11 Simple Yet Important Tips to Secure AWS

save
Share and earn Cybytes
Facebook Twitter LinkedIn Email

AWS Security Best Practices

As more and more organizations of all sizes are moving applications and workloads to the public cloud, it is critical to understand the security challenges of the cloud in general, and AWS in particular. IT environments are increasingly hybrid in nature, with many organizations maintaining some on-premises infrastructure as well as cloud infrastructure, using one or more cloud providers. It is critical to leverage security solutions that can monitor both cloud and on-premises environments.

Here are some simple yet important tips to help secure your AWS account and infrastructure:

1.Lock Down Your Root Account Credentials: When you create an AWS account, it comes with root account credentials. You can use these credentials to access all resources in the account (full access). Our recommendation is to delete the root account access keys and create an Identity and Access Management (IAM) admin user instead. Note, you will still need root account access for critical users to perform certain operations, and you can still access the root account using the username/password on the AWS console. As a final recommendation, you should enable multi-factor authentication (MFA) to protect your account.

2. Use Security Groups: Use AWS Security Groups to limit access to administrative services (SSH, RDP, etc.) as well as databases. In addition, try to restrict access and allow only certain network ranges when possible (and avoid using 0.0.0.0/0). It is also important to monitor and delete security groups that are not being used and to audit them periodically.

3. CloudTrail: AWS CloudTrail is a critical resource for monitoring your AWS environment. CloudTrail logs every event related to your AWS infrastructure, including API calls and changes made from the AWS Console, SDKs, or command line tools. While CloudTrail contains an amazing level of detail related to your AWS account activity, it is often hard to understand all the events and to identify what is important from a security point of view. That is why the CloudTrail data is much more valuable when using a solution such as USM Anywhere  that has out-the-box correlation and alerting capabilities for CloudTrail events.

Read the rest here on the AlienVault blog!

Share this post and earn Cybytes
Facebook Twitter LinkedIn Email
Follow
3263 Followers
About AT&T CyberSecurity
AT&T Cybersecurity’s edge-to-edge technologies provide phenomenal threat intelligence, collaborative defense, security without the seams, and solutions that fit your business. Our unique, collaborative approach integrates best-of-breed technologies with unrivaled network visibility and actionable threat intelligence from AT&T Alien Labs researchers, Security Operations Center analysts, and machine learning – helping to enable our customers around the globe to anticipate and act on threats to protect their business. --
Promoted Content
2018 Threat Intelligence Report
Threat intelligence has become a significant weapon in the fight against cybersecurity threats, and a large majority of organizations have made it a key part of their security programs. This threat intelligence report, produced by Cybersecurity Insiders, explores how organizations are leveraging threat intelligence data, the benefits and most critical features of threat intelligence platforms, and the biggest cyber threats organizations are using their threat intelligence to combat. Download this report now to learn industry findings around threat intelligence.

Our Revolution

We believe Cyber Security training should be free, for everyone, FOREVER. Everyone, everywhere, deserves the OPPORTUNITY to learn, begin and grow a career in this fascinating field. Therefore, Cybrary is a free community where people, companies and training come together to give everyone the ability to collaborate in an open source way that is revolutionizing the cyber security educational experience.

Cybrary On The Go

Get the Cybrary app for Android for online and offline viewing of our lessons.

Get it on Google Play
 

Support Cybrary

Donate Here to Get This Month's Donor Badge

 
Skip to toolbar

We recommend always using caution when following any link

Are you sure you want to continue?

Continue
Cancel