AWS Security Baseline and Guardrails
Learn to set an AWS security baseline: Identity Center, guardrails with SCPs, CloudTrail, Config, Access Analyzer, and Security Hub across accounts.
What You'll Learn
Understanding Why Most AWS Breaches Are Misconfigurations
A Friday evening bucket policy A retail team at a fictional company, acme-shop, needs to share an order export with a vendor in Hyderabad.
Securing the Root User and Account Basics
Locking down the root user Every AWS account has a root user with unlimited power that cannot be restricted by IAM policies, so protecting it is the...
Giving People Access with IAM Identity Center
Why Identity Center replaces IAM users A long-lived access key on a laptop is a breach waiting for a git push.
Setting Guardrails with Organizations and SCPs
What a service control policy does Permissions inside an account can be changed by anyone with enough IAM rights, including an attacker who gets...
Recording Everything with an Organisation CloudTrail
What CloudTrail records and for how long Without an audit trail you cannot answer who did what, when, and from where.
Finding Unintended Access with IAM Access Analyzer
What Access Analyzer reports You cannot review every resource policy by hand, and a wrong one can expose data to the whole internet.
Skills You'll Master
Curriculum Index10 topics
Understanding Why Most AWS Breaches Are Misconfigurations
A Friday evening bucket policy A retail team at a fictional company, acme-shop, needs to share an order export with a...
Securing the Root User and Account Basics
Locking down the root user Every AWS account has a root user with unlimited power that cannot be restricted by IAM...
Giving People Access with IAM Identity Center
Why Identity Center replaces IAM users A long-lived access key on a laptop is a breach waiting for a git push.
Setting Guardrails with Organizations and SCPs
What a service control policy does Permissions inside an account can be changed by anyone with enough IAM rights...
Recording Everything with an Organisation CloudTrail
What CloudTrail records and for how long Without an audit trail you cannot answer who did what, when, and from where.
Finding Unintended Access with IAM Access Analyzer
What Access Analyzer reports You cannot review every resource policy by hand, and a wrong one can expose data to the...
Tracking Configuration with AWS Config and Security Hub
What AWS Config does Config answers a question CloudTrail cannot: what did this resource look like last Tuesday, and...
Turning On Threat Detection as Part of the Baseline
GuardDuty in the baseline A baseline that only records what happened still needs something watching in real time.
Running the Hands-On Lab: Baseline a Sandbox Account
Before you start You will turn on Access Analyzer and Config in one Region, create a deliberately exposed bucket, watch...
Quick Reference and Common Mistakes
Quick reference Common mistakes Using the root user for daily work leaves an unrestrictable credential in constant use.
Career Impact
Roles that use the skills in this module.
- High Demand
DevSecOps Engineer
₹12L - ₹30L a year
- High Demand
Cloud Security Engineer
₹14L - ₹32L a year
- High Demand
Cloud Engineer
₹10L - ₹24L a year
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
Identity Center gives people one sign-in and short-lived credentials for every account, so there are no long-lived access keys to leak or rotate. It also connects to your company identity provider, which means MFA and offboarding happen in one place. IAM users with static keys are the legacy approach.
No. An SCP only sets the maximum permissions available in the accounts it is attached to. A user still needs an IAM policy that allows the action, and an explicit deny in an SCP overrides any allow.
Management events are enough for most baselines, because they record who changed what. Data events record object-level activity such as S3 reads and bill per event, so enable them only for sensitive buckets or functions where you need that audit trail.
Config records how resources are configured over time and evaluates them against rules. Security Hub collects findings from several services and runs security standards, giving you a posture view. Config is the recorder and rule engine, and Security Hub is the dashboard on top.