Soteria - Security Solutions & Advisory’s Post

Are you prepared to handle Incident Response in your AWS accounts? Like many things AWS Security, preparation often starts with your AWS Account structure. From the AWS Security IR Guide: It’s helpful to have a structure that supports the functions of incident response, such as having a security Organizational Unit (OU) and a forensics OU. Within the security OU, you should have accounts for: Log archival – Aggregate logs in a log archival AWS account Security tooling – Centralize security services in a security tool AWS account Within the forensics OU, you have the option to implement a single forensics account or accounts for each Region that you operate in, depending on which works best for your business and operational mode. Because it takes time to provision new accounts, it is imperative to create and instrument the forensics accounts well ahead of an incident so that responders can be prepared to effectively use them for response. The following diagram displays a sample account structure including a forensics OU with per-Region forensics accounts: For help or to answer your AWS Security questions, contact our team today: https://lnkd.in/gxeqZBnk For more details from AWS, review the AWS IR Guide: https://lnkd.in/gZ4JWQY

  • No alternative text description for this image

To view or add a comment, sign in

Explore topics