|
1
|
Standardization Guidelines
|
Purpose, scope, governance lifecycle, and feedback loops
|
|
2
|
Account Architecture
|
AWS Organizations structure, multi-account strategy, SCPs
|
|
3
|
Network Architecture
|
VPC topology, hybrid cloud connectivity (Direct Connect / VPN), DNS (Route 53), NTP
|
|
4
|
IAM & Access Governance
|
Centralized SSO (IAM Identity Center), permission boundaries, privilege separation
|
|
5
|
Detective Controls
|
AWS Security Hub, Amazon GuardDuty, AWS Config continuous compliance
|
|
6
|
Infrastructure Protection
|
Perimeter defense (AWS WAF, Shield), egress filtering, vulnerability scanning
|
|
7
|
Data Protection
|
Data classification, KMS encryption in transit and at rest, backup isolation
|
|
8
|
Observability & Monitoring
|
CloudWatch metrics, alarms, synthetic monitoring, OpenTelemetry integration
|
|
9
|
Log Management
|
CloudTrail, VPC Flow Logs, S3 access logs, centralized aggregation
|
|
10
|
Incident Response
|
Runbooks, automated containment, forensic snapshot retention
|
|
11
|
Disaster Recovery & Resiliency
|
Multi-AZ / Multi-Region failover, automated backup/restore validation
|
|
12
|
Infrastructure as Code (IaC)
|
Terraform / AWS CloudFormation standards, CI/CD deployment pipelines
|
|
13
|
Operations Management
|
Systems Manager (SSM) fleet management, automated patching, tagging policy
|
|
14
|
Cost Management
|
AWS Cost Explorer, Budgets, Savings Plans / Reserved Instances strategy
|