Security & Compliance Services

Acadestine

Learning Objectives
    • Distinguish between AWS WAF and AWS Shield for protecting web applications from malicious web traffic and DDoS attacks.
    • Explain how AWS CloudTrail records API activity to provide account accountability and audit trails.
    • Identify how AWS Artifact grants access to compliance reports and enterprise security agreements.

When Cyber Attacks and Auditors Strike at Once

Striking this balance is an ongoing process. As your cloud environment matures, your goal is to automate permission guardrails so that tight security becomes invisible to the daily developer workflow. But what happens when your application moves out of the sandbox and onto the global stage?

Imagine your company’s web application suddenly goes viral. Revenue is skyrocketing, and your team is celebrating. Then, two things happen at the exact same time: your servers crash under a massive wave of malicious traffic, and an enterprise customer demands immediate proof of your security compliance before signing a multi-million dollar contract.

Welcome to the reality of running modern cloud infrastructure. When your application is live on the internet, external threats and internal compliance pressures will hit you simultaneously.

The Reality of Modern Cyber Threats

The moment your workload gets a public IP address, bad actors start probing it for weaknesses. These aren't just bored hackers in dark rooms; they are automated scripts and massive botnets constantly scanning the web.

cloud architectures face continuous, real-world security threats, such as:

  • Distributed Denial of Service (DDoS) Attacks: Flooding your application with billions of fake requests to crash your servers and force your business offline.
  • Web Application Exploits: Crafting malicious inputs like SQL injection or cross-site scripting to trick your app into leaking sensitive data.
  • Automated Scraping and Credential Stuffing: Bots hammering your login endpoints to test stolen password dumps or steal your proprietary data.

If you don't shield your application's perimeter, a single coordinated attack can take down your service and destroy your reputation overnight.

The Pressure of Cloud Compliance

While your engineering team fights off external attacks, your business leadership faces a completely different kind of challenge: compliance pressure.

Major customers, legal regulations, and industry standards require you to prove that your environment is secure. You can no longer just say, "Trust us, our cloud is safe." You must provide concrete evidence.

Auditors will demand answers to tough questions: * Can you prove exactly who changed a database configuration three months ago? * Do you have formal documentation showing your physical and digital infrastructure meets standards like SOC 2, ISO 27001, or PCI-DSS? * Can you track every single administrative API call made inside your accounts?

Managing these dual pressures manually is an absolute nightmare. Trying to block bad IP addresses one by one while digging through endless server text logs for an auditor will lead to burn-out and security failures. When bad actors knock on your front door and auditors demand proof of your internal controls, relying on manual fixes simply won't cut it.

Why Modern Cloud Workloads Require Perimeter and Audit Shields

When bad actors knock on your front door and auditors demand proof of your internal controls, relying on manual fixes simply won't cut it.

Modern cloud environments handle millions of interactions every single day. At this scale, human operators cannot manually evaluate incoming web traffic, inspect every code modification, or assemble stacks of paper reports for regulators. To survive and scale, modern architectures require automated perimeter defense paired with continuous action auditing.

1. Stopping Cyber Attacks at Machine Speed

Cyberattacks rarely involve a human hacker sitting at a keyboard typing commands in real time. Instead, malicious actors use automated scripts and botnets that hit your application with thousands of malicious requests per second.

If your engineering team has to wake up at 2:00 AM, review server logs, and manually block bad IP addresses one by one, your application will be overwhelmed long before you can react.

Automated perimeter defense sits in front of your applications to evaluate, filter, and drop bad traffic in milliseconds. By detecting suspicious patterns at the edge of your network, your core servers remain focused on serving legitimate users without suffering downtime or degraded performance.

2. Maintaining Accountability Through Action Auditing

Defending the perimeter is only half the battle. Threats can also originate from inside your system whether through accidental employee mistakes, misconfigured permissions, or compromised insider credentials.

If a critical server suddenly disappears or a sensitive database is rendered public, you must be able to answer three critical questions immediately: Who did it? What did they change? When did it happen?

Auditing user actions provides an unchangeable record of every single digital request made within your cloud environment. Without continuous activity tracking, investigating a security incident becomes a guessing game. Continuous auditing guarantees:

  • Complete Visibility: Every change to your infrastructure leaves a clear digital footprint.
  • Rapid Root-Cause Analysis: Security teams can trace a system failure back to the exact API call or command that caused it.
  • Strong Deterrence: Users with elevated administrative rights know their actions are permanently recorded, reducing careless or unauthorized behavior.

3. Streamlining Compliance Verification

Passing a security audit used to mean spending weeks collecting evidence. Teams would spend hundreds of hours capturing software screenshots, pulling system event files, and filling out spreadsheets to prove to regulators that their infrastructure met compliance standards like PCI-DSS or ISO 27001.

Streamlining compliance verification transforms audit preparation from a painful, manual scramble into an automated, on-demand process. Instead of manually building compliance evidence from scratch, modern cloud architectures allow you to download pre-packaged, verified audit reports directly from your provider.

Operational Need Traditional Manual Approach Modern Automated Cloud Approach
Traffic Defense Manual IP blocking by on-call engineers Automated, real-time filtering at the application perimeter
Activity Tracking Fragmented system logs scattered across servers Centralized, continuous logging of all user and system actions
Compliance Audits Weeks spent manually gathering screenshots and reports Instant, self-service access to certified compliance evidence

By combining intelligent perimeter defenses with transparent auditing tools, organizations can safely scale their operations without constantly fearing an undetected breach or a failed compliance audit.

Bouncers, Security Cameras, and Vault Archives

To make sense of cloud security, it helps to step away from lines of code and step into a physical location you can easily visualize: an exclusive, high-security facility.

Protecting a modern cloud environment relies on the exact same three real-world security pillars used by high-profile physical venues: * Perimeter defense to keep out bad actors and rowdy crowds * Continuous surveillance to track every movement inside * A certified vault to store official safety records for inspectors

By mapping key AWS security services to these physical roles, you will instantly build an intuitive mental model of how your application stays safe.

The Bouncers at the Door: AWS WAF and AWS Shield

Imagine running a world-famous nightclub. Outside the front door, you face two distinct security challenges: an overwhelming crowd trying to crash the gates all at once, and individual sneaky bad actors trying to slide in with fake IDs or prohibited items.

To handle this, you hire two types of specialized security personnel at the entrance:

  1. The Crowd Control Specialist (AWS Shield): When thousands of unruly crashers rush the front gates to overwhelm the venue, this guard absorbs the impact and holds the barricades strong. AWS Shield defends your infrastructure against massive automated traffic surges designed to knock your application offline.
  2. The ID Inspector (AWS WAF): While crowd control holds the line, another guard stands right at the velvet rope checking individual guests. They inspect IDs, enforce dress codes, and search bags for malicious items before letting anyone walk inside. AWS WAF filters individual web requests, blocking malicious code and bad actors before they ever reach your web servers.

Together, AWS Shield and AWS WAF form your automated perimeter defense stopping threats right at the door before they can disturb the guests inside.

The 24/7 Security Cameras: AWS CloudTrail

Once guests and staff are safely inside the building, perimeter security is no longer enough. You still need to know who opened which door, who accessed the server room, and who adjusted the building thermostat.

AWS CloudTrail operates as a network of 24/7 high-definition security cameras recording every single action across your entire facility:

  • It does not block or stop actions from happening; its sole job is to record history with total honesty.
  • Every time someone requests an action in your cloud account like launching a server or opening a database AWS CloudTrail logs exactly who made the request, what they did, when it happened, and where they were located.
  • If a suspicious event occurs at 2:00 AM, you don’t have to guess what happened you simply play back the audit tape to see every door handle turned and every button pressed.

The Compliance Vault: AWS Artifact

Eventually, local building inspectors and fire marshals will show up at your facility. They do not want to stand around watching live security camera footage or chatting with the bouncers. Instead, they demand official proof that your facility meets global safety standards, environmental codes, and industry regulations.

Instead of spending weeks gathering paperwork from scratch, you walk the inspectors straight down to your building's secure legal archive: AWS Artifact.

