Network security is evaluated by each organization making sure it assesses the effectiveness of your defenses. Internet-facing systems receive several hundreds or even millions of attack attempts every day. Many of these are simple scans that our security system can defend against, but others catch you by surprise, unexpectedly shifting into incident investigation and cleanup mode.
This chapter provides assistance in securing a network by explaining important concepts and inter-relationships of security controls.
First of all, we need to understand the shared responsibility model, as infrastructure security is shared between AWS and customer and it varies from different service models of Infrastructure as a Service (IAAS), Platform as a Service (PAAS), and Software as a Service (SAAS).
AWS provides a global infrastructure responsible for the following:
- Underlying...