International

AWS Well-Architected Security Pillar

63 controls. 28 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

63 controls 28 frameworks share controls with it International verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

AWS Well-Architected Security Evidence & Implementation Kit

63 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
SEC01-BP01Separate workloads using accounts24
SEC01-BP02Secure account root user and properties23
SEC01-BP03Identify and validate control objectives24
SEC01-BP04Stay up to date with security threats and recommendations21
SEC01-BP05Reduce security management scope17
SEC01-BP06Automate deployment of standard security controls22
SEC01-BP07Identify threats and prioritize mitigations using a threat model23
SEC01-BP08Evaluate and implement new security services and features regularly11
SEC02-BP01Use strong sign-in mechanisms23
SEC02-BP02Use temporary credentials22
SEC02-BP03Store and use secrets securely24
SEC02-BP04Rely on a centralized identity provider22
SEC02-BP05Audit and rotate credentials periodically24
SEC02-BP06Employ user groups and attributes22
SEC03-BP01Define access requirements24
SEC03-BP02Grant least privilege access26
SEC03-BP03Establish emergency access process18
SEC03-BP04Reduce permissions continuously23
SEC03-BP05Define permission guardrails for your organization21
SEC03-BP06Manage access based on lifecycle25
SEC03-BP07Analyze public and cross-account access20
SEC03-BP08Share resources securely within your organization15
SEC03-BP09Share resources securely with a third party22
SEC04-BP01Configure service and application logging25
SEC04-BP02Capture logs, findings, and metrics in standardized locations23
SEC04-BP03Correlate and enrich security alerts24
SEC04-BP04Initiate remediation for non-compliant resources19
SEC05-BP01Create network layers24
SEC05-BP02Control traffic flow within your network layers25
SEC05-BP03Implement inspection-based protection24
SEC05-BP04Automate network protection17
SEC06-BP01Perform vulnerability management27
SEC06-BP02Provision compute from hardened images27
SEC06-BP03Reduce manual management and interactive access23
SEC06-BP04Validate software integrity22
SEC06-BP05Automate compute protection27
SEC07-BP01Understand your data classification scheme23
SEC07-BP02Apply data protection controls based on data sensitivity20
SEC07-BP03Automate identification and classification17
SEC07-BP04Define scalable data lifecycle management23
SEC08-BP01Implement secure key management21
SEC08-BP02Enforce encryption at rest22
SEC08-BP03Automate data at rest protection17
SEC08-BP04Enforce access control24
SEC09-BP01Implement secure key and certificate management19
SEC09-BP02Enforce encryption in transit23
SEC09-BP03Authenticate network communications21
SEC10-BP01Identify key personnel and external resources22
SEC10-BP02Develop incident management plans26
SEC10-BP03Prepare forensic capabilities17
SEC10-BP04Develop and test security incident response playbooks22
SEC10-BP05Pre-provision access14
SEC10-BP06Pre-deploy tools11
SEC10-BP07Run simulations20
SEC10-BP08Establish a framework for learning from incidents22
SEC11-BP01Train for application security24
SEC11-BP02Automate testing throughout the development and release lifecycle20
SEC11-BP03Perform regular penetration testing22
SEC11-BP04Conduct code reviews19
SEC11-BP05Centralize services for packages and dependencies18
SEC11-BP06Deploy software programmatically20
SEC11-BP07Regularly assess security properties of the pipelines19
SEC11-BP08Build a program that embeds security ownership in workload teams21

Tell me when AWS Well-Architected Security Pillar files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Role inventory + RACI
  • Metrics + management review
  • Annual cycle documentation
  • Supervisory dialogue records
  • Role inventory + RACI + DPO designation
  • Operational controls + tooling investment
  • Segmentation diagram
  • DMARC reject record
  • Encrypted DNS policy
  • Firewall rule review

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for AWS Well-Architected Security Pillar, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition