Typically, you will start with basic security measures in place and then rapidly iterate from there to improve your overall cloud security model and/or implementation. Before designing any of your security solutions, you will need to identify and then classify the assets you need to protect into high/medium/low risk categories. This is often a non-trivial undertaking in large enterprises. Asset data is typically entered manually in most organizations, and it relies heavily on human accuracy. Capturing this data programmatically results in better efficiency and accuracy. Integrate AWS, APIs with your existing enterprise asset management systems, and include your CloudFormation templates or scripts as artifacts in your configuration management database to get a better handle on your cloud assets.
In order to get off the ground faster,...