AMS for Security Operations
Use this reference architecture to understand how AWS Managed Services (AMS) accelerates security and compliance in an AWS environment. AMS enables numerous security guardrails as part of account onboarding, providing a well-monitored and secure environment from day one.
This reference architecture was validated by the AWS Managed Services team for technical accuracy on September 20, 2022.
The following steps describe the architecture:
-
Security and governance teams define high-level policies, requirements, and tooling. Your application and operations teams follow the guidelines to ensure security best practices are implemented.
-
As part of account onboarding, AMS enables essential AWS services and logs to achieve the desired security posture at OS, infrastructure, and account levels.
-
AMS uses to continuously monitor threats and potential malicious activities. AMS also implements custom rules for PCI, NIST, CIS, and HIPAA compliance. Optionally, AMS can monitor for sensitive data by using AWS Macie.
-
All threat findings and non-compliant rules generate monitoring events. These events go into an AMS internal service account for investigation, noise reduction, and remediation.
-
AMS uses AWS Systems Manager to create and remediate incidents. AMS also helps restore services and data by using AWS Backup.
-
You can collate and ingest security events from multiple third-party security tools and monitor them by using AWS Security Hub.
Deploy the architecture
AWS Managed Services deploys and manages this architecture on your behalf as part of the AMS operations plan. You do not need to deploy CloudFormation templates or write custom code. To get started with AMS, see the What is AWS Managed Services? section in the AMS User Guide.
For onboarding details and account setup, see AMS onboarding.
Further reading
For additional information, refer to the following resources:
Diagram history
To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.
| Change | Description | Date |
|---|---|---|
Reference architecture diagrams first published. | September 20, 2022 | |
Reference architecture diagrams first published. | September 20, 2022 | |
Initial publication | Reference architecture diagrams first published. | September 20, 2022 |
Reference architecture diagrams first published. | September 20, 2022 | |
Reference architecture diagrams first published. | September 20, 2022 | |
Reference architecture diagrams first published. | September 20, 2022 |
Note
To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.