Detecting Incidents
Even after you have put all the necessary measures in place to protect your infrastructure and your data, you are only halfway through ensuring security. Despite all the protections implemented, some incidents can still occur. It can be any type of incident—a security breach, a data leak, a system misconfiguration, a configuration change, or unexpected behavior. If you don’t do anything to check for such incidents, they will go undetected most of the time, causing potentially acute damage to your business.
The following subsection discusses the various approaches to incident detection.
Picking the Right Tool for the Right Task
First, activate AWS CloudTrail on all your accounts. AWS CloudTrail logs keep a record of all activity (such as who made what request, at what time, and from which IP address) that took place within your account, whether the related actions come from the AWS Management Console, the AWS CLI, or by using AWS SDKs. As we...