As an auditing best practice, ensure that security audits are performed periodically for your AWS account to meet compliance and regulatory requirements. To begin with, use AWS Trusted Advisor to audit security for your AWS account. Apart from periodic activity, an audit should be carried out in case of the following events:
- Changes in your organization
- One or more AWS services are no longer used
- If there is a change in the software or hardware configuration for your resources
- If there is a suspicious activity detected
The following is a list of AWS controls to be audited for security:
- Governance
- Network configuration and management
- Asset configuration and management
- Logical access control
- Data encryption
- Security logging and monitoring
- Security incident response
- Disaster recovery
- Inherited controls
Along with this checklist, there are various...