Cloud Security for Modern Infrastructure
AWS Security Best Practices: A Practical Checklist
AWS security best practices include enabling MFA on all accounts, enforcing least-privilege IAM policies, enabling CloudTrail in all regions, blocking public S3 access by default, using VPC security groups with minimal open ports, enabling GuardDuty for threat detection, and encrypting all data at rest and in transit.

Andreas Johansson · Chief Executive Officer
Senior IT management leader with 25 years of experience in Cloud, Security, and Datacenter infrastructure.
AWS Security Fundamentals
AWS provides hundreds of security features and services. The challenge isn't capability — it's knowing which controls matter most and implementing them consistently across every account, region, and service. This checklist prioritizes the controls with the highest security impact.
Account and Organization Security
- Use AWS Organizations. Manage multiple accounts through a central organization. Separate workloads by account (production, staging, development, security) to limit blast radius.
- Enable Service Control Policies (SCPs). SCPs set permission boundaries across your organization. Use them to prevent dangerous actions: disabling CloudTrail, creating public S3 buckets, or launching resources in unauthorized regions.
- Secure the root account. Enable MFA with a hardware token. Never use root for daily operations. Store root credentials in a secure vault with break-glass procedures. Set up billing alerts to detect unauthorized usage.
- Enable AWS CloudTrail in all regions. CloudTrail records every API call — it's your audit trail for everything that happens in your AWS environment. Enable it in all regions (not just your primary region) and send logs to a centralized, tamper-proof S3 bucket.
Identity and Access Management (IAM)
- Enforce MFA for all human users. Require multi-factor authentication for console access and for CLI/API access to sensitive operations. MFA prevents credential-based attacks — which account for the majority of cloud breaches.
- Implement least privilege. Use IAM Access Analyzer to identify unused permissions. Start with minimal policies and add permissions as needed rather than starting broad and trying to restrict later.
- Use IAM roles, not long-lived access keys. EC2 instances, Lambda functions, and ECS tasks should use IAM roles with temporary credentials. Long-lived access keys in code, configuration files, or developer laptops are a leading breach vector.
- Rotate credentials regularly. For any long-lived credentials that must exist, enforce regular rotation. AWS Secrets Manager automates credential rotation for RDS, Redshift, and other services.
- Implement session policies and permission boundaries. Use permission boundaries to cap the maximum permissions a role can have, preventing privilege escalation even if policies are misconfigured.
S3 and Data Security
- Block public access at the account level. Enable the S3 Block Public Access setting at the account level, not just the bucket level. This prevents any bucket from being accidentally made public.
- Enable default encryption. Configure S3 buckets to encrypt all objects by default using SSE-S3 or SSE-KMS. Enable encryption for EBS volumes, RDS instances, and all other data stores.
- Enable S3 access logging. Track who accesses your data and when. S3 access logs are essential for incident investigation and compliance evidence.
- Use S3 Object Lock for critical data. Prevent deletion or modification of critical data (backups, audit logs) using S3 Object Lock in compliance mode.
Network Security
- Use VPCs with private subnets. Place workloads in private subnets by default. Use NAT gateways for outbound internet access and load balancers for inbound traffic. Only place resources in public subnets when absolutely necessary.
- Minimize security group rules. Open only required ports to only required sources. Never allow 0.0.0.0/0 to management ports (22, 3389). Review security groups regularly for stale or overly permissive rules.
- Enable VPC Flow Logs. Flow logs capture network traffic metadata for analysis, anomaly detection, and forensics. Send flow logs to CloudWatch or S3 for retention and analysis.
- Use AWS PrivateLink for service access. Access AWS services (S3, DynamoDB, SQS) through VPC endpoints rather than over the public internet. This reduces exposure and improves performance.
Detection and Monitoring
- Enable Amazon GuardDuty. GuardDuty uses ML, anomaly detection, and threat intelligence to identify threats across your AWS environment. Enable it in all accounts and regions — it requires zero configuration and provides immediate value.
- Use AWS Security Hub. Security Hub aggregates findings from GuardDuty, Inspector, Macie, and third-party tools into a single dashboard. It also runs automated compliance checks against CIS AWS Foundations Benchmark.
- Implement AWS Config. Config records resource configurations and changes over time. Use Config Rules to automatically evaluate compliance and detect configuration drift.
- Set up CloudWatch Alarms. Create alarms for critical security events: root account usage, IAM policy changes, security group modifications, and CloudTrail changes.
Automated Compliance
- Use AWS Config Rules for continuous compliance. Map Config Rules to your compliance framework (CIS, SOC 2, PCI DSS) for automated assessment. Non-compliant resources trigger alerts and can trigger automated remediation.
- Implement infrastructure as code. Use CloudFormation or Terraform with security-reviewed templates. Scan IaC templates with tools like cfn-nag or checkov before deployment.
How SeqOps fits
SeqOps connects to AWS, Azure and Google Cloud with read-only access, checks your configuration against security benchmarks, and shows every misconfiguration in one prioritised view with guidance on how to fix it.