From the course: AWS Well-Architected Framework: Security Pillar

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

AWS detective controls for security

AWS detective controls for security - Amazon Web Services (AWS) Tutorial

From the course: AWS Well-Architected Framework: Security Pillar

Start my 1-month free trial

AWS detective controls for security

- [Narrator] The key detective controls that you should consider using for managing your security at AWS, rely on some key components, logs, monitoring, events, and alarms. There isn't a service that you can order at AWS that doesn't generate logs. Some you have to actually check the box off and say, "I'd like to keep those logs" like load balancing, but the logs are there. Monitoring of course we have to sign up for, but then again, Amazon does some monitoring on their own. We can use those services without paying any additional charges to find out a lot of information about our application stack. Events and alarms are terms that are utilized by the key detective control, and that is CloudWatch, for monitoring everything that's going on, including logs. When a certain situation or event occurs, we want an alarm to fire and we want the adequate response. CloudTrail contains all API calls of everything that happens in my…

Contents