IAM Users, Roles, and Permissions

Teams with improper IAM users, roles, and permissions are at risk of privilege escalation and unauthorized access.

Network Security Settings

AWS enables organizations to configure numerous network security settings. Teams with insecure networking settings for VPCs, Security Groups, and NACLs could end up with vulnerable network.

High Availability in Production Workloads

Organizations managing production workloads on AWS typically build for high availability. Cloud service issues related to load balancers, NAT gateways and issues with fail-over could lead to a potential service outage.

Security Controls

Individual cloud services with improper security controls may be vulnerable to hacking and may be accessed by unauthorized third parties.

Regulatory Compliance

Regulatory compliance standards such as HIPAA and cybersecurity standards such as SOC 2 require teams to maintain specific security standards for IT infrastructure. Missing protections, or changes to security configuration could lead to non-compliance.