[AWS Architecture Patterns] Security

Need to enable custom domain name and encryption in transit for an application running behind an Application Load Balancer?

Use AWS Route 53 to create an Alias record to the ALB's DNS name and attach an SSL/TLS certificate issued by Amazon Certificate Manager (ACM).

 

Company records customer information in CSV in an S3 bucket and must ont store PII data?

Use Macie to scan the S3 bucket for any PII data.

 

For compliance reasons all S3 buckets must have encryption enabled and any non-compliant buckets must be auto remediated?

Use AWS Config to check the encryption status of the buckets and use auto remediation to enable encyprtion as requried.

 

EC2 instances must be checked against CIS benchmarks every 7 days?

Install Amazon Inspector agent and configure a host assessment every 7 days.

 

Webiste running on EC2 instances behind and ALB must be protected against well known web exploits?

Create a Web ACL in AWS WAF to protect against web exploits against web exploits and attach to the ALB.

 

Need to block access to an application running on an ALB from connections originating in a specific list of countries?

Create a Web ACL in AWS WAF with a geographic match and block traffic that matches the list of countries.

 

Partten matching for 100 requests per 5 mins, block it

 

 

posted @   Zhentiw  阅读(40)  评论(0编辑  收藏  举报
相关博文:
阅读排行:
· 阿里最新开源QwQ-32B,效果媲美deepseek-r1满血版,部署成本又又又降低了!
· Manus重磅发布:全球首款通用AI代理技术深度解析与实战指南
· 开源Multi-agent AI智能体框架aevatar.ai,欢迎大家贡献代码
· 被坑几百块钱后,我竟然真的恢复了删除的微信聊天记录!
· AI技术革命,工作效率10个最佳AI工具
历史上的今天:
2021-03-28 [Node.js] Apply image filter on Express
2019-03-28 [Node.js] process.nextTick for converting sync to async
2019-03-28 [Algorithm] Print 2-D array in spiral order
2017-03-28 [Grid Layout] Use auto-fill and auto-fit if the number of repeated grid tracks is not to be def
2017-03-28 [Grid Layout] Use the repeat function to efficiently write grid-template values
2017-03-28 [Grid Layout] Use the minmax function to specify dynamically-sized tracks
2017-03-28 [Jest] Snapshot
点击右上角即可分享
微信分享提示