AWS Artifact serves as your self-service compliance vault, housing ready-to-download security certifications, ISO reports, payment compliance documentation, and formal legal agreements. When auditors demand proof of compliance, you simply log in, pull down the official signed certificates, and hand them over instantly.

Summary: Comparing Physical Roles to AWS Services

Physical Security Role AWS Service Core Operational Responsibility
Front Door Bouncers AWS WAF & AWS Shield Filters incoming web traffic and absorbs massive attacks at the perimeter line.
24/7 Security Cameras AWS CloudTrail Logs every action, API request, and user event across your infrastructure for total accountability.
Compliance Vault Archives AWS Artifact Provides immediate self-service access to official security certificates and compliance reports.

Understanding these physical security counterparts gives you a crystal-clear framework for how AWS structures its defense model.

Filtering Traffic: AWS WAF and AWS Shield

Now that you have a mental model of perimeter security, it is time to look under the hood at the exact services AWS provides to stop bad actors at the border. To protect cloud workloads from malicious traffic, AWS splits perimeter defense into two complementary services: AWS Shield and AWS WAF.

To understand why both exist, you first need to understand the primary threat they are built to stop: Distributed Denial of Service (DDoS) attacks.


Understanding DDoS Attacks

A DDoS attack occurs when an attacker uses a network of compromised internet-connected devices (a botnet) to flood a target server or application with overwhelming volumes of traffic. The goal is simple: exhaust the target's compute, memory, or network resources so legitimate users cannot access the service.

DDoS attacks generally hit applications at two distinct levels of the network stack: * Infrastructure-layer attacks (Layer 3 & Layer 4): Massive floods of raw network packets such as UDP floods or SYN floods designed to overwhelm your network interfaces or load balancers. * Application-layer attacks (Layer 7): Complex, high-volume HTTP or HTTPS requests designed to look like legitimate user actions, such as flooding a login page or database search endpoint to consume server memory.

Because these attacks operate differently, AWS provides targeted tools to defeat each type.


Protecting the Network: AWS Shield

AWS Shield is a managed DDoS protection service that safeguards applications running on AWS. It inspects incoming network traffic in real time to detect and automatically mitigate infrastructure-level attacks before they ever reach your servers.

AWS offers two tiers of DDoS protection:

Feature AWS Shield Standard AWS Shield Advanced
Target Layer Layer 3 (Network) & Layer 4 (Transport) Layer 3, Layer 4, and Layer 7 (Application)
Availability & Cost Enabled automatically for all AWS customers at no extra cost Paid subscription service for high-risk workloads
Mitigation Type Automatic defense against common, broad volumetric attacks Specialized, real-time mitigation against massive or complex attacks
Expert Support Standard AWS Support channels 24/7 direct access to the specialized AWS DDoS Response Team (DRT)
Cost Protection No financial protection against resource scaling DDoS cost protection to shield you from bill spikes caused by scaling during an attack

AWS Shield Standard acts as your baseline security layer. Every AWS customer automatically receives AWS Shield Standard protection out of the box.

For mission-critical applications where downtime translates directly to lost revenue, AWS Shield Advanced provides granular visibility, active mitigation support, and financial protection.


Inspecting Web Requests: AWS WAF

While AWS Shield protects the network pipeline, AWS WAF (Web Application Firewall) acts as an intelligent inspector for your web traffic at the Application Layer (Layer 7).

AWS WAF gives you control over how traffic reaches your applications by monitoring the HTTP and HTTPS requests directed to your web resources, such as Amazon CloudFront distributions, Application Load Balancers, or Amazon API Gateway APIs.

AWS WAF allows you to inspect specific parts of incoming requests, including: * IP Addresses: Block requests originating from known malicious IP addresses or specific geographical regions. * HTTP Headers and Cookies: Inspect request metadata to identify automated bots or spoofed browser signatures. * URI Strings and Query Parameters: Detect and block malicious code payloads hidden inside URL paths or form fields.

By inspecting these elements, AWS WAF prevents common web exploits from reaching your code including SQL Injection (SQLi), where attackers try to steal database data, and Cross-Site Scripting (XSS), where attackers inject malicious scripts into web pages.

