01Identity & AccessIAM users, roles, groups, policies, MFA, access keys, dormant identities, root account use.
02Account GovernanceAWS Organizations structure, Service Control Policies, account separation and isolation.
03Network SecurityVPC design, security groups, NACLs, public exposure, peering, Transit Gateway, perimeter ingress and egress.
04Data ProtectionEncryption at rest (KMS, EBS, S3, RDS), encryption in transit, public S3 buckets, sensitive data exposure.
05Secrets ManagementSecrets Manager / Parameter Store usage, secret rotation, hard-coded credentials.
06Logging & VisibilityCloudTrail, VPC Flow Logs, GuardDuty, Security Hub, AWS Config, retention and immutability.
07Detection & ResponseAlert routing, on-call coverage, runbooks, incident response readiness.
08Backup & RecoveryBackup coverage, recovery testing, immutability, cross-account / cross-region resilience.
09Patching & RuntimeOS and runtime patching cadence, container image hygiene, Systems Manager coverage.
10Framework AlignmentAWS Well-Architected Security Pillar mapping; optional ISO 27001 Annex A and / or SOC 2 control mapping.