simulations, automated remediation

    Five Focus Areas

    1. Security foundations (shared responsibility, governance)
    2. Identity and access management
    3. Detection (logging, monitoring, threat detection)
    4. Infrastructure protection (network, compute)
    5. Data protection (encryption, classification, backup)

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.