A common beginner mistake is assuming AWS WAF replaces AWS Shield. In reality, they target different layers of the OSI model: AWS Shield stops massive volume floods at the network layer, while AWS WAF inspects the specific contents of individual web requests at the application layer.

By combining AWS Shield for infrastructure-level DDoS protection with AWS WAF for deep application-level request filtering, your cloud perimeter gains a robust, multi-layered defense.

Tracking Actions: AWS CloudTrail

Now that your perimeter is guarded against external incoming attacks, how do you keep track of every action happening inside your AWS account?

Every time you click a button in the AWS Management Console, run a command in the AWS CLI, or deploy infrastructure using an SDK, you are issuing an Application Programming Interface (API) request. AWS CloudTrail functions as the continuous security camera system of AWS, capturing, logging, and retaining every single API call made across your infrastructure.

The Engine Behind CloudTrail: Logging API Requests

To understand AWS CloudTrail, you must first understand a fundamental operational rule: virtually everything in AWS is an API call. Whether an administrator provisions a database through the interface or an automated service scales up servers, AWS treats that action as an API request under the hood.

Without centralized logging, discovering who modified an application setting or modified critical network paths would be impossible. AWS CloudTrail automatically intercepts and records these calls into detailed event records, providing visibility into account operational history.

Each recorded event captures a rich set of context: - Who made the request (userIdentity details, including the IAM user, role, or AWS service). - What action was executed (eventName, such as RunInstances or DeleteBucket). - When the event took place (eventTime represented in UTC). - Where the request originated (sourceIPAddress and target awsRegion). - Which parameters were provided (requestParameters and responseElements).

A common beginner mistake is assuming you must build complex infrastructure before AWS CloudTrail starts logging actions. AWS automatically enables Event History for all management events by default, giving you an immediate 90-day searchable log of account activity at zero extra cost.

Analyzing Event History and Log Records

When security teams or system administrators need to analyze operational changes, they inspect the structured fields recorded by AWS CloudTrail. Because logs are generated in standardized JSON format, event data can be easily parsed and reviewed.

Field Name Purpose Example Log Value
eventTime Timestamp of when the request was made 2026-03-30T14:22:05Z
eventName The exact API operation executed StopInstances
userIdentity Identity information of the caller IAM user DevOps-Sarah
sourceIPAddress IP address where the action originated 198.51.100.24
awsRegion Region where the request was directed us-east-1

By systematically examining these fields, security analysts can reconstruct operational timelines and trace back the precise origin of system modifications.

Security Auditing and Accountability

AWS CloudTrail provides the core audit trail required to maintain non-repudiation and governance across cloud workloads. Non-repudiation means that an actor cannot deny having performed an action, because an immutable event log proves that their specific credentials were used at a specific time.

If an critical production workload suddenly experiences an outage due to a altered security setting, AWS CloudTrail removes all guesswork. Security teams can instantly identify the exact identity that executed the change, the source IP address used, and the precise moment it occurred.

Beyond internal operational troubleshooting, AWS CloudTrail serves as critical evidence for compliance auditing. Security auditors frequently require historic operational records to verify that your organization adheres to security standards, proving that unauthorized actions are actively tracked and monitored across your entire cloud environment.

Proving Compliance: AWS Artifact

Now that you have bouncers guarding the door and security cameras recording every action inside your account, how do you officially prove to external auditors that your infrastructure meets regulatory compliance standards?

When regulators, clients, or third-party security auditors knock on your door, they won't accept a simple verbal promise that your systems are secure. To satisfy strict compliance frameworks, you need official, verifiable evidence of security controls. In the cloud, this poses a unique challenge: because AWS owns and manages the physical data centers, you cannot invite an auditor to walk through an AWS server room to inspect physical lockboxes or biometric scanners.

This is where AWS Artifact steps in as your self-service compliance vault.

SCREENSHOT REQUIRED: AWS Artifact Console dashboard displaying available AWS Artifact Reports such as ISO 27001, SOC 2, and PCI DSS alongside download links.


