

本文為英文版的機器翻譯版本，如內容有任何歧義或不一致之處，概以英文版為準。

# 安全支柱
<a name="security"></a>

 AWS Well-Architected Framework 的安全支柱著重於保護資訊和系統。下列建議可協助您符合 Amazon FSx for Windows File Server 的安全設計原則和架構最佳實務。

**主要重點領域：**
+ 資料完整性和機密性
+ 管理使用者許可
+ 建立控制以偵測安全事件

## 實作強大的身分基礎
<a name="identity-foundation"></a>
+ 授予與 整合或存取 FSx for Windows File Server 之 AWS 資源所需的最低 AWS Identity and Access Management (IAM) 權限。如需詳細資訊，請參閱《[Amazon FSx 文件》中的使用 IAM for Amazon FSx 進行資源管理存取控制](https://docs.aws.amazon.com/fsx/latest/WindowsGuide/access-control-overview.html)。 FSx 
+ 使用 Windows 存取控制清單 ACLs) 來管理精細的檔案層級和資料夾層級存取。如需詳細資訊，請參閱 Amazon FSx 文件中的[使用 Windows ACLs 的檔案層級和資料夾層級存取控制](https://docs.aws.amazon.com/fsx/latest/WindowsGuide/limit-access-file-folder.html)。

## 啟用可追蹤性
<a name="traceability"></a>
+ 啟用 FSx for Windows File Server 檔案系統的檔案存取稽核。如需詳細資訊，請參閱 Amazon FSx 文件中的[檔案存取稽核](https://docs.aws.amazon.com/fsx/latest/WindowsGuide/file-access-auditing.html)。
+ 在 FSx for Windows File Server 檔案系統中設定檔案和資料夾的稽核控制，以追蹤失敗的登入。如需詳細資訊，請參閱部落格文章[使用 Amazon FSx for Windows File Server 的檔案儲存存取模式洞察](https://aws.amazon.com/blogs/storage/file-storage-access-patterns-insights-using-amazon-fsx-for-windows-file-server/)。
+ 使用共用資料夾工具來監控連線的使用者工作階段，並在 FSx for Windows File Server 檔案系統上開啟檔案。如需詳細資訊，請參閱 Amazon FSx 文件中的[使用者工作階段和開啟檔案](https://docs.aws.amazon.com/fsx/latest/WindowsGuide/manage-sessions-and-files.html)。
+ 啟用 AWS CloudTrail 以記錄 FSx for Windows File Server API 呼叫。如需詳細資訊，請參閱 AWS Workshop Studio *AWS 中多帳戶安全控管研討會*的設定[中央 AWS CloudTrail](https://catalog.us-east-1.prod.workshops.aws/workshops/d3f60827-89f2-46a8-9be7-6e7185bd7665/en-US/2-service-guardrails/cloudtrail)區段。

## 將安全性套用至所有層
<a name="layers"></a>
+ 如果您要加入自我管理 Active Directory，請使用所需的最低權限來設定您的服務帳戶。如需詳細資訊，請參閱[《Amazon FSx 文件》中的將權限委派給您的 Amazon FSx 服務帳戶](https://docs.aws.amazon.com/fsx/latest/WindowsGuide/self-managed-AD-best-practices.html#connect_delegate_privileges)。 FSx 
+ 使用安全群組和網路 ACLs 來限制對檔案系統的存取。如需詳細資訊，請參閱 [Amazon FSx 文件中的使用 Amazon VPC 的檔案系統存取控制](https://docs.aws.amazon.com/fsx/latest/WindowsGuide/limit-access-security-groups.html)。 FSx 

## 自動化安全最佳實務並為安全事件做好準備
<a name="automation"></a>
+ 自動化對特定安全事件的事件回應，例如通知安全團隊未經授權的存取嘗試。

  若要自動化事件通知和回應，您可以使用下列一或多個 AWS 服務：
  + [AWS Lambda](https://docs.aws.amazon.com/lambda/latest/dg/welcome.html)
  + [Amazon CloudWatch](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/WhatIsCloudWatch.html)
  + [Amazon EventBridge](https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-what-is.html)
  + [AWS Systems Manager](https://docs.aws.amazon.com/systems-manager/latest/userguide/what-is-systems-manager.html)
  + [Amazon Simple Notification Service (Amazon SNS)](https://docs.aws.amazon.com/sns/latest/dg/welcome.html)

## 保護傳輸中和靜態的資料
<a name="data"></a>
+ 若要強制執行傳輸中加密，請將存取權限制為僅支援伺服器訊息區塊 (SMB) 通訊協定 3.0 版和更新版本的用戶端。如需詳細資訊，請參閱 Amazon FSx 文件中的[管理傳輸中的加密](https://docs.aws.amazon.com/fsx/latest/WindowsGuide/manage-encrypt-in-transit.html)。