In this chapter, we learned about the importance of automating responses to security incidents and looked at a few AWS services that help us achieve this automation—CloudWatch, GuardDuty, and Security Hub. As your environment scales and grows (and it will, especially when you begin to integrate multiple accounts, which Amazon GuardDuty and AWS Security Hub both support), it will become essential to implement a level of automatic detection and remediation to help you identify and resolve security incidents as and when they occur.
With the help of this chapter, you are now able to adopt a range of different AWS security services, such as Amazon GuardDuty, AWS Security, Amazon CloudWatch, AWS Lambda, and AWS CloudTrail, and use them as an asset to your security strategy. Not only can you now automatically put blocks in place as and when suspicious activity is automatically detected, but you can also notify your security teams, allowing them to investigate how it happened and...