What is AWS Artifact?

AWS Artifact is a centralized, self-service portal within the AWS Management Console that provides on-demand access to AWS compliance documentation and legal agreements.

Under the AWS Shared Responsibility Model, AWS is responsible for securing the underlying cloud infrastructure. AWS Artifact is the exact tool you use to retrieve official proof that AWS is holding up its end of the bargain. Instead of opening a support ticket or negotiating with sales representatives, security teams can download official audit materials in just a few clicks.

AWS Artifact is split into two main offerings: 1. AWS Artifact Reports 2. AWS Artifact Agreements


1. AWS Artifact Reports: Third-Party Security Audits

AWS Artifact Reports grant you access to global compliance documents, audit reports, and security certifications generated by independent third-party auditors who inspect AWS infrastructure.

When building applications on AWS, your organization inherits the compliance controls implemented by AWS. AWS Artifact Reports provide the legal and technical evidence of those controls so you can present them directly to your auditors.

Common report types available in AWS Artifact Reports include:

  • SOC (System and Organization Controls) Reports: Detailed audit documents (SOC 1, SOC 2, and SOC 3) evaluating AWS operational controls covering security, availability, and confidentiality.
  • ISO Certifications: Internationally recognized standards such as ISO 27001 (Information Security Management) and ISO 27017 (Cloud Security).
  • PCI-DSS (Payment Card Industry Data Security Standard): Attestations of Compliance (AOC) proving that AWS physical infrastructure complies with strict credit card processing security requirements.

When an auditor asks, "How do we know the physical servers hosting our payment system are secure against physical tampering?", you simply navigate to AWS Artifact, download the latest PCI-DSS Attestation of Compliance, and hand it to them.


2. AWS Artifact Agreements: Legal Contracts

While Reports provide audit evidence, AWS Artifact Agreements allow your organization to review, accept, and manage formal legal contracts directly with AWS.

Certain compliance frameworks mandate specific legal bindings between your organization and your cloud provider before you can legally process sensitive data in the cloud.

Key examples of AWS Artifact Agreements include:

  • BAA (Business Associate Addendum): A legally binding agreement required under HIPAA (Health Insurance Portability and Accountability Act) if your application processes protected health information (PHI) on AWS infrastructure.
  • NDA (Non-Disclosure Agreement): Enables access to confidential AWS compliance documents that are not publicly available.
  • Organizational Agreements: Allows an administrator in an AWS Organizations management account to accept legal terms once on behalf of all child accounts across the entire enterprise.

Downloading reports from AWS Artifact requires specific IAM permissions (such as artifact:GetReport). Furthermore, many reports downloaded from AWS Artifact contain confidential information covered by an NDA, meaning they are intended strictly for your internal teams and external auditors, not for public distribution.


The Power of Self-Service Compliance

Before self-service cloud compliance portals existed, retrieving audit evidence from a infrastructure provider took weeks of email exchanges, legal reviews, and manual document requests.

AWS Artifact shifts compliance evidence gathering from a multi-week administrative bottleneck into a 60-second download.

Feature AWS Artifact Reports AWS Artifact Agreements
Primary Purpose Provide third-party audit evidence and security certifications Execute and manage binding legal contracts with AWS
Typical Audience External auditors, security officers, compliance teams Legal teams, compliance officers, account administrators
Key Examples SOC 2 Reports, ISO 27001 Certificates, PCI-DSS Attestations BAA (for HIPAA), Nondisclosure Agreements (NDA)
Primary Output Downloadable PDF reports and audit packages Signed, active contractual agreements tied to your account

By combining perimeter defense, detailed activity logging, and instant compliance verification, you have all the core building blocks required to secure modern workloads on AWS.

Putting the Security Blueprint Together

With your perimeter defended by AWS WAF and AWS Shield, your internal actions tracked by AWS CloudTrail, and your legal compliance validated by AWS Artifact, you are ready to construct a cohesive security blueprint.

