IAM Users, Roles, and Permissions
Teams with improper IAM users, roles, and permissions are at risk of privilege escalation and unauthorized access.
Network Security Settings
AWS enables organizations to configure numerous network security settings. Teams with insecure networking settings for VPCs, Security Groups, and NACLs could end up with vulnerable network.
High Availability in Production Workloads
Organizations managing production workloads on AWS typically build for high availability. Cloud service issues related to load balancers, NAT gateways and issues with fail-over could lead to a potential service outage.
Security Controls
Individual cloud services with improper security controls may be vulnerable to hacking and may be accessed by unauthorized third parties.
Regulatory Compliance
Regulatory compliance standards such as HIPAA and cybersecurity standards such as SOC 2 require teams to maintain specific security standards for IT infrastructure. Missing protections, or changes to security configuration could lead to non-compliance.