Building a resilient cloud infrastructure is not about choosing a single tool; it is about combining distinct layers into a unified strategy. A robust cloud architecture requires balancing three core security operational pillars: Protection, Auditing, and Compliance.

text +------------------------+ | Incoming Web Traffic | +-----------+------------+ | v +----------------------------------------+ | PROTECTION LAYER | | • AWS Shield (DDoS Mitigation) | | • AWS WAF (Web Traffic Filtering) | +-------------------+--------------------+ | v +----------------------------------------+ | AWS INFRASTRUCTURE & API RESOURCES | +-------------------+--------------------+ | +-------------------+--------------------+ | | v v +-------------------------------+ +-------------------------------+ | AUDITING LAYER | | COMPLIANCE LAYER | | • AWS CloudTrail | | • AWS Artifact | | (Logs API activity & changes) | | (Provides compliance reports) | +-------------------------------+ +-------------------------------+


Protection vs. Auditing vs. Compliance

To design an effective architecture, you must understand how these three pillars differ in their responsibilities, operational timing, and target audiences.

Pillar Core Objective Primary AWS Services Operational Timing Primary Target Audience
Protection Block malicious traffic and prevent service disruptions AWS WAF, AWS Shield Real-time (Inline) External attackers and malicious bots
Auditing Record identity actions, system events, and API calls AWS CloudTrail Near real-time (Passive continuous) Internal security analysts and forensic investigators
Compliance Demonstrate legal adherence and regulatory controls AWS Artifact On-demand (As-needed) Third-party auditors, legal teams, and regulators

Key Service Pairings

In a production environment, these services do not operate in isolated silos. They are paired together to create continuous feedback loops across your operational security.

  • AWS WAF + AWS CloudTrail: While AWS WAF blocks malicious HTTP requests at the edge, AWS CloudTrail logs every administrative modification made to your AWS WAF rulesets. This pairing ensures that your perimeter defense actively blocks attackers while simultaneously generating an audit log of who updated your security policies.
  • AWS Shield + AWS CloudTrail: When a large-scale DDoS attack strikes, AWS Shield automatically mitigates the volumetric threat at the network layer. Concurrently, AWS CloudTrail records the API actions taken by your operations team or automated scripts during the incident response phase.
  • AWS CloudTrail + AWS Artifact: When auditors ask for proof of security compliance, AWS Artifact provides official, signed documentation validating that AWS global infrastructure meets standards like ISO 27001 or SOC 2. Pairing AWS Artifact reports with your internal AWS CloudTrail logs allows you to prove compliance for both the underlying cloud provider and your own internal team's operations.

Key Operational Trade-offs

Architecting security infrastructure requires making deliberate architectural trade-offs between protection depth, operational expense, and management overhead.

1. Protection Depth vs. Cost and Performance

Deploying active edge security like AWS WAF and AWS Shield Advanced provides robust, automated defense against bad actors and massive DDoS attacks. However, inline inspection introduces minor operational overhead.

Inspecting complex web traffic payloads adds microsecond-level latency to requests, and advanced DDoS protections introduce fixed monthly subscription costs. Architects must balance the cost of application downtime against the financial investment of inline protection tools.

2. Auditing Coverage vs. Storage and Analysis Overhead

Enabling AWS CloudTrail across all regions ensures complete visibility into every API call made within your infrastructure.

The trade-off lies in data management: high-volume cloud environments generate millions of event logs daily. While comprehensive logging guarantees absolute accountability, it requires long-term storage strategies and query tooling to process the generated data without running up excessive storage costs.

3. Self-Service Evidence vs. Responsibility Scope

Using AWS Artifact eliminates hundreds of hours of manual audit preparation by delivering instant, self-service access to AWS compliance reports and legal agreements.

However, the key trade-off is recognizing the boundary of ownership: AWS Artifact proves that AWS manages and secures the physical hardware and underlying cloud software, but it does not automatically certify your custom application code or data configurations. You must still maintain your own operational controls and provide your own AWS CloudTrail logs to auditors.

By aligning AWS WAF and AWS Shield for real-time edge protection, AWS CloudTrail for deep operational auditing, and AWS Artifact for regulatory proof, you create a complete, enterprise-grade cloud security blueprint.